Remote Power Attacks on the Versatile Tensor Accelerator in Multi-Tenant FPGAs

Remote Power Attacks on the Versatile Tensor Accelerator in Multi-Tenant FPGAs
复制标题

DOI:
10.1109/fccm51124.2021.00037
复制
发表时间:
2021-05
期刊:
2021 IEEE 29th Annual International Symposium on Field-Programmable Custom Computing Machines (FCCM)
影响因子:
--
通讯作者:
Shanquan Tian;Shayan Moini;Adam Wolnikowski;Daniel E. Holcomb;R. Tessier;Jakub Szefer
Shanquan Tian;Shayan Moini;Adam Wolnikowski;Daniel E. Holcomb;R. Tessier;Jakub Szefer
中科院分区:
其他
文献类型:
--
作者:
Shanquan Tian;Shayan Moini;Adam Wolnikowski;Daniel E. Holcomb;R. Tessier;Jakub Szefer

文献摘要

相似文献

机器学习模型的架构细节是许多应用中知识产权的重要组成部分。揭示模型中层的结构或类型可能会导致机密或专有信息的泄露。当机器学习模型在多租户 FPGA 的加速器上执行时,这个问题变得尤其令人担忧,攻击者可以轻松地将传感电路与受害者的机器学习加速器共置。为了评估此类威胁,我们提出了第一个远程电源攻击,该攻击可以提取在 FPGA 中实现的基于现成的特定领域指令集架构 (ISA) 的神经网络加速器上执行的机器学习模型的详细信息。通过利用时间数字转换器 (TDC),攻击者可以推断出在受害者加速器上执行的指令组的组成,并恢复组内通用矩阵乘法 (GEMM) 指令的参数,所有这些都无需物理访问 FPGA。有了这些信息,攻击者就可以对加速器上执行的机器学习模型的结构和层进行逆向工程,从而导致专有信息被盗。
Architectural details of machine learning models are crucial pieces of intellectual property in many applications. Revealing the structure or types of layers in a model can result in a leak of confidential or proprietary information. This issue becomes especially concerning when the machine learning models are executed on accelerators in multi-tenant FPGAs where attackers can easily co-locate sensing circuitry next to the victim’s machine learning accelerator. To evaluate such threats, we present the first remote power attack that can extract details of machine learning models executed on an off-the-shelf domain-specific instruction set architecture (ISA) based neural network accelerator implemented in an FPGA. By leveraging a time-to-digital converter (TDC), an attacker can deduce the composition of instruction groups executing on the victim accelerator, and recover parameters of General Matrix Multiplication (GEMM) instructions within a group, all without requiring physical access to the FPGA. With this information, an attacker can then reverse-engineer the structure and layers of machine learning models executing on the accelerator, leading to potential theft of proprietary information.