SecureLoop: Design Space Exploration of Secure DNN Accelerators

SecureLoop: Design Space Exploration of Secure DNN Accelerators
复制标题

DOI:
10.1145/3613424.3614273
复制
发表时间:
2023-10
期刊:
2023 56th IEEE/ACM International Symposium on Microarchitecture (MICRO)
影响因子:
--
通讯作者:
Kyungmi Lee;Mengjia Yan;J. Emer;A. Chandrakasan
Kyungmi Lee;Mengjia Yan;J. Emer;A. Chandrakasan
中科院分区:
其他
文献类型:
--
作者:
Kyungmi Lee;Mengjia Yan;J. Emer;A. Chandrakasan

文献摘要

相似文献

深度神经网络(DNN)在从语音和视频识别到医疗保健的广泛领域中越来越受欢迎。随着越来越多的采用,迫切需要在CPU,GPU和ASIC上保护DNN执行环境。虽然在CPU上支持可信执行环境(TEE)方面有积极的研究工作,但在加速器上支持TEE的探索是有限的,只有少数解决方案可用[18],[19],[27]。沿着这条工作线的一个关键限制是,这些安全DNN加速器狭隘地考虑了一些特定的架构。保护这些架构的设计选择和相关成本不会转移到其他不同的架构。本文致力于通过开发一个设计空间探索工具来解决这一限制,以支持不同DNN加速器上的TEE。我们的目标是配备加密引擎的安全DNN加速器,其中加密操作与加速器中的数据移动密切相关。这些操作极大地复杂化了DNN加速器的调度,因为调度需要考虑这些加密操作引入的额外片上计算和片外内存访问,甚至需要考虑DNN层之间的潜在交互。我们在我们的工具中解决了这些挑战,称为SecureLoop,通过引入具有以下属性的调度搜索引擎:1)考虑与每个片外数据访问相关联的加密开销,2)使用有效的模运算技术来计算每个单独层的最佳认证块分配,以及3)使用模拟退火算法来执行跨层优化。与传统算法相比,我们的工具发现了安全DNN设计的时间表,加速率高达33.2%,能量延迟积提高了50.2%。CCS概念·计算机系统组织→神经网络;数据流架构; ·安全和隐私→硬件安全。
Deep neural networks (DNNs) are gaining popularity in a wide range of domains, ranging from speech and video recognition to healthcare. With this increased adoption comes the pressing need for securing DNN execution environments on CPUs, GPUs, and ASICs. While there are active research efforts in supporting a trusted execution environment (TEE) on CPUs, the exploration in supporting TEEs on accelerators is limited, with only a few solutions available [18], [19], [27]. A key limitation along this line of work is that these secure DNN accelerators narrowly consider a few specific architectures. The design choices and the associated cost for securing these architectures do not transfer to other diverse architectures.This paper strives to address this limitation by developing a design space exploration tool for supporting TEEs on diverse DNN accelerators. We target secure DNN accelerators equipped with cryptographic engines where the cryptographic operations are closely coupled with the data movement in the accelerators. These operations significantly complicate the scheduling for DNN accelerators, as the scheduling needs to account for the extra on-chip computation and off-chip memory accesses introduced by these cryptographic operations, and even needs to account for potential interactions across DNN layers.We tackle these challenges in our tool, called SecureLoop, by introducing a scheduling search engine with the following attributes: 1) considers the cryptographic overhead associated with every off-chip data access, 2) uses an efficient modular arithmetic technique to compute the optimal authentication block assignment for each individual layer, and 3) uses a simulated annealing algorithm to perform cross-layer optimizations. Compared to the conventional schedulers, our tool finds the schedule for secure DNN designs with up to 33.2% speedup and 50.2% improvement of energy-delay-product.CCS CONCEPTS• Computer systems organization → Neural networks; Data flow architectures; • Security and privacy → Security in hardware.