Towards Sustainable SecureML: Quantifying Carbon Footprint of Adversarial Machine Learning
Abstract: The widespread adoption of ML across various industries has raised sustainability concerns due to its substantial energy usage and carbon emissions. This issue becomes more pressing in adversarial ML, which focuses on enhancing model security against different network-based attacks. Implementing defenses in ML systems often necessitates additional computational resources and network security measures, exacerbating their environmental impacts. In this paper, we pioneer the first investigation into adversarial ML's carbon footprint, providing empirical evidence connecting greater model robustness to higher emissions. Addressing the critical need to quantify this trade-off, we introduce the Robustness Carbon Trade-off Index (RCTI). This novel metric, inspired by economic elasticity principles, captures the sensitivity of carbon emissions to changes in adversarial robustness. We demonstrate the RCTI through an experiment involving evasion attacks, analyzing the interplay between robustness against attacks, performance, and carbon emissions.
- D. Patterson, J. Gonzalez, Q. Le, C. Liang, L.-M. Munguia, D. Rothchild, D. So, M. Texier, and J. Dean, “Carbon emissions and large neural network training,” 2021.
- C.-J. Wu, R. Raghavendra, U. Gupta, B. Acun, N. Ardalani, K. Maeng, G. Chang, F. Aga, J. Huang, C. Bai et al., “Sustainable ai: Environmental implications, challenges and opportunities,” Proceedings of Machine Learning and Systems, vol. 4, pp. 795–813, 2022.
- A. Haldar and N. Sethi, “Environmental effects of information and communication technology-exploring the roles of renewable energy, innovation, trade and financial development,” Renewable and Sustainable Energy Reviews, vol. 153, p. 111754, 2022.
- M.-I. Nicolae, M. Sinn, M. N. Tran, B. Buesser, A. Rawat, M. Wistuba, V. Zantedeschi, N. Baracaldo, B. Chen, H. Ludwig, I. Molloy, and B. Edwards, “Adversarial robustness toolbox v1.2.0,” CoRR, vol. 1807.01069, 2018. [Online]. Available: https://arxiv.org/pdf/1807.01069
- E. Strubell, A. Ganesh, and A. McCallum, “Energy and policy considerations for deep learning in nlp,” 2019.
- Z. Epstein, A. Hertzmann, the Investigators of Human Creativity, M. Akten, H. Farid, J. Fjeld, M. R. Frank, M. Groh, L. Herman, N. Leach, R. Mahari, A. S. Pentland, O. Russakovsky, H. Schroeder, and A. Smith, “Art and the science of generative ai,” Science, vol. 380, no. 6650, pp. 1110–1111, 2023. [Online]. Available: https://www.science.org/doi/abs/10.1126/science.adh4451
- C.-J. Wu, R. Raghavendra, U. Gupta, B. Acun, N. Ardalani, K. Maeng, G. Chang, F. Aga, J. Huang, C. Bai, M. Gschwind, A. Gupta, M. Ott, A. Melnikov, S. Candido, D. Brooks, G. Chauhan, B. Lee, H.-H. Lee, B. Akyildiz, M. Balandat, J. Spisak, R. Jain, M. Rabbat, and K. Hazelwood, “Sustainable ai: Environmental implications, challenges and opportunities,” in Proceedings of Machine Learning and Systems, D. Marculescu, Y. Chi, and C. Wu, Eds., vol. 4, 2022, pp. 795–813.
- R. Verdecchia, J. Sallou, and L. Cruz, “A systematic review of green ai,” 2023.
- P. Henderson, J. Hu, J. Romoff, E. Brunskill, D. Jurafsky, and J. Pineau, “Towards the systematic reporting of the energy and carbon footprints of machine learning,” 2020.
- J. Dodge, T. Prewitt, R. Tachet des Combes, E. Odmark, R. Schwartz, E. Strubell, A. S. Luccioni, N. A. Smith, N. DeCario, and W. Buchanan, “Measuring the carbon intensity of ai in cloud instances,” in Proceedings of the 2022 ACM Conference on Fairness, Accountability, and Transparency, 2022, pp. 1877–1894.
- A. S. Luccioni and A. Hernandez-Garcia, “Counting carbon: A survey of factors influencing the emissions of machine learning,” arXiv preprint arXiv:2302.08476, 2023.
- L. H. Kaack, P. L. Donti, E. Strubell, G. Kamiya, F. Creutzig, and D. Rolnick, “Aligning artificial intelligence with climate change mitigation,” Nature Climate Change, vol. 12, no. 6, pp. 518–527, 2022.
- Z. Yang, X. He, Z. Li, M. Backes, M. Humbert, P. Berrang, and Y. Zhang, “Data poisoning attacks against multimodal encoders,” in International Conference on Machine Learning. PMLR, 2023, pp. 39 299–39 313.
- H. Liu, Z. Ge, Z. Zhou, F. Shang, Y. Liu, and L. Jiao, “Gradient correction for white-box adversarial attacks,” IEEE Transactions on Neural Networks and Learning Systems, 2023.
- M. M. Badr, M. Mahmoud, M. Abdulaal, A. J. Aljohani, F. Alsolami, and A. Balamsh, “A novel evasion attack against global electricity theft detectors and a countermeasure,” IEEE Internet of Things Journal, 2023.
- N. Ponomareva, H. Hazimeh, A. Kurakin, Z. Xu, C. Denison, H. B. McMahan, S. Vassilvitskii, S. Chien, and A. G. Thakurta, “How to dp-fy ml: A practical guide to machine learning with differential privacy,” Journal of Artificial Intelligence Research, vol. 77, pp. 1113–1201, 2023.
- K. Wei, J. Li, C. Ma, M. Ding, W. Chen, J. Wu, M. Tao, and H. V. Poor, “Personalized federated learning with differential privacy and convergence guarantee,” IEEE Transactions on Information Forensics and Security, 2023.
- C. Zhou and N. Ansari, “Securing federated learning enabled nwdaf architecture with partial homomorphic encryption,” IEEE Networking Letters, 2023.
- J. Xu, Y. Li, Y. Jiang, and S.-T. Xia, “Adversarial defense via local flatness regularization,” in 2020 IEEE International Conference on Image Processing (ICIP), 2020, pp. 2196–2200.
- A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” arXiv preprint arXiv:1706.06083, 2017.
- mlco2, “Codecarbon.” [Online]. Available: https://github.com/mlco2/codecarbon
- H. Gao, X. Wang, K. Wu, Y. Zheng, Q. Wang, W. Shi, and M. He, “A review of building carbon emission accounting and prediction models,” Buildings, vol. 13, no. 7, p. 1617, 2023.
- Trusted AI, “Adversarial training mnist,” 2023. [Online]. Available: https://github.com/Trusted-AI/adversarial-robustness-toolbox/blob/main/notebooks/adversarial_training_mnist.ipynb
Paper Prompts
Sign up for free to create and run prompts on this paper.