Poisoning the (Data) Well in ML-Based CAD: A Case Study of Hiding Lithographic Hotspots
Poisoning the (Data) Well in ML-Based CAD: A Case Study of Hiding Lithographic Hotspots
复制标题
DOI:
10.23919/date48585.2020.9116489
复制
发表时间:
2020-03
期刊:
影响因子:
--
通讯作者:
Kang Liu;Benjamin Tan;R. Karri;S. Garg
中科院分区:
文献类型:
--
作者:
Kang Liu;Benjamin Tan;R. Karri;S. Garg
Machine learning (ML) provides state-of-the-art performance in many parts of computer-aided design (CAD) flows. However, deep neural networks (DNNs) are susceptible to various adversarial attacks, including data poisoning to compromise training to insert backdoors. Sensitivity to training data integrity presents a security vulnerability, especially in light of malicious insiders who want to cause targeted neural network misbehavior. In this study, we explore this threat in lithographic hotspot detection via training data poisoning, where hotspots in a layout clip can be "hidden" at inference time by including a trigger shape in the input. We show that training data poisoning attacks are feasible and stealthy, demonstrating a backdoored neural network that performs normally on clean inputs but misbehaves on inputs when a backdoor trigger is present. Furthermore, our results raise some fundamental questions about the robustness of ML-based systems in CAD.