Concurrent Weight Encoding-based Detection for Bit-Flip Attack on Neural Network Accelerators

Concurrent Weight Encoding-based Detection for Bit-Flip Attack on Neural Network Accelerators
复制标题

DOI:
10.1145/3400302.3415726
复制
发表时间:
2020-11
期刊:
2020 IEEE/ACM International Conference On Computer Aided Design (ICCAD)
影响因子:
--
通讯作者:
Qi Liu;Wujie Wen;Yanzhi Wang
Qi Liu;Wujie Wen;Yanzhi Wang
中科院分区:
其他
文献类型:
--
作者:
Qi Liu;Wujie Wen;Yanzhi Wang

文献摘要

相似文献

最近发现的针对深度神经网络(dnn)的比特翻转攻击(BFA)引起了高度关注,因为它可以通过像DRAM rowhammer这样的方式仅仅翻转硬件存储器中的几个权重位来完全误导量化dnn的推理。在应用任何BFA缓解解决方案(如重新训练或重新加载模型)之前,一个关键问题是如何在不影响正常推理的情况下快速准确地检测此类攻击。在本文中,我们提出了一个基于权重编码的框架,利用BFA中位翻转的空间局部性和仅对敏感权重进行快速编码来并发检测BFA。大量的实验结果表明,我们的方法可以准确地区分BFA下的恶意故障模型和随机位翻转(也可能发生在权重记忆中),但不会像BFA那样影响准确性,并且在CIFAR-10和ImageNet数据集上的各种dnn开销都非常低。据我们所知,这是针对广泛部署在硬件加速器中的量化dnn的BFA攻击的第一个实时检测框架。
The recent revealed Bit-Flip Attack (BFA) against deep neural networks (DNNs) is highly concerning, as it can completely mislead the inference of quantized DNNs by only flipping a few weight bits in hardware memories through manners like DRAM rowhammer. A key question before applying any BFA mitigation solutions, such as retraining or model reloading, is how to quickly and accurately detect such an attack without impacting the normal inference. In this paper, we propose a weight encoding-based framework to concurrently detect BFA by leveraging the spatial locality of bit flipping in BFA and a fast encoding of sensitive weights only. Extensive experimental results show that our method can accurately differentiate the malicious fault models under BFA and the random bit flipping that could also occur in weight memories but does not impact accuracy as that of BFA, with very low overhead across various DNNs on both CIFAR-10 and ImageNet datasets. To the best of our knowledge, this is the first real-time detection framework for BFA attack against quantized DNNs that are widely deployed in hardware accelerators.