ModelShield: A Generic and Portable Framework Extension for Defending Bit-Flip based Adversarial Weight Attacks

ModelShield: A Generic and Portable Framework Extension for Defending Bit-Flip based Adversarial Weight Attacks
复制标题

DOI:
10.1109/iccd53106.2021.00090
复制
发表时间:
2021-10
期刊:
2021 IEEE 39th International Conference on Computer Design (ICCD)
影响因子:
--
通讯作者:
Yanan Guo;Liang Liu;Yueqiang Cheng;Youtao Zhang;Jun Yang
Yanan Guo;Liang Liu;Yueqiang Cheng;Youtao Zhang;Jun Yang
中科院分区:
其他
文献类型:
--
作者:
Yanan Guo;Liang Liu;Yueqiang Cheng;Youtao Zhang;Jun Yang

文献摘要

相似文献

BIT-FLIP攻击(BFA)已通过利用Rowhammer翻转存储在内存中的DNN权重来成为对深神经网络(DNN)安全的最严重威胁之一。 。权重。由于最多可以降低DNN的推理,因此我们对模型壳进行了两个优化,我们可以轻松地安装在流行的DNN框架中。 ModelShield,结果表明,它可以有效地捍卫BFA,其性能开销不到2%。
Bit-flip attack (BFA) has become one of the most serious threats to Deep Neural Network (DNN) security. By utilizing Rowhammer to flip the bits of DNN weights stored in memory, the attacker can turn a functional DNN into a random output generator. In this work, we propose ModelShield, a defense mechanism against BFA, based on protecting the integrity of weights using hash verification. ModelShield performs real-time integrity verification on DNN weights. Since this can slow down a DNN inference by up to 7×, we further propose two optimizations for ModelShield. We implement ModelShield as a lightweight software extension that can be easily installed into popular DNN frameworks. We test both the security and performance of ModelShield, and the results show that it can effectively defend BFA with less than 2% performance overhead.