arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.18169cs.CRcs.ET

RRAM-DP:用于内存边缘学习的设备校准差分隐私

RRAM-DP: Device-Calibrated Differential Privacy for In-Memory Edge Learning

Kwunhang Wong, Jichang Yang, Karl M. H. Lai, Hegan Chen, Songqi Wang, Wei Xuan, Ning Lin, Han Wang, Xiaojuan Qi, Zhongrui Wang

首次发表
浏览论文内容

中文总结 AI 辅助

研究边缘AIoT系统隐私问题,提出RRAM-DP硬件-算法协同设计,利用RRAM随机写入行为实现差分隐私保护。在CIFAR-10/100等数据集上实验,该方法准确率下降小,还能大幅节省能量、加速训练,实现高效隐私保护的内存训练。

中文摘要 AI 辅助

边缘人工智能物联网(AIoT)系统经常就地收集敏感数据,引发严重的隐私问题。电阻式开关随机存取存储器(RRAM)因其多位存储和内存计算(CiM)能力,是高效AIoT的有吸引力的基板,其固有的随机写入行为可用于差分隐私(DP)保护。本文提出RRAM-DP,一种硬件-算法协同设计,通过放松RRAM写验证操作来注入校准噪声,以实现固有(ε,δ)-DP,并进行形式化DP分析。与预训练技术一起,它提供了一种新颖的私有、高效用的CiM训练范式。在CIFAR-10/100、STS-B和SST-2上,RRAM-DP-SGD在(ε=2,δ=O(1/n))-DP下相对于非私有SGD的准确率下降最多仅3.8%。在相同隐私级别下,RRAM-DP-SGD分别比A100和DiVa-GEMM节省57倍和3.2倍的能量,加速2.7倍和1.8倍。这些结果表明在边缘RRAM上进行高效、隐私保护的内存训练是可行的。

英文摘要

Edge Artificial Intelligence of Things (AIoT) systems often collect sensitive data in situ, raising serious privacy concerns. Resistive-switching random-access memory (RRAM) is an attractive substrate for efficient AIoT thanks to its multi-bit storage and compute-in-memory (CiM) capabilities, while its inherently stochastic write behavior provides a natural source of randomness that can be leveraged for differential privacy (DP) protection. Yet how to transform this device-level randomness-typically viewed as detrimental to accuracy-into a principled randomized mechanism while preserving model utility remains underexplored. We propose RRAM-DP, a hardware-algorithm co-design that relaxes RRAM write-verify operations to inject calibrated noise for inherently (epsilon, delta)-DP with formal DP analysis; together with pretraining techniques, it renders a novel private, high-utility CiM training paradigm. On CIFAR-10/100, STS-B, and SST-2, RRAM-DP-SGD incurs at best only a 3.8% accuracy drop at (epsilon=2, delta=O(1/n))-DP relative to non-private SGD. At the same privacy level, RRAM-DP-SGD delivers up to 57x and 3.2x energy savings and 2.7x and 1.8x speedups over A100 and DiVa-GEMM, respectively. These results point toward efficient, privacy-preserving in-memory training on RRAM at the edge.

补充信息

↑