Increasing Robustness against Adversarial Attacks through Ensemble of Approximate Multipliers

Ehsan Atoofian · 2022

Over the past few years, deep neural networks (DNNs) have been used to solve a wide range of real-life problems. However, DNNs are vulnerable to adversarial attacks where carefully crafted input perturbations can mislead a well-trained DNN to produce false results. As DNNs are being deployed into security-sensitive applications such as autonomous driving, adversarial attacks may lead to catastrophic consequences. In this work, we propose ensemble of approximate multipliers (EAM) where DNNs with different approximate multipliers are used as a new approach to boost robustness against adversarial attacks. A DNN equipped with an approximate multiplier is an effective method to enhance resiliency of DNNs. However, the degree of robustness in a DNN varies with the type of approximate multiplier. Depending on the level of approximation, the accuracy of the DNN varies for different adversarial attacks. We exploit this variability and propose mixing DNNs with different types of approximate multipliers. Our proposed technique does not require changing the architecture of a model nor memory hierarchy. We only use additional approximate units within a multiplier. We evaluate EAM across different DNNs and under a variety of adversarial attacks. Our evaluations reveal that EAM increases robustness by a large margin compared to an exact model while maintaining accuracy on benign inputs.

Read the paper · More papers on PaperTik