Stealing Neural Network Structure Through Remote FPGA Side-Channel Analysis

Stealing Neural Network Structure Through Remote FPGA Side-Channel Analysis
复制标题

DOI:
10.1145/3431920.3439468
复制
发表时间:
2021-02
影响因子:
6.8
通讯作者:
Yicheng Zhang;Rozhin Yasaei;Hao Chen;Zhou Li;M. A. Faruque
Yicheng Zhang;Rozhin Yasaei;Hao Chen;Zhou Li;M. A. Faruque
中科院分区:
计算机科学1区
文献类型:
--
作者:
Yicheng Zhang;Rozhin Yasaei;Hao Chen;Zhou Li;M. A. Faruque

文献摘要

被引文献

相似文献

深层神经网络(DNN)模型已由公司广泛开发,用于广泛的应用。具有出色绩效的定制DNN模型的开发需要昂贵的投资,其结构(层和超参数)被认为是知识产权,具有巨大的价值。但是,在本文中,我们发现当基于云的FPGA加速器执行它时,模型秘密很容易受到攻击。我们基于远程功率侧通道分析和基于机器学习的秘密推断对不同的DNN模型展示了端到端攻击。评估结果表明,攻击者可以使用我们的方法以超过90%的精度重建层和高参数序列,这可以大大减少她的模型开发工作量。我们认为,攻击所带来的威胁是切实的,应针对这种威胁发展新的防御机制。
Deep Neural Network (DNN) models have been extensively developed by companies for a wide range of applications. The development of a customized DNN model with great performance requires costly investments, and its structure (layers and hyper-parameters) is considered intellectual property and holds immense value. However, in this paper, we found the model secret is vulnerable when a cloud-based FPGA accelerator executes it. We demonstrate an end-to-end attack based on remote power side-channel analysis and machine-learning-based secret inference against different DNN models. The evaluation result shows that an attacker can reconstruct the layer and hyper-parameter sequence at over 90% accuracy using our method, which can significantly reduce her model development workload. We believe the threat presented by our attack is tangible, and new defense mechanisms should be developed against this threat.