Can Hardware Performance Counters Detect Adversarial Inputs?
Preet Derasari, Siva Koppineedi, Guru Venkataramani · 2020
Deep learning has become an integral part of modern-day applications. Recent research has shown how inputs for a Neural Network can be perturbed to disrupt its detection accuracy and lead to fatal consequences. In this paper, we investigate whether hardware performance counters available in most modern microprocessors uncover adversarial inputs constructed using perturbations to the clean input images. Our experiments on three different datasets, having real-life DNN applications ranging from traffic sign to melanoma detectors, paints an interesting picture- while the hardware performance counters show a difference (approximately 1% for some performance counters) between clean and adversarial inputs on individual samples, they do not show any significant trend to distinguish between clean and modified samples.