Training Data Poisoning in ML-CAD: Backdooring DL-Based Lithographic Hotspot Detectors
Training Data Poisoning in ML-CAD: Backdooring DL-Based Lithographic Hotspot Detectors
复制标题
DOI:
10.1109/tcad.2020.3024780
复制
发表时间:
2020-09
影响因子:
2.9
通讯作者:
Kang Liu;Benjamin Tan;R. Karri;S. Garg
中科院分区:
文献类型:
--
作者:
Kang Liu;Benjamin Tan;R. Karri;S. Garg
Recent efforts to enhance computer-aided design (CAD) flows have seen the proliferation of machine learning (ML)-based techniques. However, despite achieving state-of-the-art performance in many domains, techniques, such as deep learning (DL) are susceptible to various adversarial attacks. In this work, we explore the threat posed by training data poisoning attacks where a malicious insider can try to insert backdoors into a deep neural network (DNN) used as part of the CAD flow. Using a case study on lithographic hotspot detection, we explore how an adversary can contaminate training data with specially crafted, yet meaningful, genuinely labeled, and design rule compliant poisoned clips. Our experiments show that very low poisoned/clean data ratio in training data is sufficient to backdoor the DNN; an adversary can “hide” specific hotspot clips at inference time by including a backdoor trigger shape in the input with ~100% success. This attack provides a novel way for adversaries to sabotage and disrupt the distributed design process. After finding that training data poisoning attacks are feasible and stealthy, we explore a potential ensemble defense against possible data contamination, showing promising attack success reduction. Our results raise fundamental questions about the robustness of DL-based systems in CAD, and we provide insights into the implications of these.