GINN: Fast GPU-TEE Based Integrity for Neural Network Training

GINN: Fast GPU-TEE Based Integrity for Neural Network Training
复制标题

DOI:
10.1145/3508398.3511503
复制
发表时间:
2022-04
期刊:
Proceedings of the Twelfth ACM Conference on Data and Application Security and Privacy
影响因子:
--
通讯作者:
Aref Asvadishirehjini;Murat Kantarcioglu;B. Malin
Aref Asvadishirehjini;Murat Kantarcioglu;B. Malin
中科院分区:
其他
文献类型:
--
作者:
Aref Asvadishirehjini;Murat Kantarcioglu;B. Malin

文献摘要

被引文献

相似文献

基于深度神经网络(DNN)的机器学习模型越来越多地部署在各种各样的应用中,从自动驾驶汽车到COVID-19诊断。为了支持训练DNN所需的计算能力,具有专用图形处理单元(GPU)硬件支持的云环境已成为关键基础设施。然而,有许多完整性的挑战与外包计算使用GPU的权力,由于其固有的缺乏保障,以确保计算的完整性。已经开发了各种方法来解决这些挑战,建立在可信执行环境(TEE)上。然而,没有现有的方法可扩展以支持用于繁重工作负载的现实的完整性保持DNN模型训练(例如,深度架构和数百万个训练示例),而不会对性能造成重大影响。为了减轻纯TEE(即,完全完整性)和纯GPU(即,没有完整性),我们将所选计算步骤的联合收割机随机验证与DNN超参数的系统调整(例如,狭窄的梯度剪切范围),这限制了攻击者任意移动模型参数的能力。实验分析表明,新方法可以实现比纯基于TEE的解决方案高2倍到20倍的性能改进,同时保证极高的完整性概率(例如,0.999),以应对最先进的DNN后门攻击。
Machine learning models based on Deep Neural Networks (DNNs) are increasingly deployed in a wide variety of applications, ranging from self-driving cars to COVID-19 diagnosis. To support the computational power necessary to train a DNN, cloud environments with dedicated Graphical Processing Unit (GPU) hardware support have emerged as critical infrastructure. However, there are many integrity challenges associated with outsourcing the computation to use GPU power, due to its inherent lack of safeguards to ensure computational integrity. Various approaches have been developed to address these challenges, building on trusted execution environments (TEE). Yet, no existing approach scales up to support realistic integrity-preserving DNN model training for heavy workloads (e.g., deep architectures and millions of training examples) without sustaining a significant performance hit. To mitigate the running time difference between pure TEE (i.e., full integrity) and pure GPU (i.e., no integrity) , we combine random verification of selected computation steps with systematic adjustments of DNN hyperparameters (e.g., a narrow gradient clipping range), which limits the attacker's ability to shift the model parameters arbitrarily. Experimental analysis shows that the new approach can achieve a 2X to 20X performance improvement over a pure TEE-based solution while guaranteeing an extremely high probability of integrity (e.g., 0.999) with respect to state-of-the-art DNN backdoor attacks.