返回
DefQ: Defensive Quantization Against Inference Slow-Down Attack for Edge Computing
DOI:10.1109/JIOT.2021.3138935.png)
摘要
En 中文
The novel multiexit deep neural network (DNN) architectures provide a new optimization solution for efficient model inference in edge systems. Inference of most samples can be completed within the first few layers on an edge device without the need to transmit them to a remote server. This can significantly increase the inference speed and system throughput, which is particularly beneficial to the resource-constrained scenarios. Unfortunately, researchers proposed an inference slow-down attack against this technique, where an external adversary can add imperceptible perturbations on clean samples to invalidate the multiexit mechanism. In this article, we propose a defensive quantization (DefQ) method as the first defense against the inference slow-down attack. It is designed to be lightweight and can be easily implemented in off-the-shelf camera sensors. Particularly, DefQ introduces a novel quantization operation to preprocess the input images. It is capable of removing the perturbations from the malicious samples and preserving the correct inference exit points and prediction accuracy. Meanwhile, it has little impact on the clean samples. Extensive evaluations show that DefQ can effectively defeat the inference slow-down attack and well protect the efficiency of edge systems.
Keyword:
Computational modeling
Servers
Task analysis
Sensors
Quantization (signal)
Sensor systems
Predictive models
Deep learning (DL)
edge computing
inference slow-down
security
期刊
IF:
8.9
论文数:
1.4W
被引数:
7.8W
机构
引用论文
Optimal resource allocation using reinforcement learning for IoT content-centric services针对以内容为中心的IoT服务使用强化学习的最佳资源分配
Different patterns of cortical activity in females and males during spatial long-term memory
NeuroImage
IF0
Study of bi-directional buck-boost converter topologies for application in electrical vehicle motor drives应用于电动汽车电机驱动的双向buck-boost变换器拓扑研究

