发表机构
Politecnico di Torino; Tallinn University of Technology; University of California, Irvine; Brandenburg University of Technology; Humboldt University of Berlin(都灵理工大学; 塔林理工大学; 加州大学欧文分校; 勃兰登堡工业大学; 柏林洪堡大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出统一框架联合评估拆分计算中DNN的可靠性与安全性,引入JVS指标,在ResNet-50上揭示独立评估隐藏的脆弱性趋势。
AI 中文摘要
拆分计算(Split Computing, SC)通过将推理过程在边缘设备与云服务器之间进行划分,实现了深度神经网络(DNN)的高效部署。然而,中间特征表示同时暴露于硬件故障和对抗性攻击之下,而这两类威胁传统上是被独立评估的。本文提出了一个用于拆分计算中可靠性与安全性联合评估的统一框架。首先,通过使用平均相对精度退化(Mean Relative Accuracy Degradation, MRAD)的神经元级故障注入来表征可靠性,同时通过使用攻击成功率(Attack Success Rate, ASR)的基于特征图感知的对抗性攻击模拟来表征安全性。基于这些互补的分析,引入了联合脆弱性评分(Joint Vulnerability Score, JVS),并扩展了其置信度感知版本,以联合捕获预测误差和置信度退化。该框架在基于在ILSVRC-2012上训练的ResNet-50的十种拆分计算配置上进行了评估。实验结果显示,不同压缩策略之间存在显著差异,故障注入下MRAD的范围为44.3%至61.2%,而对抗性攻击的ASR最高可达98.8%。此外,所提出的联合指标揭示了当单独分析可靠性和安全性时隐藏的脆弱性趋势,为设计可靠的拆分计算系统提供了一种更全面的方法论。
英文摘要
Split Computing (SC) enables efficient deployment of Deep Neural Networks (DNNs) by partitioning inference between edge devices and cloud servers. However, intermediate feature representations are simultaneously exposed to hardware faults and adversarial attacks, which are traditionally evaluated independently. This paper presents a unified framework for the joint assessment of reliability and security in Split Computing. First, reliability is characterized through neuron-level fault injection using the Mean Relative Accuracy Degradation (MRAD) while security through feature-map-aware adversarial attacks simulations using the Attack Success Rate (ASR). Based on these complementary analyses, the Joint Vulnerability Score (JVS) is introduced, along with a confidence-aware extension that jointly captures prediction errors and confidence degradation. The framework is evaluated on ten Split Computing configurations based on ResNet-50 trained on ILSVRC-2012. Experimental results show substantial differences across compression strategies, with MRAD ranging from 44.3% to 61.2% under fault injection, while adversarial attacks achieve up to 98.8% ASR. Furthermore, the proposed joint metrics reveal vulnerability trends that remain hidden when reliability and security are analyzed independently, providing a more comprehensive methodology for designing dependable Split Computing systems.
Comments11 pages, 9 figures. Accepted as a special session paper at the 2026 IEEE International Symposium on Defect and Fault Tolerance in VLSI and Nanotechnology Systems (DFT)