Skip to main content

Showing 1–3 of 3 results for author: Barber, K

  1. arXiv:2208.00498  [pdf, other

    cs.CR cs.AR cs.LG

    DNNShield: Dynamic Randomized Model Sparsification, A Defense Against Adversarial Machine Learning

    Authors: Mohammad Hossein Samavatian, Saikat Majumdar, Kristin Barber, Radu Teodorescu

    Abstract: DNNs are known to be vulnerable to so-called adversarial attacks that manipulate inputs to cause incorrect results that can be beneficial to an attacker or damaging to the victim. Recent works have proposed approximate computation as a defense mechanism against machine learning attacks. We show that these approaches, while successful for a range of inputs, are insufficient to address stronger, hig… ▽ More

    Submitted 31 July, 2022; originally announced August 2022.

  2. Using Undervolting as an On-Device Defense Against Adversarial Machine Learning Attacks

    Authors: Saikat Majumdar, Mohammad Hossein Samavatian, Kristin Barber, Radu Teodorescu

    Abstract: Deep neural network (DNN) classifiers are powerful tools that drive a broad spectrum of important applications, from image recognition to autonomous vehicles. Unfortunately, DNNs are known to be vulnerable to adversarial attacks that affect virtually all state-of-the-art models. These attacks make small imperceptible modifications to inputs that are sufficient to induce the DNNs to produce the wro… ▽ More

    Submitted 6 August, 2021; v1 submitted 20 July, 2021; originally announced July 2021.

    Journal ref: 2021 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)

  3. arXiv:2106.05825  [pdf, other

    cs.CR cs.AR cs.LG

    HASI: Hardware-Accelerated Stochastic Inference, A Defense Against Adversarial Machine Learning Attacks

    Authors: Mohammad Hossein Samavatian, Saikat Majumdar, Kristin Barber, Radu Teodorescu

    Abstract: Deep Neural Networks (DNNs) are employed in an increasing number of applications, some of which are safety critical. Unfortunately, DNNs are known to be vulnerable to so-called adversarial attacks that manipulate inputs to cause incorrect results that can be beneficial to an attacker or damaging to the victim. Multiple defenses have been proposed to increase the robustness of DNNs. In general, the… ▽ More

    Submitted 6 August, 2021; v1 submitted 9 June, 2021; originally announced June 2021.

    Journal ref: Secure and Private Systems for Machine Learning Workshop 2021