RRAM-DP:用于内存边缘学习的设备校准差分隐私
RRAM-DP: Device-Calibrated Differential Privacy for In-Memory Edge Learning
浏览论文内容
中文总结 AI 辅助
研究边缘AIoT系统隐私问题,提出RRAM-DP硬件-算法协同设计,利用RRAM随机写入行为实现差分隐私保护。在CIFAR-10/100等数据集上实验,该方法准确率下降小,还能大幅节省能量、加速训练,实现高效隐私保护的内存训练。
中文摘要 AI 辅助
边缘人工智能物联网(AIoT)系统经常就地收集敏感数据,引发严重的隐私问题。电阻式开关随机存取存储器(RRAM)因其多位存储和内存计算(CiM)能力,是高效AIoT的有吸引力的基板,其固有的随机写入行为可用于差分隐私(DP)保护。本文提出RRAM-DP,一种硬件-算法协同设计,通过放松RRAM写验证操作来注入校准噪声,以实现固有(ε,δ)-DP,并进行形式化DP分析。与预训练技术一起,它提供了一种新颖的私有、高效用的CiM训练范式。在CIFAR-10/100、STS-B和SST-2上,RRAM-DP-SGD在(ε=2,δ=O(1/n))-DP下相对于非私有SGD的准确率下降最多仅3.8%。在相同隐私级别下,RRAM-DP-SGD分别比A100和DiVa-GEMM节省57倍和3.2倍的能量,加速2.7倍和1.8倍。这些结果表明在边缘RRAM上进行高效、隐私保护的内存训练是可行的。
英文摘要
Edge Artificial Intelligence of Things (AIoT) systems often collect sensitive data in situ, raising serious privacy concerns. Resistive-switching random-access memory (RRAM) is an attractive substrate for efficient AIoT thanks to its multi-bit storage and compute-in-memory (CiM) capabilities, while its inherently stochastic write behavior provides a natural source of randomness that can be leveraged for differential privacy (DP) protection. Yet how to transform this device-level randomness-typically viewed as detrimental to accuracy-into a principled randomized mechanism while preserving model utility remains underexplored. We propose RRAM-DP, a hardware-algorithm co-design that relaxes RRAM write-verify operations to inject calibrated noise for inherently (epsilon, delta)-DP with formal DP analysis; together with pretraining techniques, it renders a novel private, high-utility CiM training paradigm. On CIFAR-10/100, STS-B, and SST-2, RRAM-DP-SGD incurs at best only a 3.8% accuracy drop at (epsilon=2, delta=O(1/n))-DP relative to non-private SGD. At the same privacy level, RRAM-DP-SGD delivers up to 57x and 3.2x energy savings and 2.7x and 1.8x speedups over A100 and DiVa-GEMM, respectively. These results point toward efficient, privacy-preserving in-memory training on RRAM at the edge.