Using Undervolting as an on-Device Defense Against Adversarial Machine Learning Attacks

Using Undervolting as an on-Device Defense Against Adversarial Machine Learning Attacks
复制标题

DOI:
10.1109/host49136.2021.9702287
复制
发表时间:
2021-07
期刊:
2021 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)
影响因子:
--
通讯作者:
Saikat Majumdar;Mohammad Hossein Samavatian;Kristin Barber;R. Teodorescu
Saikat Majumdar;Mohammad Hossein Samavatian;Kristin Barber;R. Teodorescu
中科院分区:
其他
文献类型:
--
作者:
Saikat Majumdar;Mohammad Hossein Samavatian;Kristin Barber;R. Teodorescu

文献摘要

相似文献

深度神经网络(DNN)分类器是一种强大的工具,可以驱动从图像识别到自动驾驶汽车等广泛的重要应用。不幸的是,DNN很容易受到对抗性攻击的影响,这些攻击几乎影响了所有最先进的模型。这些攻击对输入进行了微小的不可察觉的修改,足以诱导DNN产生错误的分类。在本文中,我们提出了一种新的,轻量级的对抗性校正和/或检测机制的图像分类器,依赖于欠电压(运行芯片的电压略低于其安全裕度)。我们建议使用控制欠电压的芯片运行的推理过程,以引入有限数量的计算错误。我们表明,这些错误以一种可用于纠正分类或检测输入为对抗性的方式破坏了对抗性输入。我们评估所提出的解决方案,在FPGA设计和通过软件仿真。我们评估了10次攻击,并在两个流行的DNN上显示出77%和90%的平均检测率。
Deep neural network (DNN) classifiers are powerful tools that drive a broad spectrum of important applications, from image recognition to autonomous vehicles. Unfortunately, DNNs are known to be vulnerable to adversarial attacks that affect virtually all state-of-the-art models. These attacks make small imperceptible modifications to inputs that are sufficient to induce the DNNs to produce the wrong classification. In this paper we propose a novel, lightweight adversarial correction and/or detection mechanism for image classifiers that relies on undervolting (running a chip at a voltage that is slightly below its safe margin). We propose using controlled undervolting of the chip running the inference process in order to introduce a limited number of compute errors. We show that these errors disrupt the adversarial input in a way that can be used either to correct the classification or detect the input as adversarial. We evaluate the proposed solution in an FPGA design and through software simulation. We evaluate 10 attacks and show average detection rates of 77% and 90% on two popular DNNs.