Deep-Dup: An Adversarial Weight Duplication Attack Framework to Crush Deep Neural Network in Multi-Tenant FPGA

Deep-Dup: An Adversarial Weight Duplication Attack Framework to Crush Deep Neural Network in Multi-Tenant FPGA
复制标题

DOI:
--
复制
发表时间:
2020-11
期刊:
ArXiv
影响因子:
--
通讯作者:
A. S. Rakin;Yukui Luo;Xiaolin Xu;Deliang Fan
A. S. Rakin;Yukui Luo;Xiaolin Xu;Deliang Fan
中科院分区:
其他
文献类型:
--
作者:
A. S. Rakin;Yukui Luo;Xiaolin Xu;Deliang Fan

文献摘要

被引文献

相似文献

深度神经网络(DNN)在高性能云计算平台中的广泛部署使现场可编程门阵列(FPGA)成为加速器的热门选择,以提高性能,因为它具有硬件重新编程的灵活性。为了提高硬件资源的利用效率,越来越多的努力已经投入到FPGA虚拟化中,使得多个独立的租户能够在共享的FPGA芯片中共存。这种用于DNN加速的多租户FPGA设置可能会在恶意用户的严重威胁下暴露DNN干扰任务。据我们所知,这项工作是第一次探索多租户FPGA中的DNN模型漏洞。我们提出了一种新型的对抗性攻击框架:Deep-Dup,其中对抗性租户可以向FPGA中受害租户的DNN模型注入故障。具体来说,她可以通过恶意的功率掠夺电路来使FPGA的共享功率分配系统过载,实现对抗性权重复制(AWD)硬件攻击,在片外存储器和片上缓冲区之间的数据传输期间复制某些DNN权重包,目的是劫持受害者租户的DNN功能。此外,为了识别给定恶意目标的最脆弱DNN权重包,我们提出了一种通用的脆弱权重包搜索算法,称为渐进差分进化搜索(P-DES),它首次适应深度学习白盒和黑盒攻击模型。与之前只在深度学习白盒设置中工作的工作不同,我们的适应性主要来自于所提出的P-DES不需要DNN模型的任何梯度信息。
The wide deployment of Deep Neural Networks (DNN) in high-performance cloud computing platforms has emerged field-programmable gate arrays (FPGA) as a popular choice of accelerator to boost performance due to its hardware reprogramming flexibility. To improve the efficiency of hardware resource utilization, growing efforts have been invested in FPGA virtualization, enabling the co-existence of multiple independent tenants in a shared FPGA chip. Such a multi-tenant FPGA setup for DNN acceleration potentially exposes the DNN interference task under severe threat from malicious users. This work, to the best of our knowledge, is the first to explore DNN model vulnerabilities in multi-tenant FPGAs. We propose a novel adversarial attack framework: Deep-Dup, in which the adversarial tenant can inject faults to the DNN model of victim tenant in FPGA. Specifically, she can aggressively overload the shared power distribution system of FPGA with malicious power-plundering circuits, achieving adversarial weight duplication (AWD) hardware attack that duplicates certain DNN weight packages during data transmission between off-chip memory and on-chip buffer, with the objective to hijack DNN function of the victim tenant. Further, to identify the most vulnerable DNN weight packages for a given malicious objective, we propose a generic vulnerable weight package searching algorithm, called Progressive Differential Evolution Search (P-DES), which is, for the first time, adaptive to both deep learning white-box and black-box attack models. Unlike prior works only working in a deep learning white-box setup, our adaptiveness mainly comes from the fact that the proposed P-DES does not require any gradient information of DNN model.