A ThreshoId-ImpIementation-Based Neural-Network Accelerator Securing Model Parameters and Inputs Against Power Side-Channel Attacks

A ThreshoId-ImpIementation-Based Neural-Network Accelerator Securing Model Parameters and Inputs Against Power Side-Channel Attacks
复制标题

基于阈值实现的神经网络加速器保护模型参数和输入免受电源侧通道攻击

DOI:
10.1109/isscc42614.2022.9731598
复制
发表时间:
2022
期刊:
2022 IEEE International Solid- State Circuits Conference (ISSCC)
影响因子:
--
通讯作者:
A. Chandrakasan
A. Chandrakasan
中科院分区:
--
文献类型:
--
作者:
Saurav Maji;Utsav Banerjee;Samuel H. Fuller;A. Chandrakasan

文献摘要

被引文献

相似文献

神经网络(NN)硬件加速器已被广泛部署在低功率批次节点上,以进行节能决策。嵌入式NN实施可以使用本地存储的专有模型,并且可以通过私人投入(例如,具有患者特异性生物医学分类器的卫生监测器[6])进行操作,这不得披露。侧通道攻击(SCA)是嵌入式系统中的主要问题,在该系统中,对操作硬件的物理访问可以使攻击者通过通过功耗,时间和电磁排放来利用信息泄漏来恢复秘密数据[1,7,8]。如图34.3.1所示,嵌入式NN实现上的SCA可以揭示模型参数[9]以及输入[10]。为了解决这些问题,我们提出了一种能量 - 有效的ASLC解决方案,用于保护模型参数和输入数据,以防止基于功率的SCA。
Neural network (NN) hardware accelerators are being widely deployed on low-power loT nodes for energy-efficient decision making. Embedded NN implementations can use locally stored proprietary models, and may operate over private inputs (e.g., health monitors with patient-specific biomedical classifiers [6]), which must not be disclosed. Side-channel attacks (SCA) are a major concern in embedded systems where physical access to the operating hardware can allow attackers to recover secret data by exploiting information leakage through power consumption, timing and electromagnetic emissions [1, 7, 8]. As shown in Fig. 34.3.1, SCA on embedded NN implementations can reveal the model parameters [9] as well as the inputs [10]. To address these concerns, we present an energy - efficient ASlC solution for protecting both the model parameters and the input data against power-based SCA.