Detection and Recovery Against Deep Neural Network Fault Injection Attacks Based on Contrastive Learning

Detection and Recovery Against Deep Neural Network Fault Injection Attacks Based on Contrastive Learning
复制标题

DOI:
10.48550/arxiv.2401.16766
复制
发表时间:
2024-01
期刊:
ArXiv
影响因子:
--
通讯作者:
Chenan Wang;Pu Zhao;Siyue Wang;Xue Lin
Chenan Wang;Pu Zhao;Siyue Wang;Xue Lin
中科院分区:
其他
文献类型:
--
作者:
Chenan Wang;Pu Zhao;Siyue Wang;Xue Lin

文献摘要

相似文献

深度神经网络(DNN)模型在执行设备上实现时,作为推理引擎,容易受到故障注入攻击(FIA)的影响,FIA会操纵模型参数以破坏推理执行,并带来灾难性的性能。这项工作介绍了视觉表征的对比学习(CL),即,将自监督学习方法引入深度学习训练和推理管道,以在FIA下实现具有自恢复能力的DNN推理引擎。我们提出的基于CL的FIA检测和恢复(CFDR)框架具有以下特点:(i)仅使用单批测试数据进行实时检测;(ii)即使仅使用少量未标记的测试数据也能快速有效地恢复。在多种类型的FIA上使用CIFAR-10数据集进行评估,我们的CFDR显示出很好的检测和恢复效果。
Deep Neural Network (DNN) models when implemented on executing devices as the inference engines are susceptible to Fault Injection Attacks (FIAs) that manipulate model parameters to disrupt inference execution with disastrous performance. This work introduces Contrastive Learning (CL) of visual representations i.e., a self-supervised learning approach into the deep learning training and inference pipeline to implement DNN inference engines with self-resilience under FIAs. Our proposed CL based FIA Detection and Recovery (CFDR) framework features (i) real-time detection with only a single batch of testing data and (ii) fast recovery effective even with only a small amount of unlabeled testing data. Evaluated with the CIFAR-10 dataset on multiple types of FIAs, our CFDR shows promising detection and recovery effectiveness.