Exploring DNN Robustness Against Adversarial Attacks Using Approximate Multipliers
Mohammad Askarizadeh, J. Castro Godinez, Ebrahim Farahmand, Ali Khayatzadeh Mahani, Laura Cabrera-Quirós, Carlos Salazar-García · 2024
Deep Neural Networks (DNNs) play an important role in advancing today’s technology by performing machine learning tasks such as image, video, speech, and text analysis, significantly improving real-world applications such as healthcare and autonomous driving. However, their high computational complexity and vulnerability to adversarial attacks are ongoing challenges. In this work, approximate multipliers are introduced in DNN computations, instead of accurate ones, to explore its robustness improvement against adversarial attacks. By uniformly replacing accurate multipliers for state-of-the-art approximate ones in DNN layer models, we explore the DNNs’ robustness against various adversarial attacks in a feasible time. Results show up 10% robust accuracy improvement for up to to 7% accuracy drop due to approximations when no attack is present.