{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,7]],"date-time":"2026-08-07T04:33:11Z","timestamp":1786077191721,"version":"3.56.0"},"reference-count":62,"publisher":"MDPI AG","issue":"15","license":[{"start":{"date-parts":[[2022,8,7]],"date-time":"2022-08-07T00:00:00Z","timestamp":1659830400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Research Foundation of Korea (NRF)","award":["NRF-2020R1G1A1012170"],"award-info":[{"award-number":["NRF-2020R1G1A1012170"]}]},{"DOI":"10.13039\/501100003725","name":"Korea government (MSIT)","doi-asserted-by":"publisher","award":["NRF-2020R1G1A1012170"],"award-info":[{"award-number":["NRF-2020R1G1A1012170"]}],"id":[{"id":"10.13039\/501100003725","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The development of deep learning technology has resulted in great contributions in many artificial intelligence services, but adversarial attack techniques on deep learning models are also becoming more diverse and sophisticated. IoT edge devices take cloud-independent on-device DNN (deep neural network) processing technology to exhibit a fast response time. However, if the computational complexity of the denoizer for adversarial noises is high, or if a single embedded GPU is shared by multiple DNN models, adversarial defense at the on-device level is bound to represent a long latency. To solve this problem, eDenoizer is proposed in this paper. First, it applies Tucker decomposition to reduce the computational amount required for convolutional kernel tensors in the denoizer. Second, eDenoizer effectively orchestrates both the denoizer and the model defended by the denoizer simultaneously. In addition, the priority of the CPU side can be projected onto the GPU which is completely priority-agnostic, so that the delay can be minimized when the denoizer and the defense target model are assigned a high priority. As a result of confirming through extensive experiments, the reduction of classification accuracy was very marginal, up to 1.78%, and the inference speed accompanied by adversarial defense was improved up to 51.72%.<\/jats:p>","DOI":"10.3390\/s22155896","type":"journal-article","created":{"date-parts":[[2022,8,9]],"date-time":"2022-08-09T04:16:55Z","timestamp":1660018615000},"page":"5896","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Time-Constrained Adversarial Defense in IoT Edge Devices through Kernel Tensor Decomposition and Multi-DNN Scheduling"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4254-4009","authenticated-orcid":false,"given":"Myungsun","family":"Kim","sequence":"first","affiliation":[{"name":"Department of Applied Artificial Intelligence, Hansung University, Seoul 02876, Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8733-9415","authenticated-orcid":false,"given":"Sanghyun","family":"Joo","sequence":"additional","affiliation":[{"name":"Department of IT Convergence Engineering, Hansung University, Seoul 02876, Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,8,7]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Singh, A., Sengupta, S., and Lakshminarayanan, V. (2020). Explainable Deep Learning Models in Medical Image Analysis. J. Imaging, 6.","DOI":"10.3390\/jimaging6060052"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"100944","DOI":"10.1016\/j.aei.2019.100944","article-title":"Times-series data augmentation and deep learning for construction equipment activity recognition","volume":"42","author":"Rashid","year":"2019","journal-title":"Adv. Eng. Inform."},{"key":"ref_3","unstructured":"Bojarski, M., Testa, D.D., Dworakowski, D., Firner, B., Flepp, B., Goyal, P., Jackel, L.D., Monfort, M., and Muller, U. (2016). End to End Learning for Self-Driving Cars. arXiv."},{"key":"ref_4","unstructured":"Zhu, H. (2022). MetaAID: A Flexible Framework for Developing Metaverse Applications via AI Technology and Human Editing. arXiv."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","article-title":"One Pixel Attack for Fooling Deep Neural Networks","volume":"23","author":"Su","year":"2019","journal-title":"IEEE Trans. Evol. Comput."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Carlini, N., and Wagner, D. (2017, January 22\u201326). Towards Evaluating the Robustness of Neural Networks. Proceedings of the 2017 IEEE Symposium on Security and Privacy (sp), San Jose, CA, USA.","DOI":"10.1109\/SP.2017.49"},{"key":"ref_7","first-page":"10932","article-title":"Improving Black-box Adversarial Attacks with a Transfer-based Prior","volume":"32","author":"Cheng","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Liao, F., Liang, M., Dong, Y., Pang, T., Hu, X., and Zhu, J. (2018, January 18\u201323). Defense Against Adversarial Attacks Using High-Level Representation Guided Denoiser. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref_9","unstructured":"NVIDIA (2022, June 10). Jetson AGX Xavier Developer Kit|NVIDIA Developer. Available online: https:\/\/developer.nvidia.com\/embedded\/jetson-agx-xavier-developer-kit."},{"key":"ref_10","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. (2013). Intriguing properties of neural networks. arXiv."},{"key":"ref_11","unstructured":"Goodfellow, I., Shiens, C., and Szegedy, C. (2014). Explaining and Harnessing Adversarial Examples. arXiv."},{"key":"ref_12","unstructured":"Kurakin, A., Goodfellow, I., and Bengio, S. (2016). Adversarial Machine Learning at Scale. arXiv."},{"key":"ref_13","unstructured":"Papernot, N., McDaniel, P., and Goodfellow, I. (2016). Transferability in Machine Learning: From Phenomena to Black-Box Attacks using Adversarial Samples. arXiv."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z.B., and Swami, A. (2017, January 2\u20136). Practical Black-Box Attacks against Machine Learning. Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, Abu Dhabi, United Arab Emirates.","DOI":"10.1145\/3052973.3053009"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Deng, J., Dong, J., Socher, R., Li, L., Li, K., and Li, F.-F. (2009, January 20\u201325). Imagenet: A large-scale hierarchical image database. Proceedings of the 2009 IEEE Conference on Computer Vision and Pattern Recognition, Miami, FL, USA.","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Vincent, P., Larochelle, H., Bengio, Y., and Manzagol, P.A. (2008, January 5\u20139). Extracting and composing robust features with denoizing autoencoders. Proceedings of the 25th International Conference on Machine Learning, Helsinki, Finland.","DOI":"10.1145\/1390156.1390294"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Ronneberger, O., Fischer, P., and Brox, T. (2015, January 5\u20139). U-Net: Convolutional Networks for Biomedical Image Segmentation. Proceedings of the International Conference on Medical Image Computing and Computer-Assisted Intervention, Munich, Germany.","DOI":"10.1007\/978-3-319-24574-4_28"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"279","DOI":"10.1007\/BF02289464","article-title":"Some mathematical notes on three-mode factor analysis","volume":"31","author":"Tucker","year":"1966","journal-title":"Psychometrika"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Kim, Y.D., Park, E., Yoo, S., Choi, T., Yang, L., and Shin, D. (2015). Compression of Deep Convolutional Neural Networks for Fast and Low Power Mobile Applications. arXiv.","DOI":"10.14257\/astl.2016.140.36"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Szegedy, C., Vanhoucke, V., Ioffe, S., Shlens, J., and Wojna, Z. (2016, January 27\u201330). Rethinking the Inception Architecture for Computer Vision. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 27\u201330). Deep Residual Learning for Image Recognition. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref_22","unstructured":"Simonyan, K., and Zisserman, A. (2014). Very Deep Convolutional Networks for Large-Scale Image Recognition. arXiv."},{"key":"ref_23","unstructured":"NVIDIA (2022, June 10). Hareness AI at the Edge with the Hetson TX2 Developer Kit|NVIDIA Developer. Available online: https:\/\/developer.nvidia.com\/embedded\/jetson-tx2-developer-kit."},{"key":"ref_24","unstructured":"NVIDIA (2022, June 10). CUDA Toolkit\u2014Free Tools and Training|NVIDIA Developer. Available online: https:\/\/developer.nvidia.com\/cuda-toolkit."},{"key":"ref_25","unstructured":"NVIDIA (2022, June 10). CUDA Deep Neural Network(cuDNN)|NVIDIA Developer. Available online: https:\/\/developer.nvidia.com\/cudnn."},{"key":"ref_26","unstructured":"Harris, M. (2022, June 10). GPU Pro Tip: CUDA 7 Streams Simplify Concurrency|NVIDIA Technical Blog. Available online: https:\/\/developer.nvidia.com\/blog\/gpu-pro-tip-cuda-7-streams-simplify-concurrency."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"85403","DOI":"10.1109\/ACCESS.2021.3088861","article-title":"ODMDEF: On-Device Multi-DNN Execution Framework Utilizing Adaptive Layer-Allocation on General Purpose Cores and Accelerators","volume":"9","author":"Lim","year":"2021","journal-title":"IEEE Access"},{"key":"ref_28","unstructured":"(2022, June 10). PyTorch. Available online: https:\/\/pytorch.org."},{"key":"ref_29","unstructured":"(2022, June 10). TensorFlow. Available online: https:\/\/www.tensorflow.org."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Xiang, Y., and Kim, H. (2019, January 3). Pipelined Data-Parallel CPU\/GPU Scheduling for Multi-DNN Real-Time Inference. Proceedings of the 2019 IEEE Real-Time Systems Symposium (RTSS), Hong Kong SAR, China.","DOI":"10.1109\/RTSS46320.2019.00042"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"1347","DOI":"10.1109\/TCOM.1987.1096719","article-title":"Input Versus Output Queueing on a Space-Division Packet Switch","volume":"35","author":"Karol","year":"1987","journal-title":"IEEE Trans. Commun."},{"key":"ref_32","unstructured":"NVIDIA (2022, June 10). CUDA Streams: Best Practices and Common Pitfalls. Available online: https:\/\/on-demand.gputechconf.com\/gtc\/2014\/presentations\/S4158-cuda-streams-best-practices-common-pitfalls.pdf."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"83","DOI":"10.1109\/LES.2021.3129769","article-title":"Guaranteeing That Multilevel Prioritized DNN Models on an Embedded GPU Have Inference Performance Proportional to Respective Priorities","volume":"14","author":"Kim","year":"2021","journal-title":"IEEE Embed. Syst. Lett."},{"key":"ref_34","unstructured":"Ajitsaria, A. (2022, June 10). What Is the Python Global Interpreter Lock (GIL)?. Available online: https:\/\/realpython.com\/python-gil."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Szegedy, C., Ioffe, S., Vanhoucke, V., and Alemi, A.A. (2017, January 4\u20139). Inception-v4, Inception-ResNet and the Impact of Residual Connections on Learning. Proceedings of the Thirty-First AAAI Conference on Artificial Intelligence, San Francisco, CA, USA.","DOI":"10.1609\/aaai.v31i1.11231"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 8\u201316). Identity Mappings in Deep Residual Networks. Proceedings of the Fourteenth European Conference on Computer Vision, Amsterdam, The Netherlands.","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"ref_37","unstructured":"Tram\u00e8r, F., Kurakin, A., Papernot, N., Goodfellow, I., Boneh, D., and McDaniel, P. (2017). Ensemble Adversarial Training: Attacks and Defenses. arXiv."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Radosavovic, I., Kosaraju, R.P., Girshick, R., He, K., and Dollar, P. (2020, January 13\u201319). Designing Network Design Spaces. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.01044"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Xie, S., Girshick, R., Dollar, P., Tu, Z., and He, K. (2017, January 21\u201326). Aggregated Residual Transformations for Deep Neural Networks. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Honolulu, HI, USA.","DOI":"10.1109\/CVPR.2017.634"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Zagoruyko, S., and Komodakis, N. (2016). Wide Residual Networks. arXiv.","DOI":"10.5244\/C.30.87"},{"key":"ref_41","unstructured":"Howard, A.G., Zhu, M., Chen, B., Kalenichenko, D., Wang, W., Weyand, T., Andreetto, M., and Adam, H. (2017). MobileNets: Efficient Convolutional Neural Networks for Mobile Vision Applications. arXiv."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Yan, M., Zhao, M., Xu, Z., Zhang, Q., Wang, G., and Su, Z. (2019, January 27\u201328). VarGFaceNet: An Efficient Variable Group Convolutional Neural Network for Lightweight Face Recognition. Proceedings of the IEEE\/CVF International Conference on Computer Vision Workshops, Seoul, Korea.","DOI":"10.1109\/ICCVW.2019.00323"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Huynh, L.N., Lee, Y., and Balan, R.K. (2017, January 19\u201323). DeepMon: Mobile GPU-based Deep Learning Framework for Continuous Vision Applications. Proceedings of the 15th Annual International Conference on Mobile Systems, Applications, and Services, Niagara Falls, NY, USA.","DOI":"10.1145\/3081333.3081360"},{"key":"ref_44","unstructured":"Han, S., Mao, H., and Dally, W.J. (2015). Deep Compression: Compressing Deep Neural Networks with Pruning, Trained Quantization and Huffman Coding. arXiv."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"243","DOI":"10.1145\/3007787.3001163","article-title":"EIE: Efficient inference engine on compressed deep neural network","volume":"44","author":"Han","year":"2016","journal-title":"ACM SIGARCH Comput. Archit. News"},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Jacob, B., Kligys, S., Chen, B., Zhu, M., Tang, M., Howard, A., Adam, H., and Kalenichenko, D. (2018, January 18\u201323). Quantization and Training of Neural Networks for Efficient Integer-Arithmetic-Only Inference. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00286"},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Panda, P. (2020). QUANOS: Adversarial noise sensitivity driven hybrid quantization of neural networks. arXiv.","DOI":"10.1145\/3370748.3406585"},{"key":"ref_48","unstructured":"(2022, June 10). NVIDIA Deep Learning Accelerator. Available online: http:\/\/nvdla.org."},{"key":"ref_49","unstructured":"(2022, June 10). Tensor Cores|NVIDIA Developer. Available online: https:\/\/developer.nvidia.com\/tensor-cores."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"269","DOI":"10.1145\/2654822.2541967","article-title":"Diannao: A small-footprint high-throughput accelerator for ubiquitous machine-learning","volume":"42","author":"Chen","year":"2014","journal-title":"ACM SIGARCH Comput. Archit. News"},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Chen, Y., Luo, T., Liu, S., Zhang, S., He, L., Wang, J., Li, L., Chen, T., Xu, Z., and Sun, N. (2014, January 13\u201317). DaDianNao: A Machine-Learning Supercomputer. Proceedings of the 2014 47th Annual IEEE\/ACM International Symposium on Microarchitecture, Cambridge, UK.","DOI":"10.1109\/MICRO.2014.58"},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Du, Z., Fasthuber, R., Chen, T., Ienne, P., Li, L., Luo, T., Feng, X., Chen, Y., and Temam, O. (2015, January 13\u201317). ShiDianNao: Shifting vision processing closer to the sensor. Proceedings of the 42nd Annual International Symposium on Computer Architecture, Portland, OR, USA.","DOI":"10.1145\/2749469.2750389"},{"key":"ref_53","doi-asserted-by":"crossref","first-page":"127","DOI":"10.1109\/JSSC.2016.2616357","article-title":"Eyeriss: An Energy-Efficient Reconfigurable Accelerator for Deep Convolutional Neural Networks","volume":"52","author":"Chen","year":"2016","journal-title":"IEEE J.-Solid-State Circuits"},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Wang, x., Hou, R., Zhao, B., Yuan, F., Zhang, J., Meng, D., and Qian, X. (2020, January 16\u201320). DNNGuard: An Elastic Heterogeneous DNN Accelerator Architecture against Adversarial Attacks. Proceedings of the 25th International Conference on Architectural Support for Programming Languages and Operating Systems, Lausanne, Switzerland.","DOI":"10.1145\/3373376.3378532"},{"key":"ref_55","unstructured":"Waterman, A., Lee, Y., Patterson, D.A., and Asanovi, K. (2017). The Risc-V Instruction Set Manual. Volume 1: User-Level Isa, Version 2.0, Cs Division, EECS Department, University of California."},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"Ma, S., Liu, Y., Tao, G., Lee, W.C., and Zhang, X. (2019, January 24\u201327). NIC: Detecting Adversarial Samples with Neural Network Invariant Checking. Proceedings of the 26th Network and Distributed System Security Symposium (NDSS 2019), San Diego, CA, USA.","DOI":"10.14722\/ndss.2019.23415"},{"key":"ref_57","doi-asserted-by":"crossref","unstructured":"Huynh, L.N., Balan, R.K., and Lee, Y. (2016, January 30). DeepSense: A GPU-based Deep Convolutional Neural Network Framework on Commodity Mobile Devices. Proceedings of the 2016 Workshop on Wearable Systems and Applications, Singapore.","DOI":"10.1145\/2935643.2935650"},{"key":"ref_58","doi-asserted-by":"crossref","first-page":"615","DOI":"10.1145\/3093337.3037698","article-title":"Neurosurgeon: Collaborative Intelligence between the Cloud and Mobile Edge","volume":"45","author":"Kang","year":"2017","journal-title":"ACM SIGARCH Comput. Archit. News"},{"key":"ref_59","doi-asserted-by":"crossref","first-page":"11429","DOI":"10.1109\/JSEN.2020.2995779","article-title":"Enabling Real-Time Computation of Psycho-Acoustic Parameters in Acoustic Sensors Using Convolutional Neural Networks","volume":"20","author":"Ballester","year":"2020","journal-title":"IEEE Sens. J."},{"key":"ref_60","unstructured":"(2022, June 10). Raspberry Pi. Available online: https:\/\/www.raspberrypi.com\/documentation."},{"key":"ref_61","doi-asserted-by":"crossref","unstructured":"Zhou, H., Bateni, S., and Liu, C. (2018, January 11\u201313). S3DNN: Supervised Streaming and Scheduling for GPU-Accelerated Real-Time DNN Workloads. Proceedings of the 2018 IEEE Real-Time and Embedded Technology and Applications Symposium (RTAS), Porto, Portugal.","DOI":"10.1109\/RTAS.2018.00028"},{"key":"ref_62","doi-asserted-by":"crossref","unstructured":"Kim, Y., Kim, J., Chae, D., Kim, D., and Kim, J. (2019, January 25\u201328). \u03bcLayer: Low Latency On-Device Inference Using Cooperative Single-Layer Acceleration and Processor-Friendly Quantization. Proceedings of the Fourteenth EuroSys Conference 2019, Dresden, Germary.","DOI":"10.1145\/3302424.3303950"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/15\/5896\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T00:05:23Z","timestamp":1760141123000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/15\/5896"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,8,7]]},"references-count":62,"journal-issue":{"issue":"15","published-online":{"date-parts":[[2022,8]]}},"alternative-id":["s22155896"],"URL":"https:\/\/doi.org\/10.3390\/s22155896","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,8,7]]}}}