Remote Power Side-Channel Attacks on CNN Accelerators in FPGAs

Remote Power Side-Channel Attacks on CNN Accelerators in FPGAs
复制标题

对 FPGA 中 CNN 加速器的远程电源侧通道攻击

DOI:
--
复制
发表时间:
2020
期刊:
arXiv.org
影响因子:
--
通讯作者:
R. Tessier
R. Tessier
中科院分区:
--
文献类型:
--
作者:
Shayan Moini;Shanquan Tian;Jakub Szefer;Daniel E. Holcomb;R. Tessier

文献摘要

参考文献

被引文献

相似文献

为了降低成本并增加云FPGA的利用,研究人员最近一直在探索多租户FPGA的概念,其中多个独立用户同时共享相同的FPGA。尽管有好处,但多端却开启了恶意用户与受害者用户在同一FPGA上共同定位并提取敏感信息的可能性。当用户运行正在处理敏感或私人信息的机器学习算法时,此问题变得尤为严重。为了证明危险,本文介绍了对在各种Xilinx FPGA中运行的深神经网络加速器的首次遥控,基于电源的侧道攻击,并使用Amazon Web Services(AWS)F1实例在云FPGA上进行了cloud FPGA。这项工作尤其表明了如何作为深神经网络推断电路的远程获得电压估计,以及如何使用信息来恢复对神经网络的输入。该攻击是通过用于从MNIST手写数字数据库中识别手写图像的二进制卷积神经网络证明的。通过使用精确的时数转换器进行远程电压估计,可以在输入图像和本地FPGA板上的最大归一化交叉相关和恢复的图像之间成功恢复MNIST输入,而在AWS上恢复了77% F1实例。攻击不需要物理访问或对FPGA硬件的修改。
To lower cost and increase the utilization of Cloud FPGAs, researchers have recently been exploring the concept of multi-tenant FPGAs, where multiple independent users simultaneously share the same FPGA. Despite its benefits, multitenancy opens up the possibility of malicious users co-locating on the same FPGA as a victim user, and extracting sensitive information. This issue becomes especially serious when the user is running a machine learning algorithm that is processing sensitive or private information. To demonstrate the dangers, this paper presents the first remote, power-based side-channel attack on a deep neural network accelerator running in a variety of Xilinx FPGAs and also on Cloud FPGAs using Amazon Web Services (AWS) F1 instances. This work in particular shows how to remotely obtain voltage estimates as a deep neural network inference circuit executes, and how the information can be used to recover the inputs to the neural network. The attack is demonstrated with a binarized convolutional neural network used to recognize handwriting images from the MNIST handwritten digit database. With the use of precise time-to-digital converters for remote voltage estimation, the MNIST inputs can be successfully recovered with a maximum normalized cross-correlation of 84% between the input image and the recovered image on local FPGA boards and 77% on AWS F1 instances. The attack requires no physical access nor modifications to the FPGA hardware.
DOI: 10.1109/host45689.2020.9300276
发表时间: 2019-10
期刊: 2020 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)
影响因子: --
作者:
Anuj Dubey;Rosario Cammarota;Aydin Aysu
通讯作者: Anuj Dubey;Rosario Cammarota;Aydin Aysu
使用云 FPGA 中的环形振荡器测量长线泄漏
DOI: 10.1109/fpl.2019.00017
发表时间: 2019
期刊: International Conference on Field-Programmable Logic and Applications
影响因子: --
作者:
Giechaskiel, Ilias;Rasmussen, Kasper Bonne;Szefer, Jakub
通讯作者: Szefer, Jakub