The increasing pervasiveness of Artificial Intelligence (AI), and Convolutional Neural Networks (CNNs) in edge-computing and Internet of Things applications pose several challenges, including the hunger for computational and power resources of predictive models, and their robustness w.r.t. security threats, e.g., adversarial attacks. As for the former, the approximate computing emerged as one of the most promising solutions to lower the computational effort of AI, since the output of approximate application is usually barely distinguishable from the exact one. Nevertheless, alterations to predictive models through approximation may actually jeopardize inner characteristics of CNNs, such as their adversarial robustness, that is their ability to discern legitimate inputs from systematically crafted malicious ones. In this paper, we investigate the vulnerability of the approximate CNNs to adversarial attacks. Specifically, we target approximate CNNs while resorting to different adversarial attacks in an aversion scenario, and we empirically prove approximation may actually compromise adversarial robustness.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Error Resiliency and Adversarial Robustness in Convolutional Neural Networks: An Empirical Analysis

  • Mario Barbareschi,
  • Salvatore Barone,
  • Valentina Casola,
  • Salvatore Della Torca

摘要

The increasing pervasiveness of Artificial Intelligence (AI), and Convolutional Neural Networks (CNNs) in edge-computing and Internet of Things applications pose several challenges, including the hunger for computational and power resources of predictive models, and their robustness w.r.t. security threats, e.g., adversarial attacks. As for the former, the approximate computing emerged as one of the most promising solutions to lower the computational effort of AI, since the output of approximate application is usually barely distinguishable from the exact one. Nevertheless, alterations to predictive models through approximation may actually jeopardize inner characteristics of CNNs, such as their adversarial robustness, that is their ability to discern legitimate inputs from systematically crafted malicious ones. In this paper, we investigate the vulnerability of the approximate CNNs to adversarial attacks. Specifically, we target approximate CNNs while resorting to different adversarial attacks in an aversion scenario, and we empirically prove approximation may actually compromise adversarial robustness.