Preventing DNN Model IP Theft via Hardware Obfuscation
Preventing DNN Model IP Theft via Hardware Obfuscation
复制标题
通过硬件混淆防止 DNN 模型 IP 盗窃
DOI:
10.1109/jetcas.2021.3076151
复制
发表时间:
2021
影响因子:
4.6
通讯作者:
Kundu, Sandip
中科院分区:
文献类型:
--
作者:
Goldstein, Brunno F.;Patil, Vinay C.;Ferreira, Victor C.;Nery, Alexandre S.;Franca, Felipe M.;Kundu, Sandip
Training accurate deep learning (DL) models require large amounts of training data, significant work in labeling the data, considerable computing resources, and substantial domain expertise. In short, they are expensive to develop. Hence, protecting these models, which are valuable storehouses of intellectual properties (IP), against model stealing/cloning attacks is of paramount importance. Today's mobile processors feature Neural Processing Units (NPUs) to accelerate the execution of DL models. DL models executing on NPUs are vulnerable to hyperparameter extraction via side-channel attacks and model parameter theft via bus monitoring attacks. This paper presents a novel solution to defend against DL IP theft in NPUs during model distribution and deployment/execution via lightweight, keyed model obfuscation scheme. Unauthorized use of such models results in inaccurate classification. In addition, we present an ideal end-to-end deep learning trusted system composed of: 1) model distribution via hardware root-of-trust and public-key cryptography infrastructure (PKI) and 2) model execution via low-latency memory encryption. We demonstrate that our proposed obfuscation solution achieves IP protection objectives without requiring specialized training or sacrificing the model's accuracy. In addition, the proposed obfuscation mechanism preserves the output class distribution while degrading the model's accuracy for unauthorized parties, covering any evidence of a hacked model.
DOI:
10.1109/asianhost.2018.8607161
发表时间:
2018
期刊:
2018 Asian Hardware Oriented Security and Trust Symposium (AsianHOST)
影响因子:
--
作者:
Mihailo Isakov;Lake Bu;Hai Cheng;Michel A. Kinsy
通讯作者:
Michel A. Kinsy
DOI:
--
发表时间:
2020
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
作者:
Santosh K. Ghosh;L. S. Kida;S. Desai;Reshma Lal
通讯作者:
Reshma Lal
DOI:
--
发表时间:
2020
期刊:
Design Automation Conference
影响因子:
--
作者:
Abhishek Chakraborty;Ankit Mondal;Ankur Srivastava
通讯作者:
Ankur Srivastava