Enhancing the Security of Collaborative Deep Neural Networks: An Examination of the Effect of Low Pass Filters

被引:3
作者
Adeyemo, Adewale A. [1 ]
Hasan, Syed Rafay [1 ]
机构
[1] Tennessee Technol Univ, Dept Elect & Comp Engn, Cookeville, TN 38505 USA
来源
PROCEEDINGS OF THE GREAT LAKES SYMPOSIUM ON VLSI 2023, GLSVLSI 2023 | 2023年
关键词
Edge Intelligence; Convolution Neural Networks (CNN); Collaborative Inference; Low Pass Filters; Adversarial Attacks;
D O I
10.1145/3583781.3590299
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
To ensure that accuracy and latency are not compromised while deploying Deep Neural Networks (DNNs) on edge devices, trained DNN models can be partitioned across many collaborating edge devices for inference. However, this collaborative inference paradigm raises new security risks because one of the collaborating edge devices could be malicious or compromised, leading to compromised accuracy and reliability of inference results. To address this challenge, this paper explores the use of low-pass filters to enhance the robustness of Collaborative DNNs. The study deploys a VGG16 network, trained on the German Traffic Sign Recognition Benchmarks (GTSRB) dataset, and a MobileNet network trained on the ImageNet dataset, using two prevalent collaborative inference methodologies. The output feature maps (FMs) of a vulnerable edge device are perturbed using four advanced adversarial noises, namely Speckle, Salt-and-Pepper, Gaussian noise, and the Fast Gradient Signed Method (FGSM). Experimental results demonstrate that implementing low-pass filtering can significantly enhance the robustness of Collaborative DNNs. On average, the top-1 classification accuracy is improved by 2.1x times, making the DNNs more robust to adversarial attacks.
引用
收藏
页码:461 / 465
页数:5
相关论文
共 35 条
[1]   Towards Enabling Dynamic Convolution Neural Network Inference for Edge Intelligence [J].
Adeyemo, Adewale ;
Sandefur, Travis ;
Odetola, Tolulope A. ;
Hasan, Syed Rafay .
2022 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS (ISCAS 22), 2022, :1833-1837
[2]   Security Analysis of Capsule Network Inference using Horizontal Collaboration [J].
Adeyemo, Adewale ;
Khalid, Faiq ;
Odetola, Tolulope ;
Hasan, Syed Rafay .
2021 IEEE INTERNATIONAL MIDWEST SYMPOSIUM ON CIRCUITS AND SYSTEMS (MWSCAS), 2021, :1074-1077
[3]   StAIn: Stealthy Avenues of Attacks on Horizontally Collaborated Convolutional Neural Network Inference and Their Mitigation [J].
Adeyemo, Adewale A. ;
Sanderson, Jonathan J. ;
Odetola, Tolulope A. ;
Khalid, Faiq ;
Hasan, Syed Rafay .
IEEE ACCESS, 2023, 11 :10520-10534
[4]   SSCNets: Robustifying DNNs using Secure Selective Convolutional Filters [J].
Ali, Hassan ;
Khalid, Faiq ;
Tariq, Hammad Ali ;
Hanif, Muhammad Abdullah ;
Ahmed, Rehan ;
Rehman, Semeen .
IEEE DESIGN & TEST, 2020, 37 (02) :58-65
[5]  
Azzeh J., 2018, Int. J. Informat. Visualizat., V2, P252, DOI [10.30630/joiv.2.4.151, DOI 10.30630/JOIV.2.4.151]
[6]  
Bianchi A, 2019, Arxiv, DOI arXiv:1904.03949
[7]  
Brendel W, 2018, Arxiv, DOI arXiv:1712.04248
[8]  
Camuto A., 2020, P ADV NEUR INF PROC, P16603
[9]  
Carbone G, 2020, ADV NEUR IN, V33
[10]  
Deng J, 2009, PROC CVPR IEEE, P248, DOI 10.1109/CVPRW.2009.5206848