MaskedNet: The First Hardware Inference Engine Aiming Power Side-Channel Protection

MaskedNet: The First Hardware Inference Engine Aiming Power Side-Channel Protection
复制标题

DOI:
10.1109/host45689.2020.9300276
复制
发表时间:
2019-10
期刊:
2020 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)
影响因子:
--
通讯作者:
Anuj Dubey;Rosario Cammarota;Aydin Aysu
Anuj Dubey;Rosario Cammarota;Aydin Aysu
中科院分区:
其他
文献类型:
--
作者:
Anuj Dubey;Rosario Cammarota;Aydin Aysu

文献摘要

被引文献

相似文献

在过去的二十年中,差异功率分析(DPA)一直是研究的积极研究领域,用于研究通过电力测量及其防御措施从加密实施中提取秘密信息的攻击。到目前为止,有关电源侧通道的研究主要集中在分析AES,DES,RSA和最近的量子加密后原始原始原始原始(例如晶格)等密码的实现。同时,机器学习应用程序在几种情况下变得无处不在,因为机器学习模型是需要机密性的知识属性。然而,将侧通道分析扩展到机器学习模型提取是在很大程度上尚未探索的。本文将DPA框架扩展到神经网络分类器。首先,它在推断过程中显示了DPA攻击,以提取神经网络的权重和偏见等秘密模型参数。其次,它提出了通过增强掩饰来抵抗这些攻击的第一个对策。最终的设计使用新颖的蒙版组件,例如蒙版的加法树,用于完全连接的层和蒙版的整流器线性单元进行激活函数。在Sakura-X FPGA板上,实验表明,对未受保护的实施的一阶DPA攻击只能使用200个痕迹成功,我们的保护分别将延迟和面积成本提高2.8 \ times $ $ $和$ 2.3 \ times $。
Differential Power Analysis (DPA) has been an active area of research for the past two decades to study the attacks for extracting secret information from cryptographic implementations through power measurements and their defenses. The research on power side-channels have so far predominantly focused on analyzing implementations of ciphers such as AES, DES, RSA, and recently post-quantum cryptography primitives (e.g., lattices). Meanwhile, machine-learning applications are becoming ubiquitous with several scenarios where the Machine Learning Models are Intellectual Properties requiring confidentiality. Expanding side-channel analysis to Machine Learning Model extraction, however, is largely unexplored. This paper expands the DPA framework to neural-network classifiers. First, it shows DPA attacks during inference to extract the secret model parameters such as weights and biases of a neural network. Second, it proposes the first countermeasures against these attacks by augmenting masking. The resulting design uses novel masked components such as masked adder trees for fully-connected layers and masked Rectifier Linear Units for activation functions. On a SAKURA-X FPGA board, experiments show that the first-order DPA attacks on the unprotected implementation can succeed with only 200 traces and our protection respectively increases the latency and area-cost by $ 2.8\times$ and $2.3\times$.