簡易檢索 / 詳目顯示

研究生: 王琦凱
Wang, Chi-Kai
論文名稱: 以硬體加速之符號區間方法分析神經網路的局部穩定性
Local Robustness Analysis on Neural Network with Symbolic Interval Analysis by Hardware Acceleration Method
指導教授: 陳盈如
Chen, Yean-Ru
學位類別: 碩士
Master
系所名稱: 電機資訊學院 - 電機工程學系
Department of Electrical Engineering
論文出版年: 2021
畢業學年度: 109
語文別: 中文
論文頁數: 59
中文關鍵詞: 符號區間分析 、局部穩定性 、安全準則 、硬體實作
外文關鍵詞: Symbolic interval analysis, Local robustness, Safety property, Hardware implementation
相關次數: 點閱:194  下載:1 
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 最近,機器學習的攻擊和擾動越來越嚴重。因此,機器學習的風險評估越來越 流行,因此相關的驗證算法也越來越多。我們專注於正式檢查神經元網絡的局部 穩定性(local robustness),它可以評估所有可能的情況。在調查過程中,我們發現 ReluVal 適合用硬體實現。此外,ReluVal 是一種健全性和完整性算法,可以讓我們 準確地檢查安全性。由於在ReluVal 中實現了眾多的加法和乘法運算,因此我們使用 硬件架構來加快計算時間。
    在這篇論文中,我們添加了兩個在ReluVal 中沒有實現的額外函數,那就是卷積和最大池化(convolution 和maxpooling),並在硬體中實現了符號區間操作的過程。此外,我們將整個工作流程整合到軟體中並自動執行。最後,我們將用實驗結果來解釋不同數據結構和策略的效果。在一些圖片中,我們可以得到比DeepPoly 和RefinePoly 相對更確定的結果。此外,在大多數測試數據中,我們的執行時間都比他們快。

    Recently, the attack and perturbation of machine learning is getting worse. There-fore, the risk assessment of machine learning is more popular so that there are more and more related verification algorithms. We are focus on checking the local robustness (safety property) of neuron network formally, it can evaluate the all possible situations. During the survey, we find that ReluVal is suitable to implement with hardware. In ad-dition, ReluVal is a soundness and completeness algorithm which make us to check the safety property exactly. Since the numerous add and multiply operation are implemented in the ReluVal , we use hardware architecture to speed up the calculation time.
    In this work, we add two extra functions (i.e. convolution and maxpooling) which are not implemented in ReluVal and implement the process of symbolic interval oper-ation in hardware. Besides, we integrate the whole workflow in the software. Finally, we will use the experimental result to explain the effect of different data structure and policy. In the some pictures, we can receive the relatively more conclusive results than DeepP oly and RefineP oly . Besides, our execution times are faster than them in the most of test data.

    摘要i 英文延伸摘要ii 誌謝 vi 目錄 vii 表格 viii 圖片 ix 第一章 緒論 1 1.1 研究背景 1 1.1.1 L infinity norm 和Epsilon 1 1.1.2 深度卷積神經網絡(CNN) 3 1.1.3 區間分析 8 1.2 研究動機 10 1.3 論文貢獻 13 1.4 論文組織 14 第二章 文獻探討 15 2.1 攻擊方法 15 2.2 安全驗證演算法 16 第三章 研究方法 21 3.1 演算法 21 3.1.1 符號(symbolic) 區間運算 23 3.1.2 安全準則檢查 31 3.1.3 尋找反例 32 3.1.4 切割區間 33 3.2 硬體實現 35 3.2.1 convolution 和maxpooling 模組 36 3.2.2 fully-connected 和relu 模組 42 3.2.3 整合 47 第四章 實驗結果 49 4.1 合成結果 49 4.2 實驗數據 50 第五章 結論 57 參考文獻 58

    [1] Asifullah Khan, Anabia Sohail, Umme Zahoora, and Aqsa Saeed Qureshi. A survey of the recent architectures of deep convolutional neural networks. Artificial Intelligence Review, 53:5455–5516, 12 2020.
    [2] Timon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov, Swarat Chaudhuri, and Martin Vechev. Ai 2 : Safety and robustness certification of neural networks with abstract interpretation.
    [3] Abien Fred Agarap. Deep learning using rectified linear units (relu). 3 2018.
    [4] Yann LeCun and Corinna Cortes. MNIST handwritten digit database. 2010.
    [5] Mykel J Kochenderfer, Jessica E Holland, and James P Chryssanthacopoulos. Next-generation airborne collision avoidance system.
    [6] Sorin Grigorescu, Bogdan Trasnea, Tiberiu Cocias, and Gigel Macesanu. A survey of deep learning techniques for autonomous driving. 10 2019.
    [7] Université Tahri, Mohammed Béchar, Saliha Benkerzaz, Youssef Elmir, and Abdeslam Dennai. A study on automatic speech recognition human computer interaction ( hci) view project multi biometric recognition view project saliha benkerzaz abdeslem dennai a study on automatic speech recognition. Journal of Information Technology Review, 10, 2019.
    [8] Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. Explaining and harnessing adversarial examples. 12 2014.
    [9] Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and
    Adrian Vladu. Towards deep learning models resistant to adversarial attacks. 6 2017.
    [10] Changliu Liu, Christopher Lazarus, Clark Barrett, and Mykel J Kochenderfer. Algorithms for verifying deep neural networks.
    [11] Gagandeep Singh, Timon Gehr, Markus Püschel, and Martin Vechev. An abstract domain for certifying neural networks. Proceedings of the ACM on Programming Languages, 3:1–30, 1 2019.
    [12] Shiqi Wang, Kexin Pei, Justin Whitehouse, Junfeng Yang, and Suman Jana. Formal security analysis of neural networks using symbolic intervals. 4 2018.
    [13] Gagandeep Singh, Rupanshu Ganvir, Markus Püschel, and Martin Vechev. Beyond the single neuron convex barrier for neural network certification, 2019.
    [14] Guy Katz, Clark Barrett, David Dill, Kyle Julian, and Mykel Kochenderfer. Reluplex: An efficient smt solver for verifying deep neural networks. 2 2017.
    [15] Mohammad Rashid Hussain and Mohammad Equebal Hussain. Simplex method to optimize mathematical manipulation cloud computing view project wireless mesh network based on design and implementation view project, 2019.

    下載圖示
    2026-09-17公開
    QR CODE