Poisoning the (Data) Well in ML-Based CAD: A Case Study of Hiding Lithographic Hotspots

Poisoning the (Data) Well in ML-Based CAD: A Case Study of Hiding Lithographic Hotspots
复制标题

DOI:
10.23919/date48585.2020.9116489
复制
发表时间:
2020-03
期刊:
2020 Design, Automation & Test in Europe Conference & Exhibition (DATE)
影响因子:
--
通讯作者:
Kang Liu;Benjamin Tan;R. Karri;S. Garg
Kang Liu;Benjamin Tan;R. Karri;S. Garg
中科院分区:
其他
文献类型:
--
作者:
Kang Liu;Benjamin Tan;R. Karri;S. Garg

文献摘要

相似文献

机器学习(ML)在计算机辅助设计(CAD)流程的许多部分提供了最先进的性能。然而,深度神经网络(dnn)容易受到各种对抗性攻击,包括数据中毒以破坏训练以插入后门。对训练数据完整性的敏感性是一个安全漏洞,特别是考虑到恶意的内部人员想要引起有针对性的神经网络错误行为。在本研究中,我们通过训练数据中毒来探索光刻热点检测中的这种威胁,其中布局剪辑中的热点可以在推理时通过在输入中包含触发形状来“隐藏”。我们证明了训练数据中毒攻击是可行的和隐蔽的,证明了一个后门神经网络在干净的输入上正常执行,但当后门触发器存在时,它在输入上表现不佳。此外,我们的结果提出了一些关于基于ml的CAD系统鲁棒性的基本问题。
Machine learning (ML) provides state-of-the-art performance in many parts of computer-aided design (CAD) flows. However, deep neural networks (DNNs) are susceptible to various adversarial attacks, including data poisoning to compromise training to insert backdoors. Sensitivity to training data integrity presents a security vulnerability, especially in light of malicious insiders who want to cause targeted neural network misbehavior. In this study, we explore this threat in lithographic hotspot detection via training data poisoning, where hotspots in a layout clip can be "hidden" at inference time by including a trigger shape in the input. We show that training data poisoning attacks are feasible and stealthy, demonstrating a backdoored neural network that performs normally on clean inputs but misbehaves on inputs when a backdoor trigger is present. Furthermore, our results raise some fundamental questions about the robustness of ML-based systems in CAD.