DNNCloak: Secure DNN Models Against Memory Side-channel Based Reverse Engineering Attacks

DNNCloak: Secure DNN Models Against Memory Side-channel Based Reverse Engineering Attacks
复制标题

DOI:
10.1109/iccd56317.2022.00023
复制
发表时间:
2022-10
期刊:
2022 IEEE 40th International Conference on Computer Design (ICCD)
影响因子:
--
通讯作者:
Yuezhi Che;Rujia Wang
Yuezhi Che;Rujia Wang
中科院分区:
其他
文献类型:
--
作者:
Yuezhi Che;Rujia Wang

文献摘要

被引文献

相似文献

随着深度神经网络(deep neural networks, DNN)的应用范围越来越广,模型的训练成本越来越高,DNN模型的结构已经成为一种有价值的知识产权,需要受到保护。然而,通过利用侧通道泄漏来逆转DNN模型已经以各种方式得到了证明。即使模型被加密并且处理硬件单元是可信的,攻击者仍然可以通过侧通道提取模型的结构和关键参数,这可能会带来重大的商业风险。在本文中,我们首先分析了DNN模型上具有代表性的内存侧信道攻击,并确定了泄漏的主要原因。我们还发现,用于保护模型参数的完全加密可能会增加大量的开销。根据我们的观察,我们提出了DNNCloak,这是一个轻量级和安全的框架,旨在减轻对常见DNN架构的逆向工程攻击。DNNCloak包括一组混淆方案,增加了DNN结构逆向工程的难度。此外,DNNCloak通过有效的矩阵置换方案减少了全权加密的开销,从而减少了内存访问时间,增强了对模型参数再训练攻击的安全性。最后,我们展示了DNNCloak如何以最小的性能开销有效地保护DNN模型免受侧信道攻击。
As deep neural networks (DNN) expand their attention into various domains and the high cost of training a model, the structure of a DNN model has become a valuable intellectual property and needs to be protected. However, reversing DNN models by exploiting side-channel leakage has been demonstrated in various ways. Even if the model is encrypted and the processing hardware units are trusted, the attacker can still extract the model’s structure and critical parameters through side channels, potentially posing significant commercial risks. In this paper, we begin by analyzing representative memory side-channel attacks on DNN models and identifying the primary causes of leakage. We also find that the full encryption used to protect model parameters could add extensive overhead. Based on our observations, we propose DNNCloak, a lightweight and secure framework aiming at mitigating reverse engineering attacks on common DNN architectures. DNNCloak includes a set of obfuscation schemes that increase the difficulty of reverse-engineering the DNN structure. Additionally, DNNCloak reduces the overhead of full weights encryption with an efficient matrix permutation scheme, resulting in reduced memory access time and enhanced security against retraining attacks on the model parameters. At last, we show how DNNCloak can defend DNN models from side-channel attacks effectively, with minimal performance overhead.