Clairvoyance: Exploiting Far-field EM Emanations of GPU to "See" Your DNN Models through Obstacles at a Distance

Clairvoyance: Exploiting Far-field EM Emanations of GPU to "See" Your DNN Models through Obstacles at a Distance
复制标题

DOI:
10.1109/spw54247.2022.9833894
复制
发表时间:
2022-05
期刊:
2022 IEEE Security and Privacy Workshops (SPW)
影响因子:
--
通讯作者:
Sisheng Liang;Zihao Zhan;Fan Yao;Long Cheng;Zhenkai Zhang
Sisheng Liang;Zihao Zhan;Fan Yao;Long Cheng;Zhenkai Zhang
中科院分区:
其他
文献类型:
--
作者:
Sisheng Liang;Zihao Zhan;Fan Yao;Long Cheng;Zhenkai Zhang

文献摘要

相似文献

深度神经网络(DNN)在现实世界的应用中变得越来越流行,它们被认为是企业的宝贵资产。近年来,已经制定了许多模型提取攻击,可以成功窃取专有的 DNN 模型。然而,以前的模型提取攻击需要对目标模型进行逻辑访问或对受害机器进行物理访问,因此不适合在外部攻击者在附近但有一定距离的情况下执行模型窃取。在本文中,我们提出了一种名为 Clairvoyance 的新模型提取攻击,它利用 GPU 发出的某些远场电磁信号来窃取距离受害机器几米远的 DNN 模型,即使中间有一些障碍物。使用 Clairvoyance,攻击者可以有效地推断出 DNN 架构(例如,层数及其类型)和层配置(例如,内核数量、层大小和步幅大小)。我们使用几个案例研究(例如 VGG 和 ResNet)来证明其有效性。
Deep neural networks (DNNs) are becoming increasingly popular in real-world applications, and they are considered valuable assets of enterprises. In recent years, a number of model extraction attacks have been formulated that can be mounted to successfully steal proprietary DNN models. Nevertheless, previous model extraction attacks require either logical access to the target models or physical access to the victim machines, and thus are not suitable for performing model stealing in scenarios where an outside attacker is in the proximity but at a distance.In this paper, we propose a new model extraction attack named Clairvoyance that exploits certain far-field electromagnetic signals emanated from a GPU to steal DNN models at a distance of several meters away from the victim machine even with some obstacles in-between. Using Clairvoyance, an attacker can effectively deduce DNN architectures (e.g., the number of layers and their types) and layer configurations (e.g., the number of kernels, sizes of layers, and sizes of strides). We use several case studies (e.g., VGG and ResNet) to demonstrate its effectiveness.