Improving the adversarial robustness of quantized neural networks via exploiting the feature diversity.
Saved in:
| Title: | Improving the adversarial robustness of quantized neural networks via exploiting the feature diversity. |
|---|---|
| Authors: | Chu, Tianshu1 (AUTHOR) chutianshu@sjtu.edu.cn, Fang, Kun1 (AUTHOR) fanghenshao@sjtu.edu.cn, Yang, Jie2 (AUTHOR) jieyang@sjtu.edu.cn, Huang, Xiaolin1,2 (AUTHOR) xiaolinhuang@sjtu.edu.cn |
| Source: | Pattern Recognition Letters. Dec2023, Vol. 176, p117-122. 6p. |
| Subjects: | Deep learning |
| Abstract: | Quantized neural networks (QNNs) have become one of the most prevalent approaches in deep learning model compression due to their computational and storage efficiency. However, there is a lack of research specialized in the adversarial robustness of QNNs, which is important for applications in security-critical domains. Existing defenses focus on conventional full-precision networks, which can result in behavioral disparities and degrade the expected performance when directly transferred to QNNs. A novel defensive strategy promotes feature diversity through an orthogonal constraint, which can synergize well with quantization. Inspired by this intuition, we propose an orthogonal regularization with quantization to improve the adversarial robustness of QNNs in this paper. Moreover, we observe that quantization serves as an implicit regularization and is able to alleviate orthogonal degeneration. The proposed orthogonal regularization with quantization is validated on several typical network architectures and benchmark datasets. The results demonstrate that the proposed method can notably enhance adversarial robustness against both white-box and black-box attacks. • We address the issue of the adversarial vulnerability of quantized neural networks (QNNs). • The adversarial robustness of QNNs is improved via exploiting the feature diversity. • The orthogonal degeneration is alleviated by network quantization. • The proposed Q-OMP method is validated via extensive experiments. [ABSTRACT FROM AUTHOR] |
| Copyright of Pattern Recognition Letters is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Database: | Engineering Source |
| FullText | Text: Availability: 0 |
|---|---|
| Header | DbId: egs DbLabel: Engineering Source An: 174013955 AccessLevel: 6 PubType: Academic Journal PubTypeId: academicJournal PreciseRelevancyScore: 0 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: Improving the adversarial robustness of quantized neural networks via exploiting the feature diversity. – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Chu%2C+Tianshu%22">Chu, Tianshu</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> chutianshu@sjtu.edu.cn</i><br /><searchLink fieldCode="AR" term="%22Fang%2C+Kun%22">Fang, Kun</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> fanghenshao@sjtu.edu.cn</i><br /><searchLink fieldCode="AR" term="%22Yang%2C+Jie%22">Yang, Jie</searchLink><relatesTo>2</relatesTo> (AUTHOR)<i> jieyang@sjtu.edu.cn</i><br /><searchLink fieldCode="AR" term="%22Huang%2C+Xiaolin%22">Huang, Xiaolin</searchLink><relatesTo>1,2</relatesTo> (AUTHOR)<i> xiaolinhuang@sjtu.edu.cn</i> – Name: TitleSource Label: Source Group: Src Data: <searchLink fieldCode="JN" term="%22Pattern+Recognition+Letters%22">Pattern Recognition Letters</searchLink>. Dec2023, Vol. 176, p117-122. 6p. – Name: Subject Label: Subjects Group: Su Data: <searchLink fieldCode="DE" term="%22Deep+learning%22">Deep learning</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: Quantized neural networks (QNNs) have become one of the most prevalent approaches in deep learning model compression due to their computational and storage efficiency. However, there is a lack of research specialized in the adversarial robustness of QNNs, which is important for applications in security-critical domains. Existing defenses focus on conventional full-precision networks, which can result in behavioral disparities and degrade the expected performance when directly transferred to QNNs. A novel defensive strategy promotes feature diversity through an orthogonal constraint, which can synergize well with quantization. Inspired by this intuition, we propose an orthogonal regularization with quantization to improve the adversarial robustness of QNNs in this paper. Moreover, we observe that quantization serves as an implicit regularization and is able to alleviate orthogonal degeneration. The proposed orthogonal regularization with quantization is validated on several typical network architectures and benchmark datasets. The results demonstrate that the proposed method can notably enhance adversarial robustness against both white-box and black-box attacks. • We address the issue of the adversarial vulnerability of quantized neural networks (QNNs). • The adversarial robustness of QNNs is improved via exploiting the feature diversity. • The orthogonal degeneration is alleviated by network quantization. • The proposed Q-OMP method is validated via extensive experiments. [ABSTRACT FROM AUTHOR] – Name: AbstractSuppliedCopyright Label: Group: Ab Data: <i>Copyright of Pattern Recognition Letters is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=174013955 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.1016/j.patrec.2023.10.024 Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 6 StartPage: 117 Subjects: – SubjectFull: Deep learning Type: general Titles: – TitleFull: Improving the adversarial robustness of quantized neural networks via exploiting the feature diversity. Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Chu, Tianshu – PersonEntity: Name: NameFull: Fang, Kun – PersonEntity: Name: NameFull: Yang, Jie – PersonEntity: Name: NameFull: Huang, Xiaolin IsPartOfRelationships: – BibEntity: Dates: – D: 01 M: 12 Text: Dec2023 Type: published Y: 2023 Identifiers: – Type: issn-print Value: 01678655 Numbering: – Type: volume Value: 176 Titles: – TitleFull: Pattern Recognition Letters Type: main |
| ResultId | 1 |