Preventing DNN Model IP Theft via Hardware Obfuscation

Preventing DNN Model IP Theft via Hardware Obfuscation
复制标题

通过硬件混淆防止 DNN 模型 IP 盗窃

DOI:
10.1109/jetcas.2021.3076151
复制
发表时间:
2021
影响因子:
4.6
通讯作者:
Kundu, Sandip
Kundu, Sandip
中科院分区:
工程技术2区
文献类型:
--
作者:
Goldstein, Brunno F.;Patil, Vinay C.;Ferreira, Victor C.;Nery, Alexandre S.;Franca, Felipe M.;Kundu, Sandip

文献摘要

参考文献

被引文献

相似文献

训练准确的深度学习 (DL) 模型需要大量的训练数据、标记数据的大量工作、大量的计算资源和大量的领域专业知识。简而言之,它们的开发成本很高。因此,保护​​这些模型(知识产权(IP)的宝贵宝库)免受模型窃取/克隆攻击至关重要。当今的移动处理器配备神经处理单元 (NPU),可加速深度学习模型的执行。在 NPU 上执行的深度学习模型很容易受到侧通道攻击的超参数提取和总线监控攻击的模型参数盗窃的影响。本文提出了一种新颖的解决方案,通过轻量级、带密钥的模型混淆方案,在模型分发和部署/执行期间防止 NPU 中的 DL IP 盗窃。未经授权使用此类模型会导致分类不准确。此外,我们提出了一个理想的端到端深度学习可信系统,其组成包括:1)通过硬件信任根和公钥加密基础设施(PKI)进行模型分发,2)通过低延迟内存加密进行模型执行。我们证明,我们提出的混淆解决方案可以实现知识产权保护目标,而无需专门培训或牺牲模型的准确性。此外,所提出的混淆机制保留了输出类分布,同时降低了未经授权方的模型准确性,涵盖了被黑客攻击模型的任何证据。
Training accurate deep learning (DL) models require large amounts of training data, significant work in labeling the data, considerable computing resources, and substantial domain expertise. In short, they are expensive to develop. Hence, protecting these models, which are valuable storehouses of intellectual properties (IP), against model stealing/cloning attacks is of paramount importance. Today's mobile processors feature Neural Processing Units (NPUs) to accelerate the execution of DL models. DL models executing on NPUs are vulnerable to hyperparameter extraction via side-channel attacks and model parameter theft via bus monitoring attacks. This paper presents a novel solution to defend against DL IP theft in NPUs during model distribution and deployment/execution via lightweight, keyed model obfuscation scheme. Unauthorized use of such models results in inaccurate classification. In addition, we present an ideal end-to-end deep learning trusted system composed of: 1) model distribution via hardware root-of-trust and public-key cryptography infrastructure (PKI) and 2) model execution via low-latency memory encryption. We demonstrate that our proposed obfuscation solution achieves IP protection objectives without requiring specialized training or sacrificing the model's accuracy. In addition, the proposed obfuscation mechanism preserves the output class distribution while degrading the model's accuracy for unauthorized parties, covering any evidence of a hacked model.
防止机器学习硬件加速器中的神经网络模型渗透
DOI: 10.1109/asianhost.2018.8607161
发表时间: 2018
期刊: 2018 Asian Hardware Oriented Security and Trust Symposium (AsianHOST)
影响因子: --
作者:
Mihailo Isakov;Lake Bu;Hai Cheng;Michel A. Kinsy
通讯作者: Michel A. Kinsy
>100 Gbps 内联 AES-GCM 硬件引擎以及 SGX Enclave 和 FPGA 加速器设备之间受保护的 DMA 传输
DOI: --
发表时间: 2020
期刊: IACR Cryptology ePrint Archive
影响因子: --
作者:
Santosh K. Ghosh;L. S. Kida;S. Desai;Reshma Lal
通讯作者: Reshma Lal
深度学习模型的硬件辅助知识产权保护
DOI: --
发表时间: 2020
期刊: Design Automation Conference
影响因子: --
作者:
Abhishek Chakraborty;Ankit Mondal;Ankur Srivastava
通讯作者: Ankur Srivastava