AegisDNN: Dependable and Timely Execution of DNN Tasks with SGX

AegisDNN: Dependable and Timely Execution of DNN Tasks with SGX
复制标题

DOI:
10.1109/rtss52674.2021.00018
复制
发表时间:
2021-12
期刊:
2021 IEEE Real-Time Systems Symposium (RTSS)
影响因子:
--
通讯作者:
Yecheng Xiang;Yidi Wang;Hyun-Seon Choi;Mohsen Karimi;Hyoseung Kim
Yecheng Xiang;Yidi Wang;Hyun-Seon Choi;Mohsen Karimi;Hyoseung Kim
中科院分区:
其他
文献类型:
--
作者:
Yecheng Xiang;Yidi Wang;Hyun-Seon Choi;Mohsen Karimi;Hyoseung Kim

文献摘要

相似文献

随着安全关键系统中新兴DNN应用需求的不断增长,DNN推理输出的可靠性和可信度受到了广泛关注。虽然之前已经通过在英特尔SGX安全区内执行整个DNN模型来提高DNN推理的隐私性,但现有方法在同时实现可靠和及时的执行方面面临严峻的性能挑战。在本文中,我们提出了AegisDNN,一个DNN推理框架来解决这个问题。AegisDNN利用安全的SGX飞地,仅保护易受潜在故障注入攻击的实时DNN任务的关键部分。为了选择正确的保护层,同时确保任务执行的及时性,AegisDNN包含一个基于动态编程的算法,可以为每个任务找到一个层保护配置,以满足基于分层DNN时间和SDC(Silent Data Corruption)分析机制的实时性和可靠性要求。AegisDNN还利用基于机器学习的SDC预测方法,显著缩短所有可能的层保护配置的SDC速率估计时间。我们在Caffe、PyTorch和Tensorflow上实现了AegisDNN,并将Eigen BLAS移植到SGX安全区,以全面展示AegisDNN对抗最先进的DNN故障注入攻击的有效性。实验结果表明,AegisDNN可以同时满足可靠性和实时性的要求,当没有其他比较的方法可以做到这一点。
With the rising demand for emerging DNN applications in safety-critical systems, much attention has been given to the reliability and trustworthiness of DNN inference output against malicious attacks. Although prior work has been conducted to improve the privacy of DNN inference by executing the entire DNN model inside Intel SGX enclaves, existing approaches pose severe performance challenges to achieve dependable and timely execution simultaneously. In this paper, we propose AegisDNN, a DNN inference framework to address this problem. AegisDNN leverages secure SGX enclaves for protecting only the critical part of real-time DNN tasks which are vulnerable to potential fault injection attacks. To choose the right set of layers for protection while ensuring the timeliness of task execution, AegisDNN includes a dynamic-programming based algorithm that finds a layer protection configuration for each task to meet the real-time and dependability requirements based on the layer-wise DNN time and SDC (Silent Data Corruption) profiling mechanism. AegisDNN also utilizes a machine-learning based SDC prediction method to significantly reduce the time for estimating SDC rates for all possible layer protection configurations. We implemented AegisDNN on Caffe, PyTorch, and Tensorflow with Eigen BLAS ported into SGX enclaves to comprehensively demonstrate the effectiveness of AegisDNN against state-of-the-art DNN fault-injection attacks. Experiment results indicate that AegisDNN could satisfy both dependability and real-time requirements simultaneously, when none of the other compared approaches could do so.