Skip to main content
QUICK REVIEW

[論文レビュー] Adversarial Attacks on Brain-Inspired Hyperdimensional Computing-Based Classifiers

Fangfang Yang, Shaolei Ren|arXiv (Cornell University)|Jun 10, 2020
Ferroelectric and Negative Capacitance Devices参考文献 49被引用数 13
ひとこと要約

本稿は、脳にインspiredされたハイパーサイクルコンピューティング(HDC)分類器に対する敵対的攻撃の最初の体系的研究を提示し、最小限の摂動を伴う入力に対してその脆弱性を示している。灰色ボックス設定下で修正された遺伝的アルゴリズムを用いて、固定多数決ルール下で78%の成功率でHDC分類器をだます敵対的サンプルを生成した。これは、エネルギー効率の高いデバイス内AIシステムにおけるセキュリティリスクを示している。

ABSTRACT

Being an emerging class of in-memory computing architecture, brain-inspired hyperdimensional computing (HDC) mimics brain cognition and leverages random hypervectors (i.e., vectors with a dimensionality of thousands or even more) to represent features and to perform classification tasks. The unique hypervector representation enables HDC classifiers to exhibit high energy efficiency, low inference latency and strong robustness against hardware-induced bit errors. Consequently, they have been increasingly recognized as an appealing alternative to or even replacement of traditional deep neural networks (DNNs) for local on device classification, especially on low-power Internet of Things devices. Nonetheless, unlike their DNN counterparts, state-of-the-art designs for HDC classifiers are mostly security-oblivious, casting doubt on their safety and immunity to adversarial inputs. In this paper, we study for the first time adversarial attacks on HDC classifiers and highlight that HDC classifiers can be vulnerable to even minimally-perturbed adversarial samples. Concretely, using handwritten digit classification as an example, we construct a HDC classifier and formulate a grey-box attack problem, where an attacker's goal is to mislead the target HDC classifier to produce erroneous prediction labels while keeping the amount of added perturbation noise as little as possible. Then, we propose a modified genetic algorithm to generate adversarial samples within a reasonably small number of queries. Our results show that adversarial images generated by our algorithm can successfully mislead the HDC classifier to produce wrong prediction labels with a high probability (i.e., 78% when the HDC classifier uses a fixed majority rule for decision). Finally, we also present two defense strategies -- adversarial training and retraining-- to strengthen the security of HDC classifiers.

研究の動機と目的

  • HDC分類器のセキュリティ上の脆弱性を調査すること。HDC分類器は、その効率性と耐性から、低消費電力のIoTデバイスでますます利用されている。
  • HDC分類器がハードウェアノイズに対しては耐性があるものの、深層ニューラルネットワークと同様に敵対的サンプルに対して感受性を示すかどうかを分析すること。
  • 灰色ボックス脅威モデル下で、効果的かつクエリ効率の良い攻撃手法をHDC分類器に適用すること。
  • 敵対的訓練および再訓練を含む防御メカニズムを提案・評価し、HDC分類器の耐性を高めること。

提案手法

  • 攻撃者がHDC分類器の意思決定メカニズムの一部の知識を持つ灰色ボックス攻撃問題を定式化する。
  • ターゲットモデルへのクエリ数を最小限に抑えつつ、最小限の摂動で敵対的サンプルを生成するための修正された遺伝的アルゴリズムを設計する。
  • 意思決定に固定多数決ルールを用いたハイパーコンパクトベース分類を採用し、攻撃成功率の体系的評価を可能にする。
  • 生成された敵対的サンプルに対して耐性を持つように、敵対的訓練および再訓練戦略を適用する。
  • 攻撃および防御のパフォーマンスを評価するため、MNIST手書き数字分類をベンチマークとして用いる。
  • 攻撃成功率および摂動の大きさを評価し、HDC分類器の脅威表面を定量化する。

実験結果

リサーチクエスチョン

  • RQ1HDC分類器が低消費電力・デバイス内推論を目的として設計されていながら、敵対的攻撃によって誤って分類されることは可能か?
  • RQ2灰色ボックス仮定下で、クエリ効率の良い遺伝的アルゴリズムに基づく攻撃は、HDC分類器に対して敵対的サンプルを効果的に生成できるか?
  • RQ3異なるHDC分類器の構成において、敵対的サンプルによる誤分類の成功率はどの程度か?
  • RQ4敵対的訓練および再訓練は、HDC分類器の耐性を顕著に向上させることができるか?
  • RQ5敵対的サンプルの摂動の大きさは、HDCシステムの内在的なノイズ耐性と比べてどの程度か?

主な発見

  • 固定多数決ルールを用いたHDC分類器では、提案された攻撃が、手書き数字の誤分類に78%の成功率で成功した。
  • 最小限の摂動で敵対的サンプルを生成できることから、HDC分類器が微細で目に見えない入力の変更に対して感受性を示すことが明らかになった。
  • 修正された遺伝的アルゴリズムは、限られたクエリ数で入力空間を効果的に探索でき、実世界のシナリオにおいて実用的であることが示された。
  • 敵対的訓練および再訓練は、その後の攻撃の成功率を顕著に低下させ、防御機構としての有効性を実証した。
  • HDCがハードウェア由来のビットエラーに対しては内在的に耐性があるものの、標的的で入力レベルの敵対的摂動に対しては依然として脆弱であることが判明した。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。