Preventing Neural Network Model Exfiltration in Machine Learning Hardware Accelerators

Preventing Neural Network Model Exfiltration in Machine Learning Hardware Accelerators
复制标题

防止机器学习硬件加速器中的神经网络模型渗透

DOI:
10.1109/asianhost.2018.8607161
复制
发表时间:
2018
期刊:
2018 Asian Hardware Oriented Security and Trust Symposium (AsianHOST)
影响因子:
--
通讯作者:
Michel A. Kinsy
Michel A. Kinsy
中科院分区:
--
文献类型:
--
作者:
Mihailo Isakov;Lake Bu;Hai Cheng;Michel A. Kinsy

文献摘要

被引文献

相似文献

机器学习(ML)模型通常使用私人数据集进行训练,这些数据集收集起来非常昂贵,或者高度敏感,需要使用大量的计算能力。这些模型通常通过在线API公开,或者在现场部署的硬件设备中使用,或者提供给最终用户。这为对手窃取这些ML模型作为收集数据集的代理提供了激励。虽然以前已经研究过基于API的模型渗透,但到目前为止还没有探索过硬件设备上机器学习模型的盗窃和保护。在这项工作中,我们将研究ML模型设计和部署的这一重要方面。我们说明了攻击者如何通过内存探测,侧信道或精心制作的输入攻击来获取模型或模型架构,并提出(1)作为加密替代方案的节能混淆,以及(2)定时侧信道对策。
Machine learning (ML) models are often trained using private datasets that are very expensive to collect, or highly sensitive, using large amounts of computing power. The models are commonly exposed either through online APIs, or used in hardware devices deployed in the field or given to the end users. This provides an incentive for adversaries to steal these ML models as a proxy for gathering datasets. While API-based model exfiltration has been studied before, the theft and protection of machine learning models on hardware devices have not been explored as of now. In this work, we examine this important aspect of the design and deployment of ML models. We illustrate how an attacker may acquire either the model or the model architecture through memory probing, side-channels, or crafted input attacks, and propose (1) power-efficient obfuscation as an alternative to encryption, and (2) timing side-channel countermeasures.