본문

서브메뉴

Integrated AI Security and Efficiency: Trustworthiness, Trojan Detection, and Performance Acceleration
Integrated AI Security and Efficiency: Trustworthiness, Trojan Detection, and Performance ...
Integrated AI Security and Efficiency: Trustworthiness, Trojan Detection, and Performance Acceleration

상세정보

자료유형  
 학위논문 서양
최종처리일시  
20250211152702
ISBN  
9798384104599
DDC  
621.3
저자명  
Zhang, Xinqiao.
서명/저자  
Integrated AI Security and Efficiency: Trustworthiness, Trojan Detection, and Performance Acceleration
발행사항  
[Sl] : University of California, San Diego, 2024
발행사항  
Ann Arbor : ProQuest Dissertations & Theses, 2024
형태사항  
151 p
주기사항  
Source: Dissertations Abstracts International, Volume: 86-03, Section: B.
주기사항  
Advisor: Koushanfar, Farinaz;Huang, Ke.
학위논문주기  
Thesis (Ph.D.)--University of California, San Diego, 2024.
초록/해제  
요약Artificial Intelligence (AI) has been extensively applied across various fields due to its exceptional performance. Deep Neural Networks (DNNs) are a subset of machine learning models inspired by the structure and function of the human brain. They consist of multiple layers of interconnected nodes (neurons) that can learn complex data representations through training on large datasets. However, DNNs are vulnerable to Trojan attacks, especially for constrained, real-time, security-sensitive applications.This thesis focuses on designing DNN algorithms and architectures to enhance their robustness, enabling safer applications. Using different approaches, we effectively advance DNNs' trustworthiness, Trojan detection, and performance acceleration.As AI technology evolves, security concerns are receiving increasing attention. This thesis advances the field by addressing the limitations and concerns of the latest AI technologies through the design of domain-specific DNN algorithms and systems.This dissertation integrates theoretical foundations, domain-specific architecture design, and automated tools to facilitate the co-optimization of deep learning algorithms with the underlying platform while meeting various constraints. The key contributions of this dissertation are as follows:• Proposing DeepTD, the first FPGA-based accelerator architecture for efficient DNN Trojan Detection. DeepTD significantly improves state-of-the-art works regarding both latency and memory efficiency for the same detection threshold. Proof of concept realization demonstrates up to 60x faster detection time than state-of-the-art CPU and GPU realizations.• Devising AdaTest with a Software/Hardware co-design principle and providing an optimized on-chip architecture solution. AdaTest's architecture minimizes the hardware overhead in two ways: (i) Deploying circuit emulation on programmable hardware to accelerate reward evaluation of the test input; (ii) Pipelining each computation stage in AdaTest by automatically constructing auxiliary circuit for test input generation, reward evaluation, and adaptive sampling. We evaluate AdaTest's performance on various HT benchmarks and compare it with two prior works that use logic testing for HT detection. Experimental results show that AdaTest engenders up to two orders of test generation speedup and two orders of test set size reduction compared to the prior works while achieving the same or higher Trojan detection rate.• Developing a lightweight cryptographic protocol explicitly designed to exploit the unique characteristics of Binary Neural Networks(BNNs) and presenting an advanced dynamic exploration of the runtime-accuracy tradeoff of scalable BNNs in a single-shot training process. While previous works trained multiple BNNs with different computational complexities (which is cumbersome due to the slow convergence of BNNs), we trained a single BNN that can perform inference under various computational budgets. Compared to CryptFlow2, the state-of-the-art technique in the oblivious inference of non-binary DNNs, our approach reaches 3x faster inference while keeping the same accuracy. Compared to XONN, the state-of-the-art technique in the oblivious inference of binary networks, we achieve 2x to 12x faster inference while obtaining higher accuracy.• Establishing the first private robustness check that uses high break point rank-based statistics on aggregated model updates. By exploiting randomized clustering, we significantly improve the scalability of our defense without compromising privacy. We leverage the derived statistical bounds in zero-knowledge proofs to detect and remove malicious updates without revealing private user updates. Our novel framework, zPROBE, enables Byzantine resilient and secure federated learning. We show the effectiveness of zPROBE on several computer vision benchmarks. Empirical evaluations demonstrate that zPROBE provides a low-overhead solution to defend against state-of-the-art Byzantine attacks while preserving privacy.
일반주제명  
Computer engineering
일반주제명  
Computer science
일반주제명  
Electrical engineering
키워드  
Hardware acceleration
키워드  
Security
키워드  
Trojan detection
키워드  
Binary Neural Networks
키워드  
Deep Neural Networks
기타저자  
University of California, San Diego Electrical and Computer Engineering (Joint Doctoral with SDSU)
기본자료저록  
Dissertations Abstracts International. 86-03B.
전자적 위치 및 접속  
로그인 후 원문을 볼 수 있습니다.

MARC

 008250123s2024        us                              c    eng  d
■001000017163394
■00520250211152702
■006m          o    d                
■007cr#unu||||||||
■020    ▼a9798384104599
■035    ▼a(MiAaPQ)AAI31488090
■040    ▼aMiAaPQ▼cMiAaPQ
■0820  ▼a621.3
■1001  ▼aZhang,  Xinqiao.
■24510▼aIntegrated  AI  Security  and  Efficiency:  Trustworthiness,  Trojan  Detection,  and  Performance  Acceleration
■260    ▼a[Sl]▼bUniversity  of  California,  San  Diego▼c2024
■260  1▼aAnn  Arbor▼bProQuest  Dissertations  &  Theses▼c2024
■300    ▼a151  p
■500    ▼aSource:  Dissertations  Abstracts  International,  Volume:  86-03,  Section:  B.
■500    ▼aAdvisor:  Koushanfar,  Farinaz;Huang,  Ke.
■5021  ▼aThesis  (Ph.D.)--University  of  California,  San  Diego,  2024.
■520    ▼aArtificial  Intelligence  (AI)  has  been  extensively  applied  across  various  fields  due  to  its  exceptional  performance.  Deep  Neural  Networks  (DNNs)  are  a  subset  of  machine  learning  models  inspired  by  the  structure  and  function  of  the  human  brain.  They  consist  of  multiple  layers  of  interconnected  nodes  (neurons)  that  can  learn  complex  data  representations  through  training  on  large  datasets.  However,  DNNs  are  vulnerable  to  Trojan  attacks,  especially  for  constrained,  real-time,  security-sensitive  applications.This  thesis  focuses  on  designing  DNN  algorithms  and  architectures  to  enhance  their  robustness,  enabling  safer  applications.  Using  different  approaches,  we  effectively  advance  DNNs'  trustworthiness,  Trojan  detection,  and  performance  acceleration.As  AI  technology  evolves,  security  concerns  are  receiving  increasing  attention.  This  thesis  advances  the  field  by  addressing  the  limitations  and  concerns  of  the  latest  AI  technologies  through  the  design  of  domain-specific  DNN  algorithms  and  systems.This  dissertation  integrates  theoretical  foundations,  domain-specific  architecture  design,  and  automated  tools  to  facilitate  the  co-optimization  of  deep  learning  algorithms  with  the  underlying  platform  while  meeting  various  constraints.  The  key  contributions  of  this  dissertation  are  as  follows:•  Proposing  DeepTD,  the  first  FPGA-based  accelerator  architecture  for  efficient  DNN  Trojan  Detection.  DeepTD  significantly  improves  state-of-the-art  works  regarding  both  latency  and  memory  efficiency  for  the  same  detection  threshold.  Proof  of  concept  realization  demonstrates  up  to  60x  faster  detection  time  than  state-of-the-art  CPU  and  GPU  realizations.•  Devising  AdaTest  with  a  Software/Hardware  co-design  principle  and  providing  an  optimized  on-chip  architecture  solution.  AdaTest's  architecture  minimizes  the  hardware  overhead  in  two  ways:  (i)  Deploying  circuit  emulation  on  programmable  hardware  to  accelerate  reward  evaluation  of  the  test  input;  (ii)  Pipelining  each  computation  stage  in  AdaTest  by  automatically  constructing  auxiliary  circuit  for  test  input  generation,  reward  evaluation,  and  adaptive  sampling.  We  evaluate  AdaTest's  performance  on  various  HT  benchmarks  and  compare  it  with  two  prior  works  that  use  logic  testing  for  HT  detection.  Experimental  results  show  that  AdaTest  engenders  up  to  two  orders  of  test  generation  speedup  and  two  orders  of  test  set  size  reduction  compared  to  the  prior  works  while  achieving  the  same  or  higher  Trojan  detection  rate.•  Developing  a  lightweight  cryptographic  protocol  explicitly  designed  to  exploit  the  unique  characteristics  of  Binary  Neural  Networks(BNNs)  and  presenting  an  advanced  dynamic  exploration  of  the  runtime-accuracy  tradeoff  of  scalable  BNNs  in  a  single-shot  training  process.  While  previous  works  trained  multiple  BNNs  with  different  computational  complexities  (which  is  cumbersome  due  to  the  slow  convergence  of  BNNs),  we  trained  a  single  BNN  that  can  perform  inference  under  various  computational  budgets.  Compared  to  CryptFlow2,  the  state-of-the-art  technique  in  the  oblivious  inference  of  non-binary  DNNs,  our  approach  reaches  3x  faster  inference  while  keeping  the  same  accuracy.  Compared  to  XONN,  the  state-of-the-art  technique  in  the  oblivious  inference  of  binary  networks,  we  achieve  2x  to  12x  faster  inference  while  obtaining  higher  accuracy.•  Establishing  the  first  private  robustness  check  that  uses  high  break  point  rank-based  statistics  on  aggregated  model  updates.  By  exploiting  randomized  clustering,  we  significantly  improve  the  scalability  of  our  defense  without  compromising  privacy.  We  leverage  the  derived  statistical  bounds  in  zero-knowledge  proofs  to  detect  and  remove  malicious  updates  without  revealing  private  user  updates.  Our  novel  framework,  zPROBE,  enables  Byzantine  resilient  and  secure  federated  learning.  We  show  the  effectiveness  of  zPROBE  on  several  computer  vision  benchmarks.  Empirical  evaluations  demonstrate  that  zPROBE  provides  a  low-overhead  solution  to  defend  against  state-of-the-art  Byzantine  attacks  while  preserving  privacy.
■590    ▼aSchool  code:  0033.
■650  4▼aComputer  engineering
■650  4▼aComputer  science
■650  4▼aElectrical  engineering
■653    ▼aHardware  acceleration
■653    ▼aSecurity
■653    ▼aTrojan  detection
■653    ▼aBinary  Neural  Networks
■653    ▼aDeep  Neural  Networks
■690    ▼a0464
■690    ▼a0984
■690    ▼a0544
■690    ▼a0800
■71020▼aUniversity  of  California,  San  Diego▼bElectrical  and  Computer  Engineering  (Joint  Doctoral  with  SDSU).
■7730  ▼tDissertations  Abstracts  International▼g86-03B.
■790    ▼a0033
■791    ▼aPh.D.
■792    ▼a2024
■793    ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17163394▼nKERIS▼z이  자료의  원문은  한국교육학술정보원에서  제공합니다.

미리보기

내보내기

chatGPT토론

Ai 추천 관련 도서


    신착도서 더보기
    최근 3년간 통계입니다.

    소장정보

    • 예약
    • 소재불명신고
    • 나의폴더
    • 우선정리요청
    • 비도서대출신청
    • 야간 도서대출신청
    소장자료
    등록번호 청구기호 소장처 대출가능여부 대출정보
    TF12220 전자도서 대출가능 마이폴더 부재도서신고 비도서대출신청 야간 도서대출신청

    * 대출중인 자료에 한하여 예약이 가능합니다. 예약을 원하시면 예약버튼을 클릭하십시오.

    해당 도서를 다른 이용자가 함께 대출한 도서

    관련 인기도서

    로그인 후 이용 가능합니다.