The Inherent Adversarial Robustness of Analog In-Memory Computing

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Lammie, Corey, Büchel, Julian, Vasilopoulos, Athanasios, Gallo, Manuel Le, Sebastian, Abu
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910860738297856
author Lammie, Corey
Büchel, Julian
Vasilopoulos, Athanasios
Gallo, Manuel Le
Sebastian, Abu
author_facet Lammie, Corey
Büchel, Julian
Vasilopoulos, Athanasios
Gallo, Manuel Le
Sebastian, Abu
contents A key challenge for Deep Neural Network (DNN) algorithms is their vulnerability to adversarial attacks. Inherently non-deterministic compute substrates, such as those based on Analog In-Memory Computing (AIMC), have been speculated to provide significant adversarial robustness when performing DNN inference. In this paper, we experimentally validate this conjecture for the first time on an AIMC chip based on Phase Change Memory (PCM) devices. We demonstrate higher adversarial robustness against different types of adversarial attacks when implementing an image classification network. Additional robustness is also observed when performing hardware-in-the-loop attacks, for which the attacker is assumed to have full access to the hardware. A careful study of the various noise sources indicate that a combination of stochastic noise sources (both recurrent and non-recurrent) are responsible for the adversarial robustness and that their type and magnitude disproportionately effects this property. Finally, it is demonstrated, via simulations, that when a much larger transformer network is used to implement a Natural Language Processing (NLP) task, additional robustness is still observed.
format Preprint
id arxiv_https___arxiv_org_abs_2411_07023
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle The Inherent Adversarial Robustness of Analog In-Memory Computing
Lammie, Corey
Büchel, Julian
Vasilopoulos, Athanasios
Gallo, Manuel Le
Sebastian, Abu
Emerging Technologies
Cryptography and Security
A key challenge for Deep Neural Network (DNN) algorithms is their vulnerability to adversarial attacks. Inherently non-deterministic compute substrates, such as those based on Analog In-Memory Computing (AIMC), have been speculated to provide significant adversarial robustness when performing DNN inference. In this paper, we experimentally validate this conjecture for the first time on an AIMC chip based on Phase Change Memory (PCM) devices. We demonstrate higher adversarial robustness against different types of adversarial attacks when implementing an image classification network. Additional robustness is also observed when performing hardware-in-the-loop attacks, for which the attacker is assumed to have full access to the hardware. A careful study of the various noise sources indicate that a combination of stochastic noise sources (both recurrent and non-recurrent) are responsible for the adversarial robustness and that their type and magnitude disproportionately effects this property. Finally, it is demonstrated, via simulations, that when a much larger transformer network is used to implement a Natural Language Processing (NLP) task, additional robustness is still observed.
title The Inherent Adversarial Robustness of Analog In-Memory Computing
topic Emerging Technologies
Cryptography and Security
url https://arxiv.org/abs/2411.07023