A Hybrid Quantization Method for Image Recognition Models Based on Bit Flip Attack

By optimizing the objective function through bit-flipping attacks and evolutionary algorithms, the optimal mixed precision quantization strategy for image recognition models is determined, solving the problem of high model storage space and computing resources in existing technologies, and achieving rapid mixed quantization and improved recognition speed.

CN117593631BActive Publication Date: 2026-05-26JILIN UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
JILIN UNIVERSITY
Filing Date
2023-12-18
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing technologies struggle to rapidly achieve hybrid quantization of deep learning models while maintaining image recognition accuracy, and they also require excessive computing resources and storage space.

Method used

The sensitivity of model parameters is recorded layer by layer using a bit-flipping attack method. The objective function is optimized by combining the bit-flipping attack with the evolutionary algorithm to determine the optimal mixed precision quantization strategy. The optimal bit width is set for different layers of the model. The optimal mixed precision quantization strategy is searched through bit-flipping attack and evolutionary algorithm to optimize the storage and recognition speed of the model.

Benefits of technology

It significantly reduces the model's storage space requirements and improves recognition speed while maintaining image recognition accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117593631B_ABST
    Figure CN117593631B_ABST
Patent Text Reader

Abstract

This invention discloses a hybrid quantization method for image recognition models based on bit-flipping attacks, comprising: Step 1, performing initial quantization on the image recognition model to convert it into an initial quantized model; starting from the first layer of the initial quantized model, performing bit-flipping attacks layer by layer, and recording the sensitivity of each layer under attack; forming a sensitivity set of the initial quantized model from the sensitivities of all layers; constructing an optimization objective function and determining optimization constraints, and determining the optimal hybrid precision quantization strategy for the image recognition model based on the optimization objective function and the optimization constraints; Step 3, setting the bit width for storing the parameters of each layer of the image recognition model according to the optimal hybrid precision quantization strategy, thereby obtaining the optimal hybrid quantization model; Step 4, acquiring the image to be recognized and performing image recognition using the optimal hybrid quantization model.
Need to check novelty before this filing date? Find Prior Art