Ayesha Siddique

dblp:283/4583 · DBLP profile ↗
← Back
7ranked-venue papers
6as first author
7since 2021 · last 2025
0000-0002-2073-5253ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 6 · 5 first-author · 6 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 ApproXAI: Energy-Efficient Hardware Acceleration of Explainable AI using Approximate Computing
abstract
Explainable artificial intelligence (XAI) enhances AI system transparency by framing interpretability as an optimization problem. However, this approach often necessitates numerous iterations of computationally intensive operations, limiting its applicability in real-time scenarios. While recent research has focused on XAI hardware acceleration on FPGAs and TPU, these methods do not fully address energy efficiency in real-time settings. To address this limitation, we propose XAIedge, a novel framework that leverages approximate computing techniques into XAI algorithms, including integrated gradients, model distillation, and Shapley analysis. XAIedge translates these algorithms into approximate matrix computations and exploits the synergy between convolution, Fourier transform, and approximate computing paradigms. This approach enables efficient hardware acceleration on TPU-based edge devices, facilitating faster real-time outcome interpretations. Our comprehensive evaluation demonstrates that XAIedge achieves a 2× improvement in energy efficiency compared to existing accurate XAI hardware acceleration techniques while maintaining comparable accuracy. These results highlight the potential of XAIedge to significantly advance the deployment of explainable AI in energy-constrained real-time applications.
Ayesha Siddique, Khurram Khalil, Khaza Anuarul Hoque
IJCNN1
2025 Explainable AI-Guided Neural Architecture Search for Adversarial Robustness in Approximate DNNs
abstract
Deep neural networks are lucrative targets of adversarial attacks and approximate deep neural networks (AxDNNs) are no exception. Searching manually for adversarially robust AxDNN architectures incurs outrageous time and human effort. In this paper, we propose XAI-NAS, an explainable neural architecture search (NAS) method that leverages explainable artificial intelligence (XAI) to efficiently co-optimize the adversarial robustness and hardware efficiency of AxDNN architectures on systolic-array hardware accelerators. During the NAS process, AxDNN architectures are evolved layer-wise with heterogeneous approximate multipliers to deliver the best trade-offs between adversarial robustness, energy consumption, latency, and memory footprint. The most suitable approximate multipliers are automatically selected from an open-source Evoapprox8b library. Our extensive evaluations provide a set of Pareto optimal hardware efficient and adversarially robust solutions. For example, a Pareto-optimal DNN AxDNN for the MNIST and CIFAR-10 datasets exhibits up to 1.5× higher adversarial robustness, 2.1× less energy consumption, 4.39× reduced latency, and 2.37× low memory footprint when compared to the state-of-the-art NAS approaches.
Ayesha Siddique, Khaza Anuarul Hoque
IEEE Trans. Sustain. Comput.1
2024 Moving Target Defense Through Approximation for Low-Power Neuromorphic Edge Intelligence
abstract
Neuromorphic intelligence is driven by spiking neural networks (SNNs) to achieve high algorithmic performance. However, similar to artificial neural networks (ANNs), SNNs are vulnerable to adversarial attacks. Such attacks often succeed in misclassification by repeatedly probing a fixed target model. Recent works claim that repeated attacks can be defended in ANNs by employing a moving target defense (MTD). Nonetheless, the state-of-the-art defense mechanisms in SNNs do not consider the notion of moving targets and are limited to shallow network architectures. To this end, we propose a novel MTD strategy for neuromorphic edge intelligence (MTSpike) that incorporates approximate knowledge distillation based on the distinct inherent structural parameters, i.e., firing threshold and time steps in SNNs, under a pre-train and finetune paradigm. Indeed, it is a 2-in-1 approach that enhances robustness against repeated attacks and reduces energy consumption for deeper SNNs. We evaluate our proposed MTSpike with four benchmark image classification datasets, i.e., ImageNet, CIFAR10, DVS128 Gesture, and CIFAR10-DVS datasets against white-box, black-box, and grey-box FGSM, PGD, sparse and efficiency attacks on deep residual SNNs. Our results demonstrate that MTSpike outperforms the state-of-the-art defense techniques by enabling SNNs to operate with a negligible drop in classification accuracy (as low as 1%–2%) under adversarial attacks. Also, MTSpike achieves 1.3× higher energy efficiency under efficiency attack. Apart from defense, MTSpike provides an additional advantage of energy efficiency by reducing the spike rate by 3× in deeper SNNs.
Ayesha Siddique, Khaza Anuarul Hoque
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2023 Security-Aware Approximate Spiking Neural Networks
Syed Tihaam Ahmad, Ayesha Siddique, Khaza Anuarul Hoque
DATE2
2023 Improving Reliability of Spiking Neural Networks through Fault Aware Threshold Voltage Optimization
abstract
Spiking neural networks have made breakthroughs in computer vision by lending themselves to neuromorphic hardware. However, the neuromorphic hardware lacks parallelism and hence, limits the throughput and hardware acceleration of SNNs on edge devices. To address this problem, many systolic-array SNN accelerators (systolicSNNs) have been proposed recently, but their reliability is still a major concern. In this paper, we first extensively analyze the impact of permanent faults on the SystolicSNNs. Then, we present a novel fault mitigation method, i.e., fault-aware threshold voltage optimization in retraining (FalVolt). FalVolt optimizes the threshold voltage for each layer in retraining to achieve the classification accuracy close to the baseline in the presence of faults. To demonstrate the effectiveness of our proposed mitigation, we classify both static (i.e., MNIST) and neuromorphic datasets (i.e., N-MNIST and DVS Gesture) on a 256x256 systolicSNN with stuck-at faults. We empirically show that the classification accuracy of a systolicSNN drops significantly even at extremely low fault rates (as low as 0.012%). Our proposed FalVolt mitigation method improves the performance of systolicSNNs by enabling them to operate at fault rates of up to 60%, with a negligible drop in classification accuracy (as low as 0.1%). Our results show that FalVolt is 2x faster compared to other state-of-the-art techniques common in artificial neural networks (ANNs), such as fault-aware pruning and retraining without threshold voltage optimization.
Ayesha Siddique, Khaza Anuarul Hoque
DATE1
2023 Exposing Reliability Degradation and Mitigation in Approximate DNNs Under Permanent Faults
abstract
Approximate computing is known for enhancing deep neural network accelerators’ energy efficiency by introducing inexactness with a tolerable accuracy loss. However, small accuracy variations may increase the sensitivity of these accelerators toward undesired subtle disturbances, such as permanent faults. The impact of permanent faults in accurate deep neural network (AccDNN) accelerators has been thoroughly investigated in the literature. Conversely, the impact of permanent faults and their mitigation in approximate DNN (AxDNN) accelerators is vastly underexplored. Toward this, we first present an extensive fault resilience analysis of approximate multilayer perceptrons (MLPs) and convolutional neural networks (CNNs) using the state-of-the-art Evoapprox8b multipliers in graphic processing unit (GPU) and tensor processing unit (TPU) accelerators. Then, we propose a novel fault mitigation method, i.e., fault-aware retuning of weights (Fal-reTune). Fal-reTune retunes the weights using a weight mapping function in the presence of faults for improved classification accuracy. To evaluate the fault resilience and the effectiveness of our proposed mitigation method, we used the most widely used MNIST, Fashion-MNIST, and CIFAR10 datasets. Our results demonstrate that the permanent faults exacerbate the accuracy loss in AxDNNs compared with the AccDNN accelerators. For instance, a permanent fault in AxDNNs can lead to 56% accuracy loss, whereas the same faulty bit can lead to only 4% accuracy loss in AccDNN accelerators. We empirically show that our proposed Fal-reTune mitigation method improves the performance of AxDNNs up to 98%, even with fault rates up to 50%. Furthermore, we observe that the fault resilience in AxDNNs is orthogonal to their energy efficiency.
Ayesha Siddique, Khaza Anuarul Hoque
IEEE Trans. Very Large Scale Integr. Syst.1
2022 Is Approximation Universally Defensive Against Adversarial Attacks in Deep Neural Networks?
abstract
Approximate computing is known for its effectiveness in improvising the energy efficiency of deep neural network (DNN) accelerators at the cost of slight accuracy loss. Very recently, the inexact nature of approximate components, such as approximate multipliers have also been reported successful in defending adversarial attacks on DNNs models. Since the approximation errors traverse through the DNN layers as masked or unmasked, this raises a key research question—can approximate computing always offer a defense against adversarial attacks in DNNs, i.e., are they universally defensive? Towards this, we present an extensive adversarial robustness analysis of different approximate DNN accelerators (AxDNNs) using the state-of-the-art approximate multipliers. In particular, we evaluate the impact of ten adversarial attacks on different AxDNNs using the MNIST and CIFAR-10 datasets. Our results demonstrate that adversarial attacks on AxDNNs can cause 53% accuracy loss whereas the same attack may lead to almost no accuracy loss (as low as 0.06%) in the accurate DNN. Thus, approximate computing cannot be referred to as a universal defense strategy against adversarial attacks.
Ayesha Siddique, Khaza Anuarul Hoque
DATE1