节点文献

基于PYNQ平台的对抗攻击算法的边缘实现

Edge implementation of counter attack algorithm based on PYNQ platform

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 凌瑾许武军范红禹素萍

【Author】 LING Jin;Xu Wujun;Fan Hong;Yu Suping;College of Information Science and Technology,Donghua University;Engineering Research Center of Digitalized Textiles and Fashion Technology,Ministry of Education;

【机构】 东华大学信息科学与技术学院数字化纺织服装技术教育部工程研究中心

【摘要】 深度神经网络发展至今,在计算机视觉领域占据了重要地位,但是神经网络容易受到人为细微扰动的对抗攻击,研究神经网络的对抗攻击,有利于提出防御策略来提高模型的鲁棒性。而边缘计算平台相较于云计算在数据处理的实时性、数据传输的安全性以及设备能耗性方面具有很大优势。为此在PYNQ_Z2开发板上部署了一种神经网络的攻击模型。通过差分优化算法(DE)策略生成对抗样本图片,攻击神经网络分类算法。首先使用Tensor Flow和Keras框架训练参数并且取得了较好的攻击效果,然后将模型移植到PYNQ_Z2板上。在JupyterNotebook应用上编写算法,将生成的样本图片发送给硬件加速器进行测试。与传统的神经网络实现不同,将调用PYNQ上的硬件库(Overlay)作为分类模型接口,该硬件电路基于FPGA实现,利用FPGA的高并行性和低功耗特点可以显著优化神经网络的运算性能。结果表明,该对抗学习算法可以成功地部署到嵌入式系统中。

【Abstract】 Deep neural network has occupied an important position in the field of computer vision. However, neural networks are vulnerable to adversarial attacks from man-made subtle disturbances. Researching adversarial attacks of neural networks is helpful to propose defense strategies to improve the robustness of the model. Compared with cloud computing, the edge computing platform has great advantages in real-time data processing, data transmission security, and equipment energy consumption. For this reason, a neural network attack model is deployed on the PYNQ_Z2 development board. The differential evolution algorithm(DE) strategy is used to generate adversarial sample images and attack the neural network classification algorithm. First use Tensor Flow and Keras framework to train parameters and achieve good attack results, and then transplant the model to the PYNQ_Z2 board. Write the algorithm on the Jupyter Notebook application and send the generated sample pictures to the hardware accelerator for testing. Different from the traditional neural network implementation, the hardware library(Overlay) on PYNQ is used as the classification model interface. The hardware circuit is implemented based on FPGA, and the high parallelism and low power consumption of FPGA can significantly optimize the computational performance of the neural network. The results show that the adversarial learning algorithm can be successfully deployed in embedded systems.

  • 【会议录名称】 2020中国自动化大会(CAC2020)论文集
  • 【会议名称】2020中国自动化大会(CAC2020)
  • 【会议时间】2020-11-06
  • 【会议地点】中国上海
  • 【分类号】TP183
  • 【主办单位】中国自动化学会
节点文献中: