Bias Busters: Robustifying DL-Based Lithographic Hotspot Detectors Against Backdooring Attacks

Bias Busters: Robustifying DL-Based Lithographic Hotspot Detectors Against Backdooring Attacks
复制标题

DOI:
10.1109/tcad.2020.3033749
复制
发表时间:
2020-04
影响因子:
2.9
通讯作者:
Kang Liu;Benjamin Tan;Gaurav Rajavendra Reddy;S. Garg;Y. Makris;R. Karri
Kang Liu;Benjamin Tan;Gaurav Rajavendra Reddy;S. Garg;Y. Makris;R. Karri
中科院分区:
计算机科学3区
文献类型:
--
作者:
Kang Liu;Benjamin Tan;Gaurav Rajavendra Reddy;S. Garg;Y. Makris;R. Karri

文献摘要

被引文献

相似文献

深度学习在整个CAD工具流中提供了潜在的改进,其中一个很有前途的应用是光刻热点检测。然而,DL技术已经被证明特别容易受到推理和训练时间的对抗性攻击。最近的研究表明,一小部分恶意的物理设计人员可以在基于DL的热点检测器的训练阶段偷偷地对其进行“后门”,以便它准确地将常规布局剪辑分类,但将包含特殊制作的触发器形状的热点预测为非热点。我们提出了一种新的训练数据扩充策略,作为对这种回溯攻击的有力防御。辩护的工作原理是消除训练数据中引入的故意偏见,但不需要知道哪些训练样本有毒或后门触发的性质。我们的结果表明,防御可以将攻击成功率从84%大幅降低到~0%。
Deep learning (DL) offers potential improvements throughout the CAD tool-flow, one promising application being lithographic hotspot detection. However, DL techniques have been shown to be especially vulnerable to inference and training time adversarial attacks. Recent work has demonstrated that a small fraction of malicious physical designers can stealthily “backdoor” a DL-based hotspot detector during its training phase such that it accurately classifies regular layout clips but predicts hotspots containing a specially crafted trigger shape as nonhotspots. We propose a novel training data augmentation strategy as a powerful defense against such backdooring attacks. The defense works by eliminating the intentional biases introduced in the training data but does not require knowledge of which training samples are poisoned or the nature of the backdoor trigger. Our results show that the defense can drastically reduce the attack success rate from 84% to ~0%.