Deep Neural Networks (DNNs) have gained widespread adoption, but they also exhibit post-deployment failures that pose risks to property and life. Consequently, enhancing DNN robustness in safety-critical areas is crucial. This paper improves the robustness of DNN models against failures that may arise during either design time or run time. For design failures, we introduce TestRank, an efficient method for identifying DNN design issues. Constrained by test resources, TestRank selects high-quality test cases leveraging intrinsic and contextual attributes of test samples. HybridRepair then offers effective failure repair by selectively annotating failure regions and utilizing semi-supervised learning techniques. To counteract run-time fault injection attacks, we propose D2NN and DeepDyve, which introduce the dual modular redundancy concept to models for protection at the neuron and system levels, respectively. This delicate redundancy achieves lightweight protection for DNN-based systems. Evaluation performed on various image classification datasets demonstrates the effectiveness of our approaches.
Paper
Full text
Towards Robust Deep Neural Networks Against Design-Time and Run-Time Failures
OpenAlex · Adversarial Robustness in Machine Learning · 2023
Abstract
Deep Neural Networks (DNNs) have gained widespread adoption, but they also exhibit post-deployment failures that pose risks to property and life. Consequently, enhancing DNN robustness in safety-critical areas is crucial. This paper improves the robustness of DNN models against failures that may arise during either design time or run time. For design failures, we introduce TestRank, an efficient method for identifying DNN design issues. Constrained by test resources, TestRank selects high-quality test cases leveraging intrinsic and contextual attributes of test samples. HybridRepair then offers effective failure repair by selectively annotating failure regions and utilizing semi-supervised learning techniques. To counteract run-time fault injection attacks, we propose D2NN and DeepDyve, which introduce the dual modular redundancy concept to models for protection at the neuron and system levels, respectively. This delicate redundancy achieves lightweight protection for DNN-based systems. Evaluation performed on various image classification datasets demonstrates the effectiveness of our approaches.