about
Hardware Accelerator for Adversarial Attacks on Deep Learning Neural Networks (arxiv.org)
48 points by godelmachine on Aug 9, 2020 | hide | past | pdf | 5 comments on HN

In plain words: Tiny image tweaks humans can't see can fool a neural network, and the software that makes them is slow. This chip uses a grid of tiny resistors that hold values to make those tweaks faster and with less energy than a regular processor.

Abstract

Recent studies identify that Deep learning Neural Networks (DNNs) are vulnerable to subtle perturbations, which are not perceptible to human visual system but can fool the DNN models and lead to wrong outputs. A class of adversarial attack network algorithms has been proposed to generate robust physical perturbations under different circumstances. These algorithms are the first efforts to move forward secure deep learning by providing an avenue to train future defense networks, however, the intrinsic complexity of them prevents their broader usage. In this paper, we propose the first hardware accelerator for adversarial attacks based on memristor crossbar arrays. Our design significantly improves the throughput of a visual adversarial perturbation system, which can further improve the robustness and security of future deep learning systems. Based on the algorithm uniqueness, we propose four implementations for the adversarial attack accelerator ($A^3$) to improve the throughput, energy efficiency, and computational efficiency.

Haoqiang Guo, Lu Peng, Jian Zhang, Fang Qi, Lide Duan
arXiv:2008.01219 · eess.SP, cs.AR, cs.LG · submitted Aug 3, 2020
abstract · pdf · html · IGSC'2019 (https://shirazi21.wixsite.com/igsc2019archive) Best paper award

add comment on HN

You can attack deep learning networks?
Yes: you can (for example) confuse a vision algorithm into thinking an image of a turtle is a rifle https://mashable.com/2017/11/02/mit-researchers-fool-google-...
Yeah, many ways. Besides what the article describes there are at least 5-10 known attacks at the moment.
By “attack” the authors mean figuring out ways to trick the network into classifying things incorrectly. For example, you might attack a network that recognizes faces by determining certain inputs that still are recognizable as faces to a human, but not to the network.
A practical example of this is getting ads in banned ad categories (drugs, sex, etc.) around google or facebooks ad filters