Deep neural network reliability evaluation method, system and device based on analysis and mixed fault injection, and medium
By quantifying the vulnerability factor of deep neural networks based on analysis and mixed fault injection methods, the problem of time-consuming and inability to quantify DNN reliability in the prior art is solved, and efficient and accurate reliability evaluation is achieved.
Patent Information
- Application Number
- CN202510555263.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-08-12
AI Technical Summary
The reliability evaluation methods of existing deep neural networks (DNNs) are time-consuming and cannot provide critical reliability indicators, and cannot quantify the evaluation of system reliability.
Using a method based on analysis and mixed fault injection, we use search for the vulnerability range of the target deep neural network, perform bit flips on each bit of the neuron, calculate the difference in the output results, and calculate the vulnerability factors of the layer, neuron and bits to quantify the reliability of the DNN.
The fine-grained and accurate reliability evaluation of DNN is achieved, and layer vulnerability factors, neuronal vulnerability factors and bit vulnerability factors are provided, which improves the evaluation efficiency and accuracy.
Smart Images

Figure CN120471094A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of machine learning, and in particular to reliability assessment of deep neural networks. Background Art
[0002] Artificial intelligence, especially machine learning, has developed rapidly in recent years, and deep neural networks (DNNs) are one of the most commonly used algorithms for solving various tasks. Due to their excellent properties, they are often used in fields ranging from image classification to natural language processing, and have applications in healthcare, defense, aerospace, finance, drones, and autonomous driving. However, in some fields with high computing requirements, such as self-driving cars, airplanes, or drones, extremely high reliability is required and any unexpected errors must be avoided. As transistor feature sizes gradually shrink, the hardware failure rate in logic and memory circuits continues to rise due to the increased sensitivity of transistors to soft errors, temperature changes, etc., making it necessary and complex to evaluate their hardware reliability before deploying them in critical safety applications.
[0003] To ensure reliable deployment of DNNs, a top priority is to thoroughly evaluate the performance and functionality of pre-trained DNNs under hardware failure conditions. There are three main approaches to achieve this goal:
[0004] 1) Fault injection method, which is to introduce faults into the target system and perform simulation tests;
[0005] 2) Analytical methods, i.e. using mathematical models to analyze the impact of faults;
[0006] 3) Hybrid approach, which combines fault injection with analysis methods.
[0007] In current research, most work relies on fault injection methods, including simulation, emulation, or irradiation experiments, to accurately model faults and evaluate DNN behavior under faulty conditions. However, any fault injection experiment must ensure sufficient statistical confidence, which typically requires a large number of repeated experiments and the configuration of fault locations, requiring powerful computing resources. On the other hand, some research works have proposed analytical methods to address DNN reliability issues, but these methods cannot provide key reliability metrics and cannot quantitatively assess system reliability. Therefore, a time-saving evaluation method that can quantify DNN reliability indicators is urgently needed. Summary of the Invention
[0008] The present invention aims to solve the problems that existing DNN reliability assessment methods are time-consuming and unable to provide key reliability indicators and quantitatively assess system reliability. A deep neural network reliability assessment method, system, device and medium based on analysis and hybrid fault injection are provided.
[0009] A deep neural network reliability assessment method based on analytical and hybrid fault injection, including:
[0010] Searching for vulnerabilities in target deep neural networks;
[0011] Performing bit flipping on each bit of each neuron in the target deep neural network, calculating the difference between the output results of each neuron before and after the bit flipping, and determining whether the difference corresponding to each bit falls within the vulnerability range. If so, classify the bit as vulnerable; otherwise, classify the bit as non-vulnerable;
[0012] According to the classification results, the layer vulnerability factor, neuron vulnerability factor and bit vulnerability factor of the target deep neural network are calculated respectively to evaluate the reliability of the target deep neural network.
[0013] Furthermore, before searching for the vulnerability range of the target deep neural network, the method further includes:
[0014] Adding a perturbation to the output of any neuron in a target deep neural network so that the deep neural network performs forward propagation, wherein the perturbation can cause a critical change in the output result of the target deep neural network;
[0015] When the target deep neural network with added perturbations has less than 50% output gradient of zero, the reliability of the target deep neural network is evaluated.
[0016] Furthermore, the above-mentioned search for the vulnerability range of the target deep neural network includes:
[0017] The maximum negative disturbance and the minimum positive disturbance that can keep the classification result of the target deep neural network unchanged are searched, and the range encircled by the maximum negative disturbance and the minimum positive disturbance is used as the vulnerability range.
[0018] Furthermore, the layer vulnerability factors of the target deep neural network are calculated based on the classification results, including:
[0019] The layer vulnerability factor LVF of the target deep neural network is calculated according to the following formula:
[0020]
[0021] Where N vl is the number of single-layer vulnerable bits in the target deep neural network, N in The number of input data for the target deep neural network, N ln is the number of single-layer neurons in the target deep neural network, l w The length in bytes.
[0022] Furthermore, the neuron vulnerability factors of the target deep neural network are calculated based on the classification results, including:
[0023] The neuron vulnerability factor NVF of the target deep neural network is calculated according to the following formula:
[0024]
[0025] Where N nb is the number of neuron vulnerability bits in the target deep neural network, N in The number of input data for the target deep neural network, l w The length in bytes.
[0026] Furthermore, the bit vulnerability factor of the target deep neural network is calculated based on the classification results, including:
[0027] The bit vulnerability factor BVF of the target deep neural network is calculated according to the following formula:
[0028]
[0029] Where, T vb is the number of times a bit is flipped in all input data and causes misclassification, N in The amount of input data for the target deep neural network.
[0030] Furthermore, the loss function of the above target deep neural network is The expression is:
[0031]
[0032] Where N is the number of iterations, is the error output value of the golden vertex class, Error output value for any other output class.
[0033] A deep neural network reliability assessment system based on analytical and hybrid fault injection, including:
[0034] Search unit: used to search for the vulnerability range of the target deep neural network;
[0035] A classification unit is configured to perform a bit flip on each bit of each neuron in the target deep neural network, calculate the difference between the output results of each neuron before and after the bit flip, and determine whether the difference corresponding to each bit falls within the vulnerability range. If so, the bit is classified as vulnerable; otherwise, the bit is classified as non-vulnerable;
[0036] Evaluation unit: used to calculate the layer vulnerability factor, neuron vulnerability factor and bit vulnerability factor of the target deep neural network according to the classification results, so as to evaluate the reliability of the target deep neural network.
[0037] The above-mentioned deep neural network reliability assessment system based on analysis and hybrid fault injection also includes:
[0038] Perturbation unit: used to add perturbation to the output of any neuron in the target deep neural network, so that the deep neural network performs forward propagation, and the perturbation can cause a critical change in the output result of the target deep neural network;
[0039] Judgment unit: used to evaluate the reliability of the target deep neural network when the gradient of the output results of the target deep neural network with added disturbance is less than 50% of zero.
[0040] Furthermore, the above-mentioned search for the vulnerability range of the target deep neural network includes:
[0041] The maximum negative disturbance and the minimum positive disturbance that can keep the classification result of the target deep neural network unchanged are searched, and the range encircled by the maximum negative disturbance and the minimum positive disturbance is used as the vulnerability range.
[0042] Furthermore, the layer vulnerability factors of the target deep neural network are calculated based on the classification results, including:
[0043] The layer vulnerability factor LVF of the target deep neural network is calculated according to the following formula:
[0044]
[0045] Where N vl is the number of single-layer vulnerable bits in the target deep neural network, N in The number of input data for the target deep neural network, N ln is the number of single-layer neurons in the target deep neural network, l w The length in bytes.
[0046] Furthermore, the neuron vulnerability factors of the target deep neural network are calculated based on the classification results, including:
[0047] The neuron vulnerability factor NVF of the target deep neural network is calculated according to the following formula:
[0048]
[0049] Where N nb is the number of neuron vulnerability bits in the target deep neural network, Nin The number of input data for the target deep neural network, l w The length in bytes.
[0050] Furthermore, the bit vulnerability factor of the target deep neural network is calculated based on the classification results, including:
[0051] The bit vulnerability factor BVF of the target deep neural network is calculated according to the following formula:
[0052]
[0053] Where, T vb is the number of times a bit is flipped in all input data and causes misclassification, N in The amount of input data for the target deep neural network.
[0054] Furthermore, the loss function of the above target deep neural network is The expression is:
[0055]
[0056] Where N is the number of iterations, is the error output value of the golden vertex class, Error output value for any other output class.
[0057] A deep neural network reliability assessment device based on analysis and hybrid fault injection, the deep neural network reliability assessment device based on analysis and hybrid fault injection includes a processor and a memory, the memory stores at least one instruction, and the at least one instruction is loaded and executed by the processor to implement the deep neural network reliability assessment method based on analysis and hybrid fault injection as described above.
[0058] A computer storage medium having at least one instruction stored therein, wherein the at least one instruction is loaded and executed by a processor to implement the above-mentioned deep neural network reliability assessment method based on analysis and hybrid fault injection.
[0059] The present invention evaluates the reliability of deep neural networks by calculating and analyzing their vulnerability factors. First, gradient initialization is performed to screen neurons, and vulnerability analysis is performed on the screened neurons to determine the vulnerability value range. Bit-flip mapping is used to identify vulnerable bits, and the vulnerability factors of quantization layers, neurons, and bits are calculated, providing a fine-grained and accurate reliability assessment for DNNs. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] Figure 1This is a flow chart of the deep neural network reliability assessment method based on analysis and hybrid fault injection according to the present invention;
[0061] Figure 2 Schematic diagram of the correlation between layer vulnerability factor and accuracy loss obtained through layer-level fault injection. DETAILED DESCRIPTION
[0062] The following will be combined with the accompanying drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention. It should be noted that the embodiments of the present invention and the features in the embodiments can be combined with each other in the absence of conflict.
[0063] With the rapid development of artificial intelligence (AI) and machine learning (ML), deep neural networks (DNNs) have been widely used in various safety-critical applications, such as autonomous driving and medical diagnosis. These applications place extremely high demands on system reliability, as even the slightest failure can lead to catastrophic consequences. Hardware reliability assessment is a critical step in the deployment of DNNs. Due to the large number of parameters and computational complexity of DNNs, traditional fault injection (FI) methods face extremely high time complexity when evaluating their reliability. Therefore, new methods are needed to improve evaluation efficiency.
[0064] Existing DNN reliability assessment methods fall into two main categories: FI methods and analytical methods. FI methods, while accurate, are computationally very complex. While analytical methods are computationally efficient, they lack detailed reliability assessment metrics. Hybrid methods also exist, but they are typically specific to certain accelerator architectures.
[0065] Based on this, this embodiment adopts a deep neural network reliability assessment method based on analysis and hybrid fault injection to effectively evaluate the reliability of DNN.
[0066] Specific implementation method 1: refer to Figure 1 and Figure 2 Specifically describing this embodiment, the deep neural network reliability assessment method based on analysis and hybrid fault injection described in this embodiment includes:
[0067] Step 1: Gradient-based initialization: By adding positive or negative sample values to the output of neurons, performing forward propagation of the network, calculating the loss function and evaluating the gradient changes to initialize the weights for vulnerability analysis. The details are as follows:
[0068] A perturbation is added to the output of target neuron k in the DNN. This perturbation causes a critical change in the DNN's prediction results (i.e., at the critical point between change and no change). Forward propagation is performed on the perturbed DNN. If the gradient of more than 50% of the DNN output results is zero, the target neuron k is considered to have no effect on the classification result, and subsequent vulnerability analysis is not performed. Otherwise, a search vulnerability range (e.g., 0) is initialized before subsequent vulnerability analysis is performed.
[0069] Define a loss function The loss function Used to calculate the difference between the output of the DNN after adding the perturbation and the original output.
[0070] The loss function The expression is:
[0071]
[0072] Where N is the number of iterations, is the error output value of the golden vertex class, which refers to the classification result output by the fault-free DNN; Error output value for any other output class.
[0073] Step 2: Neuronal vulnerability analysis.
[0074] For the target neuron k, the non-vulnerability range R VV (1, k, x) means that perturbation of neuron output within this range will not lead to classification errors, and the vulnerability range R NV (1,k,x) means that perturbations on neuron outputs within this range will lead to classification errors.
[0075] For the input data x, find the maximum negative perturbation and minimum positive perturbation that keep the DNN classification result unchanged, and use the range defined by the maximum negative perturbation and the minimum positive perturbation as the vulnerability range.
[0076] A bit flip is performed on each bit of each neuron, and the difference between the target neuron output result after the bit flip and the target neuron output result before the bit flip is calculated. It is determined whether the difference falls into the vulnerability range. If so, the bit is classified as fragile, otherwise it is classified as non-fragile.
[0077] Calculate the vulnerability factor of DNN, including:
[0078] The ratio of vulnerable bits in each layer of the DNN is calculated as the layer vulnerability factor LVF, which is used to indicate the sensitivity of the layer to bit flip faults:
[0079]
[0080] Where Nvl is the number of single-layer vulnerable bits in the target deep neural network, N in The number of input data for the target deep neural network, N ln is the number of single-layer neurons in the target deep neural network, l w The length in bytes.
[0081] The proportion of fragile bits in each neuron is calculated as the neuron vulnerability factor NVF, which is used to indicate the sensitivity of the neuron to bit flip failures:
[0082]
[0083] Where N nb is the number of neuron vulnerability bits in the target deep neural network.
[0084] The ratio of the number of times each bit is marked as fragile across all neurons and input data is calculated as the bit vulnerability factor BVF, which is used to represent the impact of the bit on the reliability of the entire network:
[0085]
[0086] Where, T vb is the number of times a bit is flipped in all input data and causes misclassification.
[0087] The above factors are used to reflect the probability of DNN misclassification when the target element undergoes bit flipping, thereby evaluating the overall reliability of the DNN.
[0088] The deep neural network reliability assessment method based on analysis and hybrid fault injection described in this embodiment is compared with the hierarchical fault injection method, such as Figure 2 Figure 2 shows a schematic diagram of the correlation between the layer vulnerability factor (LVF) and the accuracy loss obtained through layer-level fault injection (FI). The figure plots two curves, representing the correlation between the layer vulnerability factor (LVF) and the accuracy loss when performing fault injection experiments on the same test set and different test sets, respectively. It can be observed that there is a significant positive correlation between the layer vulnerability factor (LVF) and the accuracy loss, regardless of whether the same test set or different test sets are used. This means that layers with higher LVF values tend to result in greater accuracy loss after fault injection, thus verifying the effectiveness of the layer vulnerability factor (LVF) as a network layer vulnerability assessment indicator.
[0089] Specific embodiment 2: The deep neural network reliability assessment system based on analysis and hybrid fault injection described in this embodiment includes:
[0090] Perturbation unit: used to add perturbation to the output of any neuron in the target deep neural network, so that the deep neural network performs forward propagation. The perturbation can cause a critical change in the output result of the target deep neural network.
[0091] Judgment unit: used to evaluate the reliability of the target deep neural network when the gradient of the output results of the target deep neural network with added disturbance is less than 50% of zero.
[0092] A search unit is used to search for the vulnerability range of the target deep neural network. The search unit searches for the maximum negative perturbation and minimum positive perturbation that can leave the classification result of the target deep neural network unchanged, and the range enclosed by the maximum negative perturbation and minimum positive perturbation is used as the vulnerability range.
[0093] A classification unit is configured to perform bit flipping on each bit of each neuron in the target deep neural network, calculate the difference in output results of each neuron before and after the bit flipping, and determine whether the difference corresponding to each bit falls within the vulnerability range. If so, the bit is classified as fragile; otherwise, the bit is classified as non-fragile.
[0094] Evaluation unit: used to calculate the layer vulnerability factor, neuron vulnerability factor and bit vulnerability factor of the target deep neural network according to the classification results, so as to evaluate the reliability of the target deep neural network.
[0095] The layer vulnerability factor LVF of the target deep neural network is calculated according to the following formula:
[0096]
[0097] Where N vl is the number of single-layer vulnerable bits in the target deep neural network, N in The number of input data for the target deep neural network, N ln is the number of single-layer neurons in the target deep neural network, l w The length in bytes.
[0098] The neuron vulnerability factors of the target deep neural network are calculated according to the classification results, including:
[0099] The neuron vulnerability factor NVF of the target deep neural network is calculated according to the following formula:
[0100]
[0101] Where N nb is the number of neuron vulnerability bits in the target deep neural network, N in The number of input data for the target deep neural network, l wThe length in bytes.
[0102] Calculating the bit vulnerability factor of the target deep neural network according to the classification results, including:
[0103] The bit vulnerability factor BVF of the target deep neural network is calculated according to the following formula:
[0104]
[0105] Where, T vb is the number of times a bit is flipped in all input data and causes misclassification, N in The amount of input data for the target deep neural network.
[0106] The loss function of the above target deep neural network The expression is:
[0107]
[0108] Where N is the number of iterations, is the error output value of the golden vertex class, Error output value for any other output class.
[0109] Specific embodiment three: The deep neural network reliability assessment device based on analysis and hybrid fault injection described in this embodiment includes a processor and a memory, and the memory stores at least one instruction, and the at least one instruction is loaded and executed by the processor to implement the deep neural network reliability assessment method based on analysis and hybrid fault injection as described in specific embodiment one.
[0110] Specific embodiment four: A computer storage medium described in this embodiment stores at least one instruction, and the at least one instruction is loaded and executed by a processor to implement the deep neural network reliability assessment method based on analysis and hybrid fault injection as described in specific embodiment one.
[0111] In summary, the present invention adopts the existing Python-based Pytorch software framework and utilizes the deep neural network reliability assessment method based on analysis and hybrid fault injection to perform reliability assessment simulation on the ResNet neural network and obtain its layer vulnerability factor, which provides strong support for improving the robustness of deep learning models.
[0112] Although the present invention is described herein with reference to specific embodiments, it should be understood that these embodiments are merely illustrative of the principles and applications of the invention. It should be understood that many modifications may be made to the illustrative embodiments, and that other arrangements may be devised, without departing from the spirit and scope of the invention as defined by the appended claims. It should be understood that the various dependent claims and features described herein may be combined in ways other than those described in the original claims. It should also be understood that features described in conjunction with individual embodiments may be used in conjunction with other described embodiments.
Claims
1. A deep neural network reliability assessment method based on analysis and hybrid fault injection, characterized by: include: Searching for vulnerabilities in target deep neural networks; Performing bit flipping on each bit of each neuron in the target deep neural network, calculating the difference between the output results of each neuron before and after the bit flipping, and determining whether the difference corresponding to each bit falls within the vulnerability range. If so, classify the bit as vulnerable; otherwise, classify the bit as non-vulnerable; According to the classification results, the layer vulnerability factor, neuron vulnerability factor and bit vulnerability factor of the target deep neural network are calculated respectively to evaluate the reliability of the target deep neural network.
2. The deep neural network reliability assessment method based on analysis and hybrid fault injection according to claim 1 is characterized in that Before searching for the vulnerability scope of the target deep neural network, it also includes: Adding a perturbation to the output of any neuron in a target deep neural network so that the deep neural network performs forward propagation, wherein the perturbation can cause a critical change in the output result of the target deep neural network; When the target deep neural network with added perturbations has less than 50% output gradient of zero, the reliability of the target deep neural network is evaluated.
3. The deep neural network reliability assessment method based on analysis and hybrid fault injection according to claim 2 is characterized in that Searching for a vulnerability range of the target deep neural network includes: The maximum negative disturbance and the minimum positive disturbance that can keep the classification result of the target deep neural network unchanged are searched, and the range encircled by the maximum negative disturbance and the minimum positive disturbance is used as the vulnerability range.
4. The deep neural network reliability assessment method based on analysis and hybrid fault injection according to claim 1, 2 or 3, characterized in that: The step of calculating the layer vulnerability factors of the target deep neural network according to the classification results includes: The layer vulnerability factor LVF of the target deep neural network is calculated according to the following formula: Where N vl is the number of single-layer vulnerable bits in the target deep neural network, N in The number of input data for the target deep neural network, N ln is the number of single-layer neurons in the target deep neural network, l w The length in bytes.
5. The deep neural network reliability assessment method based on analysis and hybrid fault injection according to claim 1, 2 or 3, characterized in that: The step of calculating the neuron vulnerability factors of the target deep neural network according to the classification results includes: The neuron vulnerability factor NVF of the target deep neural network is calculated according to the following formula: Where N nb is the number of neuron vulnerability bits in the target deep neural network, N in The number of input data for the target deep neural network, l w The length in bytes.
6. The deep neural network reliability assessment method based on analysis and hybrid fault injection according to claim 1, 2 or 3, characterized in that: The step of calculating the bit vulnerability factor of the target deep neural network according to the classification results includes: The bit vulnerability factor BVF of the target deep neural network is calculated according to the following formula: Where, T vb is the number of times a bit is flipped in all input data and causes misclassification, N in The amount of input data for the target deep neural network.
7. The deep neural network reliability assessment method based on analysis and hybrid fault injection according to claim 1, 2 or 3, characterized in that: The loss function of the target deep neural network The expression is: Where N is the number of iterations, is the error output value of the golden vertex class, Error output value for any other output class.
8. A deep neural network reliability assessment system based on analytical and hybrid fault injection, characterized by: include: Search unit: used to search for the vulnerability range of the target deep neural network; A classification unit is configured to perform a bit flip on each bit of each neuron in the target deep neural network, calculate the difference between the output results of each neuron before and after the bit flip, and determine whether the difference corresponding to each bit falls within the vulnerability range. If so, the bit is classified as vulnerable; otherwise, the bit is classified as non-vulnerable; Evaluation unit: used to calculate the layer vulnerability factor, neuron vulnerability factor and bit vulnerability factor of the target deep neural network according to the classification results, so as to evaluate the reliability of the target deep neural network.
9. A device for deep neural network reliability assessment based on analytical and hybrid fault injection, characterized in that The deep neural network reliability assessment device based on analysis and hybrid fault injection includes a processor and a memory, wherein the memory stores at least one instruction, and the at least one instruction is loaded and executed by the processor to implement the deep neural network reliability assessment method based on analysis and hybrid fault injection according to any one of claims 1 to 7.
10. A computer storage medium, characterized in that The computer storage medium stores at least one instruction, and the at least one instruction is loaded and executed by the processor to implement the deep neural network reliability assessment method based on analysis and hybrid fault injection as described in any one of claims 1 to 7.