DeepCloak: Adversarial Crafting As a Defensive Measure to Cloak Processes

DeepCloak: Adversarial Crafting As a Defensive Measure to Cloak Processes
复制标题

DOI:
10.1145/3464458.3464459
复制
发表时间:
2018-08
期刊:
Proceedings of the 2019 Workshop on DYnamic and Novel Advances in Machine Learning and Intelligent Cyber Security
影响因子:
--
通讯作者:
Mehmet Sinan Inci;T. Eisenbarth;B. Sunar
Mehmet Sinan Inci;T. Eisenbarth;B. Sunar
中科院分区:
其他
文献类型:
--
作者:
Mehmet Sinan Inci;T. Eisenbarth;B. Sunar

文献摘要

被引文献

相似文献

在过去的十年中,旁道已被证明对现代计算系统构成重大且实际的威胁。最近的攻击都利用了底层共享硬件。虽然实用,但发起如此复杂的攻击仍然类似于在拥挤的火车站监听私人谈话。攻击者必须执行大量的体力劳动或使用人工智能系统来自动化该过程。最近的学术文献指出了后一种选择。随着廉价计算能力的丰富和人工智能的进步,自动化此类任务是相当有利的。然而,通过使用人工智能系统,恶意方也继承了它们的弱点,最明显的是对抗性样本的脆弱性。在这项工作中,我们建议使用对抗性学习作为防御工具来混淆和掩盖侧通道信息。我们首先通过不同过程的泄漏跟踪来训练 CNN 和其他机器学习分类器,从而证明了这种方法的可行性。训练出高度准确的模型(准确率超过 99%)后,我们对其进行对抗性学习测试。我们证明,通过对输入痕迹进行最小的扰动,防御者可以作为原始进程的附件运行,并将其隐藏起来以抵御恶意分类器。最后,我们研究攻击者是否可以使用对抗性防御方法、对抗性再训练和防御性蒸馏来保护模型。我们的结果表明,即使存在使用此类技术的智能对手,对抗性学习方法仍然能够成功地制造扰动,因此所提出的隐形方法是成功的。
Over the past decade, side-channels have proven to be significant and practical threats to modern computing systems. Recent attacks have all exploited the underlying shared hardware. While practical, mounting such a complicated attack is still akin to listening on a private conversation in a crowded train station. The attacker has to either perform significant manual labor or use AI systems to automate the process. The recent academic literature points to the latter option. With the abundance of cheap computing power and the improvements made in AI, it is quite advantageous to automate such tasks. By using AI systems however, malicious parties also inherit their weaknesses, most notably the vulnerability to adversarial samples. In this work, we propose the use of adversarial learning as a defensive tool to obfuscate and mask side-channel information. We demonstrate the viability of this approach by first training CNNs and other machine learning classifiers on leakage trace of different processes. After training a highly accurate model (99+% accuracy), we test it against adversarial learning. We show that through minimal perturbations to input traces, the defender can run as an attachment to the original process and cloak it against a malicious classifier. Finally, we investigate if an attacker can use adversarial defense methods, adversarial re-training and defensive distillation to protect the model. Our results show that even in the presence of an intelligent adversary that employs such techniques, adversarial learning methods still manage to successfully craft perturbations hence the proposed cloaking methodology succeeds.