ModelShield: A Generic and Portable Framework Extension for Defending Bit-Flip based Adversarial Weight Attacks
ModelShield: A Generic and Portable Framework Extension for Defending Bit-Flip based Adversarial Weight Attacks
复制标题
DOI:
10.1109/iccd53106.2021.00090
复制
发表时间:
2021-10
期刊:
影响因子:
--
通讯作者:
Yanan Guo;Liang Liu;Yueqiang Cheng;Youtao Zhang;Jun Yang
中科院分区:
文献类型:
--
作者:
Yanan Guo;Liang Liu;Yueqiang Cheng;Youtao Zhang;Jun Yang
Bit-flip attack (BFA) has become one of the most serious threats to Deep Neural Network (DNN) security. By utilizing Rowhammer to flip the bits of DNN weights stored in memory, the attacker can turn a functional DNN into a random output generator. In this work, we propose ModelShield, a defense mechanism against BFA, based on protecting the integrity of weights using hash verification. ModelShield performs real-time integrity verification on DNN weights. Since this can slow down a DNN inference by up to 7×, we further propose two optimizations for ModelShield. We implement ModelShield as a lightweight software extension that can be easily installed into popular DNN frameworks. We test both the security and performance of ModelShield, and the results show that it can effectively defend BFA with less than 2% performance overhead.