LeQC-At: Learning Quantization Configurations During Adversarial Training for Robust Deep Neural Networks

Siddharth Gupta, Salim Ullah, Akash Kumar · 2024

Due to the high feature learning capability of Deep Neural Networks (DNNs), they are widely used in state-of-the-art machine learning tasks such as image and text recognition and natural language processing. However, in the recent developments of deep learning models, it has been observed that specially crafted inputs (adversarial samples) can deceive DNNs and result in incorrect predictions with high confidence. Such incorrect predictions by adversarially attacked DNNs can have devastating results in safety-critical applications. This situation can be further exacerbated in quantized DNNs, which employ reduced precision numbers to reduce the overall computational complexity of DNNs. To this end, this work proposes a framework for the joint optimization of DNNs to improve the natural accuracy of quantized DNNs and increase the robustness of the quantized models against adversarial attacks. In particular, the proposed framework employs quantization step size aware adversarial training of DNNs. Our proposed framework is generic and can be utilized with any quantization scheme that allows learning of quantization configurations during training. Furthermore, we present a novel loss function for adversarial training to improve the quantized networks' accuracy. For example, our 3-bit quantized adversarial training of ResNet-18, ResNet-34, and WideResNet shows up to 21.63%, 24.49%, and 15.08% higher inference accuracy with attacked data, respectively, when compared to 3-bit vanilla quantized adversarial training on benchmark datasets.

Read the paper · More papers on PaperTik