Practical Attacks on Deep Neural Networks by Memory Trojaning

Practical Attacks on Deep Neural Networks by Memory Trojaning
复制标题

DOI:
10.1109/tcad.2020.2995347
复制
发表时间:
2021-06-01
影响因子:
2.9
通讯作者:
Xie, Yuan
Xie, Yuan
中科院分区:
计算机科学3区
文献类型:
--
作者:
Hu, Xing;Zhao, Yang;Xie, Yuan

文献摘要

被引文献

相似文献

深度神经网络(DNN)加速器被广泛应用于计算机视觉、语音识别和机器翻译应用中,其中针对DNN的攻击已经成为人们日益关注的问题。本文重点探讨硬件特洛伊木马攻击对DNNS的影响。特洛伊木马是硬件安全中最具挑战性的威胁模型之一,攻击者在其中插入对原始集成电路(IC)的恶意修改,一旦触发就会导致故障。由于现代IC通常包括第三方知识产权(IP)块,因此此类攻击可由攻击者进行。以前的研究设计了硬件木马来攻击DNN,假设攻击者除了硬件平台外,还完全知道或操纵DNN系统的受害者模型和工具链,但这种威胁模型是严格的,限制了它们的实际采用。在本文中,我们提出了一种内存木马方法,该方法只将恶意逻辑植入到DNN系统的内存控制器中,而不需要操纵工具链或访问受害者模型,因此具有实际应用的可行性。具体地说,我们根据内存访问模式在海量的内存流量中定位输入图像数据,并提出了一种基于检测输入图像几何特征的木马触发机制。大量实验表明,所提出的触发机制即使在存在环境噪声和预处理操作的情况下也是有效的。此外,我们设计和实现了负载,并验证了所提出的木马技术可以有效地对DNN进行非定向攻击和定向攻击。
Deep neural network (DNN) accelerators are widely deployed in computer vision, speech recognition, and machine translation applications, in which attacks on DNNs have become a growing concern. This article focuses on exploring the implications of hardware Trojan attacks on DNNs. Trojans are one of the most challenging threat models in hardware security where adversaries insert malicious modifications to the original integrated circuits (ICs), leading to malfunction once being triggered. Such attacks can be conducted by adversaries because modern ICs commonly include third-party intellectual property (IP) blocks. Previous studies design hardware Trojans to attack DNNs with the assumption that adversaries have full knowledge or manipulation of the DNN systems' victim model and toolchain in addition to the hardware platforms, yet such a threat model is strict, limiting their practical adoption. In this article, we propose a memory Trojan methodology that implants the malicious logics merely into the memory controllers of DNN systems without the necessity of toolchain manipulation or accessing to the victim model and thus is feasible for practical uses. Specifically, we locate the input image data among the massive volume of memory traffics based on memory access patterns and propose a Trojan trigger mechanism based on detecting the geometric feature in input images. Extensive experiments show that the proposed trigger mechanism is effective even in the presence of environmental noises and preprocessing operations. Furthermore, we design and implement the payload and verify that the proposed Trojan technique can effectively conduct both untargeted and targeted attacks on DNNs.