Neighbors From Hell: Voltage Attacks Against Deep Learning Accelerators on Multi-Tenant FPGAs

Neighbors From Hell: Voltage Attacks Against Deep Learning Accelerators on Multi-Tenant FPGAs
复制标题

来自地狱的邻居:针对多租户 FPGA 上的深度学习加速器的电压攻击

DOI:
10.1109/icfpt51103.2020.00023
复制
发表时间:
2020
期刊:
2020 International Conference on Field-Programmable Technology (ICFPT)
影响因子:
--
通讯作者:
Vaughn Betz
Vaughn Betz
中科院分区:
--
文献类型:
--
作者:
Andrew Boutros;Mathew Hall;Nicolas Papernot;Vaughn Betz

文献摘要

参考文献

被引文献

相似文献

现场可编程门阵列(FPGA)由于其灵活性和能效,正在成为无数数据中心应用的广泛使用的加速器。在这些应用中,FPGA在加速低延迟实时深度学习(DL)推理方面表现出了良好的效果,这正在成为许多最终用户应用不可或缺的组件。随着可由多个用户共享的虚拟化云FPGA的新兴研究方向,基于FPGA的DL加速器的安全性方面需要仔细考虑。在这项工作中,我们评估了DL加速器在多租户FPGA场景中对基于电压的完整性攻击的安全性。我们首先证明了这种攻击的可行性,在一个国家的最先进的Stratix 10卡使用不同的攻击者电路,在逻辑上和物理上隔离在一个单独的攻击者的角色,并且不能被标记为恶意电路由传统的比特流检查器。我们表明,积极的时钟门控,一种有效的节能技术,也可以是一个潜在的安全威胁,在现代FPGA。然后,我们对以受害者角色运行ImageNet分类的DL加速器进行攻击,以评估DL模型对对手引起的时序故障的固有弹性。我们发现,即使使用最强的攻击者电路,DL加速器的预测精度不会受到影响时,在其安全的工作频率运行。此外,我们可以通过对DL加速器进行超频来实现1.18 - 1.31倍的推理性能,而不会影响其预测精度。
Field-programmable gate arrays (FPGAs) are becoming widely used accelerators for a myriad of datacenter applications due to their flexibility and energy efficiency. Among these applications, FPGAs have shown promising results in accelerating low-latency real-time deep learning (DL) inference, which is becoming an indispensable component of many end-user applications. With the emerging research direction towards virtualized cloud FPGAs that can be shared by multiple users, the security aspect of FPGA-based DL accelerators requires careful consideration. In this work, we evaluate the security of DL accelerators against voltage-based integrity attacks in a multi-tenant FPGA scenario. We first demonstrate the feasibility of such attacks on a state-of-the-art Stratix 10 card using different attacker circuits that are logically and physically isolated in a separate attacker role, and cannot be flagged as malicious circuits by conventional bitstream checkers. We show that aggressive clock gating, an effective power-saving technique, can also be a potential security threat in modern FPGAs. Then, we carry out the attack on a DL accelerator running ImageNet classification in the victim role to evaluate the inherent resilience of DL models against timing faults induced by the adversary. We find that, even when using the strongest attacker circuit, the prediction accuracy of the DL accelerator is not compromised when running at its safe operating frequency. Furthermore, we can achieve 1.18-1.31× higher inference performance by over-clocking the DL accelerator without affecting its prediction accuracy.
DOI: --
发表时间: 2020-11
期刊: ArXiv
影响因子: --
作者:
A. S. Rakin;Yukui Luo;Xiaolin Xu;Deliang Fan
通讯作者: A. S. Rakin;Yukui Luo;Xiaolin Xu;Deliang Fan
使用云 FPGA 中的环形振荡器测量长线泄漏
DOI: 10.1109/fpl.2019.00017
发表时间: 2019
期刊: International Conference on Field-Programmable Logic and Applications
影响因子: --
作者:
Giechaskiel, Ilias;Rasmussen, Kasper Bonne;Szefer, Jakub
通讯作者: Szefer, Jakub