Exploiting Logic Locking for a Neural Trojan Attack on Machine Learning Accelerators

Exploiting Logic Locking for a Neural Trojan Attack on Machine Learning Accelerators
复制标题

DOI:
10.1145/3583781.3590242
复制
发表时间:
2023-04
期刊:
Proceedings of the Great Lakes Symposium on VLSI 2023
影响因子:
--
通讯作者:
Hongye Xu;Dongfang Liu;Cory E. Merkel;Michael Zuzak
Hongye Xu;Dongfang Liu;Cory E. Merkel;Michael Zuzak
中科院分区:
其他
文献类型:
--
作者:
Hongye Xu;Dongfang Liu;Cory E. Merkel;Michael Zuzak

文献摘要

相似文献

为了在芯片制造过程中保护知识产权,人们提出了逻辑锁。逻辑锁定技术通过使设计中的组合模块的子集依赖于不受信任的各方保留的秘密密钥来保护硬件IP。如果使用了不正确的密钥,则会在锁定模块中产生一组确定性错误,从而限制未经授权的使用。逻辑锁定的一个常见目标是神经加速器,特别是随着机器学习即服务变得越来越普遍。在这项工作中,我们探讨了如何使用逻辑锁定来损害它所保护的神经加速器的安全性。具体来说,我们展示了由不正确的密钥引起的确定性错误如何被利用来产生神经木马式的后门。为此,我们首先概述一个动机攻击场景,其中一个精心选择的错误密钥(我们称之为木马密钥)会对锁定加速器中攻击者指定的输入类产生错误分类。然后,我们开发了一种理论上健壮的攻击方法来自动识别特洛伊木马密钥。为了评估这次攻击,我们在几个锁定的加速器上发射它。在我们最大的基准加速器中,我们的攻击识别了一个木马密钥,该密钥导致攻击者指定的触发输入的分类准确率降低了74%,而其他输入的准确率平均仅降低了1.7%。
Logic locking has been proposed to safeguard intellectual property (IP) during chip fabrication. Logic locking techniques protect hardware IP by making a subset of combinational modules in a design dependent on a secret key that is withheld from untrusted parties. If an incorrect secret key is used, a set of deterministic errors is produced in locked modules, restricting unauthorized use. A common target for logic locking is neural accelerators, especially as machine-learning-as-a-service becomes more prevalent. In this work, we explore how logic locking can be used to compromise the security of a neural accelerator it protects. Specifically, we show how the deterministic errors caused by incorrect keys can be harnessed to produce neural-trojan-style backdoors. To do so, we first outline a motivational attack scenario where a carefully chosen incorrect key, which we call a trojan key, produces misclassifications for an attacker-specified input class in a locked accelerator. We then develop a theoretically-robust attack methodology to automatically identify trojan keys. To evaluate this attack, we launch it on several locked accelerators. In our largest benchmark accelerator, our attack identified a trojan key that caused a 74% decrease in classification accuracy for attacker-specified trigger inputs, while degrading accuracy by only 1.7% for other inputs on average.