Seeds of SEED: NMT-Stroke: Diverting Neural Machine Translation through Hardware-based Faults

Seeds of SEED: NMT-Stroke: Diverting Neural Machine Translation through Hardware-based Faults
复制标题

DOI:
10.1109/seed51797.2021.00019
复制
发表时间:
2021-09
期刊:
2021 International Symposium on Secure and Private Execution Environment Design (SEED)
影响因子:
--
通讯作者:
Kunbei Cai;Md Hafizul Islam Chowdhuryy;Zhenkai Zhang;Fan Yao
Kunbei Cai;Md Hafizul Islam Chowdhuryy;Zhenkai Zhang;Fan Yao
中科院分区:
其他
文献类型:
--
作者:
Kunbei Cai;Md Hafizul Islam Chowdhuryy;Zhenkai Zhang;Fan Yao

文献摘要

相似文献

深度学习的快速发展大大提高了自然语言处理(NLP)在语言建模方面的性能。硬件安全研究的最新进展已经证明,基于硬件的威胁可以严重危害计算系统的完整性(例如,静态数据的故障攻击)。利用这种硬件漏洞的内部对手正在成为一个主要的安全问题。然而,硬件故障对运行NLP模型的系统的影响还没有完全理解。在本文中,我们进行了第一次调查,基于硬件的故障注入现代神经机器翻译(NMT)模型。我们发现,与神经网络分类器(例如,CNN),对NMT模型的故障攻击提出了独特的挑战。我们提出了一种新的攻击框架NMT-中风,可以恶意转移受害者NMT模型的翻译建模内存故障注入rowhammer攻击向量。我们设计了一个错误注入策略,以尽量减少所需的位翻转,这将误导翻译到一个任意的自然输出句子。我们对最先进的基于transformer的NMT模型的评估表明,NMT-Stroke可以通过错误的最小参数位有效地诱导攻击者期望的和语言上合理的翻译。我们的工作强调了理解新兴NLP模型在存在硬件漏洞的情况下的鲁棒性的重要性,这可能会导致未来新的研究方向。
The rapid development of deep learning has significantly bolstered the performance of natural language processing (NLP) in the form of language modeling. Recent advances in hardware security studies have demonstrated that hardware-based threats can severely jeopardize the integrity of computing systems (e.g., fault attacks for data at rest). Internal adversaries exploiting such hardware vulnerabilities are becoming a major security concern. Yet the impact of hardware faults on systems running NLP models has not been fully understood.In this paper, we perform the first investigation of hardware-based fault injections in modern neural machine translation (NMT) models. We find that compared to neural network classifiers (e.g., CNNs), fault attacks on NMT models present unique challenges. We propose a novel attack framework–NMT-Stroke–that can maliciously divert the translation of a victim NMT model by modeling memory fault injections with the rowhammer attack vector. We design a fault injection strategy to minimize bit flips needed, which would mislead the translation to an arbitrary natural output sentence. Our evaluation on state-of-the-art Transformer-based NMT models shows that NMT-Stroke can effectively induce the attacker-desired and linguistically sound translation by faulting minimal parameter bits. Our work highlights the significance of understanding the robustness of emerging NLP models with the presence of hardware vulnerabilities, which could lead to future new research directions.