Guarding Machine Learning Hardware Against Physical Side-channel Attacks

Guarding Machine Learning Hardware Against Physical Side-channel Attacks
复制标题

DOI:
10.1145/3465377
复制
发表时间:
2021-09
期刊:
ACM Journal on Emerging Technologies in Computing Systems (JETC)
影响因子:
--
通讯作者:
Anuj Dubey;Rosario Cammarota;Vikram B. Suresh;Aydin Aysu
Anuj Dubey;Rosario Cammarota;Vikram B. Suresh;Aydin Aysu
中科院分区:
其他
文献类型:
--
作者:
Anuj Dubey;Rosario Cammarota;Vikram B. Suresh;Aydin Aysu

文献摘要

相似文献

由于开发成本的原因,机器学习(ML)模型可能是商业机密。因此,它们需要针对恶意形式的反向工程(例如,在知识产权盗版中)提供保护。随着ML越来越多地转向边缘设备,部分是为了性能,部分是为了隐私利益,这些型号已经变得容易受到所谓的物理侧通道攻击。与密码学相比,ML是一个相对较新的目标,在缺乏已发表文献的背景下提出了旁路分析的问题。新兴的基于边缘的ML设备与为其提供旁路安全的足够防御的研究之间的差距,从而推动了我们的研究。我们的工作为硬件模块中的ML模型开发和组合了不同风格的侧通道防御。提出并优化了基于布尔掩蔽的第一种防御算法。我们首先实现所有被屏蔽的硬件块。然后,我们提出了一种加法器优化,以减少面积和延迟开销。最后,我们将其与基于洗牌的防守相结合。根据所采用的加法器拓扑结构,我们量化了掩蔽的面积延迟开销在5.4×到4.7×之间,并证明了数百万功率迹线的一阶侧信道安全性。此外,混洗反措施阻碍了对我们的一阶掩码实现的直接二阶攻击。
Machine learning (ML) models can be trade secrets due to their development cost. Hence, they need protection against malicious forms of reverse engineering (e.g., in IP piracy). With a growing shift of ML to the edge devices, in part for performance and in part for privacy benefits, the models have become susceptible to the so-called physical side-channel attacks. ML being a relatively new target compared to cryptography poses the problem of side-channel analysis in a context that lacks published literature. The gap between the burgeoning edge-based ML devices and the research on adequate defenses to provide side-channel security for them thus motivates our study. Our work develops and combines different flavors of side-channel defenses for ML models in the hardware blocks. We propose and optimize the first defense based on Boolean masking. We first implement all the masked hardware blocks. We then present an adder optimization to reduce the area and latency overheads. Finally, we couple it with a shuffle-based defense. We quantify that the area-delay overhead of masking ranges from 5.4× to 4.7× depending on the adder topology used and demonstrate a first-order side-channel security of millions of power traces. Additionally, the shuffle countermeasure impedes a straightforward second-order attack on our first-order masked implementation.