arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

理解对抗鲁棒剪枝模型的容错性

Understanding Fault Tolerance of Adversarially Robust Pruned Models

Manali Dangarikar, Cory Merkel

arXiv 2608.04173首次发表:更新:

发表机构

Rochester Institute of Technology(罗切斯特理工学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究探究剪枝、对抗训练与硬件故障对CNN鲁棒性的交互影响,发现对抗训练提升抗扰动性但增权重故障敏感性,剪枝不显著增故障敏感性,需兼顾对抗鲁棒性与硬件可靠性。

AI 中文摘要

部署在资源受限的神经形态硬件上的深度神经网络(DNNs)面临三个并发挑战:需要通过剪枝进行模型压缩、易受对抗输入扰动影响、易受硬件诱导的权重故障(如 stuck-at-zero 错误)影响。虽然这些因素已被单独研究,但它们对模型可靠性的综合影响却很少受到关注。本文对剪枝、对抗训练和硬件故障注入如何相互作用影响卷积神经网络的鲁棒性进行了实证研究。使用在 MNIST 上训练的紧凑三层 CNN,我们开展了三项实验:(1)比较自然训练和对抗训练模型在同时存在硬件故障和对抗攻击时的容错性;(2)评估剪枝如何影响对抗鲁棒性;(3)刻画在故障率、对抗扰动幅度和剪枝水平上的联合准确率曲面。我们的结果表明,对抗训练可提升对输入扰动的鲁棒性,但会增加对 stuck-at-zero 权重故障的敏感性;与直觉相反,剪枝并未显著增加故障敏感性,且改变剪枝水平对不同故障率和攻击强度几乎无影响。这些结果凸显了需同时考虑对抗鲁棒性和硬件可靠性。

英文摘要

Deep neural networks (DNNs) deployed on resource-constrained neuromorphic hardware face three concurrent challenges: the need for model compression through pruning, vulnerability to adversarial input perturbations, and susceptibility to hardware-induced weight faults such as stuck-at-zero errors. While each of these factors has been studied in isolation, their combined effects on model reliability have received little attention. This paper presents an empirical investigation of how pruning, adversarial training, and hardware fault injection interact to affect the robustness of convolutional neural networks. Using a compact three-layer CNN trained on MNIST, we conduct three experiments: (1) comparing the fault tolerance of naturally and adversarially trained models under simultaneous hardware faults and adversarial attacks, (2) evaluating how pruning affects adversarial robustness, and (3) characterizing the joint accuracy surface across fault rates, adversarial perturbation magnitudes, and pruning levels. Our results show that adversarial training improves robustness against input perturbations but increases sensitivity to stuck-at-zero weight faults. Contrary to intuition, pruning did not significantly increase fault sensitivity, and varying the pruning level had little effect across fault rates and attack strengths. These results highlight the need to jointly consider adversarial robustness and hardware reliability.

Comments6 pages, 4 figures, Accepted for oral presentation at the 2026 IEEE National Aerospace and Electronics Conference (NAECON 2026)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑