To compress or not to compress: Understanding the Interactions between Adversarial Attacks and Neural Network Compression
arXiv:1810.00208
Abstract
As deep neural networks (DNNs) become widely used, pruned and quantised models are becoming ubiquitous on edge devices; such compressed DNNs are popular for lowering computational requirements. Meanwhile, recent studies show that adversarial samples can be effective at making DNNs misclassify. We, therefore, investigate the extent to which adversarial samples are transferable between uncompressed and compressed DNNs. We find that adversarial samples remain transferable for both pruned and quantised models. For pruning, the adversarial samples generated from heavily pruned models remain effective on uncompressed models. For quantisation, we find the transferability of adversarial samples is highly sensitive to integer precision.
Presented at SysML 2019
References in corpus (6)
- Binarized Neural Networks: Training Deep Neural Networks with Weights and Activations Constrained to +1 or -1
- Bidirectional Attention Flow for Machine Comprehension
- Quantized Neural Networks: Training Neural Networks with Low Precision Weights and Activations
- Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples
- Rethinking the Value of Network Pruning
- The Space of Transferable Adversarial Examples