强化性能的故障:通过GPU降电压提升CNN对抗鲁棒性
Faults That Fortify: CNN Adversarial Robustness via GPU Undervolting
浏览论文内容
中文总结 AI 辅助
该研究针对CNN的对抗脆弱性与高训练成本问题,提出在训练时对GPU降电压,利用硬件故障作为隐式正则化,在不修改算法的情况下提升对抗鲁棒性并降低能耗。
中文摘要 AI 辅助
卷积神经网络(CNN)面临双重挑战:易受对抗攻击且训练成本高昂。对抗训练虽有效但代价不菲,随着学习转向受能量约束的边缘设备,该负担不断加剧。本文通过训练期间的GPU降电压同时解决这两个问题。降低电源电压会引入随机扰动,起到隐式正则化作用,在降低功耗的同时提升鲁棒性。我们在比特层面表征降电压引发的故障,随后在标准和对抗两种训练模式下,分别以额定电压和降电压对LeNet、VGG-6和MobileNetV3在MNIST和CIFAR-10数据集上进行训练,并评估所有模型的对抗攻击性能。在两种模式下,降电压模型的对抗准确率始终高于其额定电压对应模型,表明硬件引发的故障甚至能强化对抗训练。由于动态功耗与电源电压呈平方比例关系,这些鲁棒性提升伴随着显著的节能效果。因此,GPU降电压是一种易于部署的硬件级防御措施,无需算法变更,为鲁棒性与能效协同提升开辟了有前景的方向。
英文摘要
Convolutional Neural Networks (CNNs) face a dual challenge: vulnerability to adversarial attacks and prohibitive training cost. Adversarial training is effective but expensive, a burden that grows as learning shifts to the energy-constrained edge. This paper addresses both through GPU undervolting during training. Reducing supply voltage introduces stochastic perturbations that act as implicit regularization, improving robustness while lowering power. We characterize undervolting-induced faults at the bit level, then train LeNet, VGG-6, and MobileNetV3 on MNIST and CIFAR-10 under two training regimes, standard and adversarial, each at nominal and undervolted voltage, and evaluate all models against adversarial attacks. In both regimes, the undervolted model consistently achieves higher adversarial accuracy than its nominal-voltage counterpart, showing that hardware-induced faults strengthen even adversarial training. Because dynamic power scales quadratically with supply voltage, these robustness gains arrive with substantial energy savings. GPU undervolting is therefore a readily deployable hardware-level defense requiring no algorithmic change, and opens a promising direction in which robustness and energy efficiency move together.
发表机构
- George Mason University(乔治梅森大学)
- SecureMind Technologies Inc(SecureMind科技公司)
- Rochester Institute of Technology(罗切斯特理工学院)
机构由 AI 辅助整理,请以论文原文为准。