Cache Telepathy: Leveraging Shared Resource Attacks to Learn DNN Architectures

Cache Telepathy: Leveraging Shared Resource Attacks to Learn DNN Architectures
复制标题

DOI:
--
复制
发表时间:
2018-08
期刊:
ArXiv
影响因子:
--
通讯作者:
Mengjia Yan;Christopher W. Fletcher;J. Torrellas
Mengjia Yan;Christopher W. Fletcher;J. Torrellas
中科院分区:
其他
文献类型:
--
作者:
Mengjia Yan;Christopher W. Fletcher;J. Torrellas

文献摘要

相似文献

深度神经网络(DNNS)因其在各种机器学习任务中获得良好准确性的能力而迅速变得无处不在。 DNN的架构(即其超参数)广泛地决定了DNN的准确性和性能,并且通常是机密的。在云中攻击DNN以获得其体系结构可能会提供主要的商业价值。此外,获得DNN的架构有助于其他现有的DNN攻击。本文介绍了缓存心灵感应:一种快速准确的机制,可以使用缓存侧通道窃取DNN的架构。我们的攻击是基于DNN推论的洞察力,严重依赖瓷砖Gemm(广义矩阵倍增),并且DNN体系结构参数决定了GEMM调用的数量和GEMM函数中使用的矩阵的尺寸。这些信息可以通过缓存侧通道泄漏。本文使用Prime+探针和冲洗+重新加载来攻击运行OpenBlas和Intel MKL库的VGG和Resnet DNN。我们的攻击可有效地通过大大减少目标DNN体系结构的搜索空间来帮助获得架构。例如,对于使用OpenBlas的VGG,它将搜索空间从$ 10^{35} $架构缩小到仅16。
Deep Neural Networks (DNNs) are fast becoming ubiquitous for their ability to attain good accuracy in various machine learning tasks. A DNN's architecture (i.e., its hyper-parameters) broadly determines the DNN's accuracy and performance, and is often confidential. Attacking a DNN in the cloud to obtain its architecture can potentially provide major commercial value. Further, attaining a DNN's architecture facilitates other, existing DNN attacks. This paper presents Cache Telepathy: a fast and accurate mechanism to steal a DNN's architecture using the cache side channel. Our attack is based on the insight that DNN inference relies heavily on tiled GEMM (Generalized Matrix Multiply), and that DNN architecture parameters determine the number of GEMM calls and the dimensions of the matrices used in the GEMM functions. Such information can be leaked through the cache side channel. This paper uses Prime+Probe and Flush+Reload to attack VGG and ResNet DNNs running OpenBLAS and Intel MKL libraries. Our attack is effective in helping obtain the architectures by very substantially reducing the search space of target DNN architectures. For example, for VGG using OpenBLAS, it reduces the search space from more than $10^{35}$ architectures to just 16.