Reliable Hardware Watermarks for Deep Learning Systems

Reliable Hardware Watermarks for Deep Learning Systems
复制标题

DOI:
10.1109/tvlsi.2024.3360240
复制
发表时间:
2024-04
影响因子:
2.8
通讯作者:
Joseph Clements;Yingjie Lao
Joseph Clements;Yingjie Lao
中科院分区:
工程技术2区
文献类型:
--
作者:
Joseph Clements;Yingjie Lao

文献摘要

相似文献

深度学习的最新成功表明,硬件技术将在未来的深度学习行业和应用中发挥重要作用。鉴于他们的价值,研究人员已经认识到,深层神经网络(DNN)和其他深度学习智力特性(IP)很容易被盗版,尤其是在未防御的环境中。尽管已经确定了捍卫深度学习系统的多种途径,但水印特别有价值,因为它们可以在发生时识别和修复IP盗窃。但是,对于捍卫运行深度学习系统的硬件平台的捍卫,此类防御尚未考虑。本文介绍了第一个将水印用于捍卫深入学习的硬件加速器免受盗版(称为Deephardmark)的框架。所提出的方法将修改嵌入了深度学习硬件加速器的功能块中,以充当水印签名。这些修改会为相应的密钥样本执行密钥DNN的执行产生针对性的更改,该样本标识了硬件。我们优化了这种方法,以同时最大程度地减少深度学习系统的硬件和算法组件的水印对硬件和算法组件的影响。我们的实验评估表明,将所提出的修改嵌入典型的硬件设计以及各种深度学习的情况下的可行性。
Recent successes in deep learning have indicated that hardware technologies will play a prominent role in future deep learning industries and applications. In light of their value, researchers have recognized that deep neural networks (DNNs) and other deep learning intellectual properties (IPs) can be easily pirated, especially in undefended settings. While multiple avenues of defending deep learning systems have been identified, watermarks are particularly valuable as they allow IP theft to be identified and remedied when it occurs. However, such defenses have yet to be considered for defending the hardware platforms running the deep learning systems. This article presents the first framework for applying watermarks toward defending deep-learning hardware accelerators from piracy, called DeepHardMark. The proposed methodology embeds modifications into the functional blocks of deep-learning hardware accelerators to act as a watermark signature. These modifications produce targeted alterations to the execution of key DNNs on corresponding key samples, which identifies the hardware. We optimize this methodology to simultaneously minimize the impact of the watermark embedding on both the hardware and algorithmic components of the deep learning system making the watermark unobtrusive and challenging to detect. Our experimental evaluations demonstrate the feasibility of embedding the proposed modifications into typical hardware designs and in various deep-learning scenarios.