Noise Switches for Adversarial Training Robustness

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Machine learning systems are vulnerable to adversarial training attacks, which trick the models into accepting or rejecting unintended inputs by adapting to malicious data, lacking robustness against input variations.

Innovation Solution

Incorporating noise switches on wordlines in an in-memory machine learning system with static random-access memory (SRAM) cells to add noise proportional to signal magnitude, training neural networks with noise-applied data to generate classifiers robust against adversarial attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If adversarial training data is used to train machine learning models, then the models can handle malicious inputs, but the models become less accurate for expected inputs and adapt to non-representative data

Engineering Contradiction:
Improverobustness against adversarial attacksVSAvoidclassification accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies preliminary action by adding noise to training data before the model training process. Noise switches are integrated into the training pipeline to corrupt training inputs with adversarial noise, preparing the model in advance to handle malicious inputs during deployment without sacrificing accuracy on clean data

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs parameter changes by dynamically adjusting noise characteristics (magnitude, type, distribution) through the noise switches during training. This allows the system to modify training conditions to optimize both robustness and accuracy, changing the noise parameters based on the specific adversarial threat model being addressed

Inventive Principle:
Principle #35Parameter changes

2Reliability

If noise is added to training data to improve robustness, then the model becomes more resistant to adversarial attacks, but the training process becomes more complex

Engineering Contradiction:
Improverobustness against adversarial attacksVSAvoidtraining system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The noise switches are designed to be self-configuring components that automatically generate and apply appropriate noise patterns without requiring complex external control systems. The switches self-adapt to the training data characteristics and adversarial threat model, reducing the overall system complexity while maintaining robustness training effectiveness

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The noise switch architecture is designed as a universal component that can handle multiple types of adversarial noise and be applied across different machine learning models and data types. This multi-functional design reduces training system complexity by providing a single versatile noise injection mechanism rather than requiring separate systems for different adversarial scenarios

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11586912B2Integrated noise generation for adversarial training
Publication Date: 2023.02.21 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11586912B2 patent drawing
  • US11586912B2 patent drawing
  • US11586912B2 patent drawing

AI summary

Methods, systems, and circuits for training a neural network include applying noise to a set of training data across wordlines using a respective noise switch on each wordline. A neural network is trained using the noise-applied training data to generate a classifier that is robust against adversarial training.