MirrorNet: A TEE-Friendly Framework for Secure On-Device DNN Inference

MirrorNet: A TEE-Friendly Framework for Secure On-Device DNN Inference
复制标题

DOI:
10.1109/iccad57390.2023.10323746
复制
发表时间:
2023-10
期刊:
2023 IEEE/ACM International Conference on Computer Aided Design (ICCAD)
影响因子:
--
通讯作者:
Ziyu Liu;Yukui Luo;Shijin Duan;Tong Zhou;Xiaolin Xu
Ziyu Liu;Yukui Luo;Shijin Duan;Tong Zhou;Xiaolin Xu
中科院分区:
其他
文献类型:
--
作者:
Ziyu Liu;Yukui Luo;Shijin Duan;Tong Zhou;Xiaolin Xu

文献摘要

被引文献

相似文献

深度神经网络(DNN)模型已在边缘设备中盛行,以进行实时推断。但是,它们容易受到模型提取攻击的影响,需要保护。现有的国防方法要么无法完全保护模型机密性,要么导致重大的延迟问题。为了克服这些挑战,本文介绍了Mirrornet,该挑战利用可信赖的执行环境(TEE)来实现安全的内在DNN推断。它为任何给定的DNN模型生成了TEE友好的实现,以保护模型机密性,同时满足TEE的严格计算和存储约束。该框架由两个关键组成部分组成:骨干模型(BackboneNet),该模型存储在正常世界中,但可实现较低的推理精度,而伴随部分监视器(CPM),一个保存在安全世界中的轻量级镜像分支,保留模型机密。在推断期间,CPM监视后苯甲部中间体并纠正分类输出以达到更高的精度。为了提高灵活性,MirrorNet结合了两个模块:CPM策略生成器,该策略生成各种保护策略和性能模拟器,该模块估算了每种策略的性能并选择最佳的效果。广泛的实验证明了MirrOrNet在提供安全保证的同时保持低计算延迟的有效性,这使MirrorNet成为安全的智障DNN推断的实用且有前途的解决方案。为了进行评估,MirrorNet可以在身份验证和非法使用之间达到18.6%的精度差距,而仅引入0.99%的硬件开销。
Deep neural network (DNN) models have become prevalent in edge devices for real-time inference. However, they are vulnerable to model extraction attacks and require protection. Existing defense approaches either fail to fully safeguard model confidentiality or result in significant latency issues. To overcome these challenges, this paper presents MirrorNet, which leverages Trusted Execution Environment (TEE) to enable secure on-device DNN inference. It generates a TEE-friendly implementation for any given DNN model to protect the model confidentiality, while meeting the stringent computation and storage constraints of TEE. The framework consists of two key components: the backbone model (BackboneNet), which is stored in the normal world but achieves lower inference accuracy, and the Companion Partial Monitor (CPM), a lightweight mirrored branch stored in the secure world, preserving model confidentiality. During inference, the CPM monitors the intermediate results from the BackboneNet and rectifies the classification output to achieve higher accuracy. To enhance flexibility, MirrorNet incorporates two modules: the CPM Strategy Generator, which generates various protection strategies, and the Performance Emulator, which estimates the performance of each strategy and selects the most optimal one. Extensive experiments demonstrate the effectiveness of MirrorNet in providing security guarantees while maintaining low computation latency, making MirrorNet a practical and promising solution for secure on-device DNN inference. For the evaluation, MirrorNet can achieve a 18.6% accuracy gap between authenticated and illegal use, while only introducing 0.99% hardware overhead.