BoMaNet: Boolean Masking of an Entire Neural Network

BoMaNet: Boolean Masking of an Entire Neural Network
复制标题

DOI:
10.1145/3400302.3415649
复制
发表时间:
2020-06
期刊:
2020 IEEE/ACM International Conference On Computer Aided Design (ICCAD)
影响因子:
--
通讯作者:
Anuj Dubey;Rosario Cammarota;Aydin Aysu
Anuj Dubey;Rosario Cammarota;Aydin Aysu
中科院分区:
其他
文献类型:
--
作者:
Anuj Dubey;Rosario Cammarota;Aydin Aysu

文献摘要

相似文献

最近关于从具有物理侧通道攻击的推理引擎中窃取机器学习(ML)模型的工作迫切需要有效的侧通道防御。本文提出了第一个完全屏蔽神经网络推理机的设计。掩蔽使用安全多方计算来将秘密分割成随机份额,并将依赖于秘密的计算的统计关系去关联到旁路(例如,功率提取)。在这项工作中,我们构造了安全的硬件原语来屏蔽神经网络中所有的线性和非线性操作。我们解决了屏蔽整数加法的挑战,将每个加法转换为一系列XOR和AND门,并增强了特里希纳的安全布尔屏蔽风格。我们通过添加流水线元件来改进传统的旋风与门,以获得更好的抗毛刺能力,并且我们设计了整个设计,以维持每个周期1次屏蔽加法的吞吐量。我们在Xilinx Spartan-6(XC6SLX75)的现场可编程门阵列上实现了该安全推理引擎。结果表明,掩蔽导致的延迟开销为3.5%,面积为5.9倍。最后,我们用2M条踪迹验证了掩蔽设计的安全性。
Recent work on stealing machine learning (ML) models from inference engines with physical side-channel attacks warrant an urgent need for effective side-channel defenses. This work proposes the first fully-masked neural network inference engine design. Masking uses secure multi-party computation to split the secrets into random shares and to decorrelate the statistical relation of secret-dependent computations to side-channels (e.g., the power draw). In this work, we construct secure hardware primitives to mask all the linear and non-linear operations in a neural network. We address the challenge of masking integer addition by converting each addition into a sequence of XOR and AND gates and by augmenting Trichina's secure Boolean masking style. We improve the traditional Trichina's AND gates by adding pipelining elements for better glitch-resistance and we architect the whole design to sustain a throughput of 1 masked addition per cycle. We implement the proposed secure inference engine on a Xilinx Spartan-6 (XC6SLX75) FPGA. The results show that masking incurs an overhead of 3.5% in latency and 5.9× in area. Finally, we demonstrate the security of the masked design with 2M traces.