Training Data Poisoning in ML-CAD: Backdooring DL-Based Lithographic Hotspot Detectors

Training Data Poisoning in ML-CAD: Backdooring DL-Based Lithographic Hotspot Detectors
复制标题

DOI:
10.1109/tcad.2020.3024780
复制
发表时间:
2020-09
影响因子:
2.9
通讯作者:
Kang Liu;Benjamin Tan;R. Karri;S. Garg
Kang Liu;Benjamin Tan;R. Karri;S. Garg
中科院分区:
计算机科学3区
文献类型:
--
作者:
Kang Liu;Benjamin Tan;R. Karri;S. Garg

文献摘要

相似文献

最近增强计算机辅助设计 (CAD) 流程的努力见证了基于机器学习 (ML) 的技术的激增。然而,尽管深度学习 (DL) 等技术在许多领域实现了最先进的性能,但仍容易受到各种对抗性攻击。在这项工作中,我们探讨了训练数据中毒攻击所带来的威胁,其中恶意内部人员可以尝试将后门插入用作 CAD 流程一部分的深度神经网络 (DNN)。通过光刻热点检测的案例研究,我们探讨了对手如何使用特制的、有意义的、真正标记的且符合设计规则的有毒片段污染训练数据。我们的实验表明,训练数据中非常低的中毒/干净数据比率足以对 DNN 进行后门;攻击者可以通过在输入中包含后门触发器形状来在推理时“隐藏”特定的热点片段,成功率约为 100%。这种攻击为对手提供了一种破坏和破坏分布式设计过程的新方法。在发现训练数据中毒攻击是可行且隐蔽的之后,我们探索了针对可能的数据污染的潜在集成防御,显示出有希望减少攻击成功率。我们的结果提出了关于 CAD 中基于 DL 的系统的稳健性的基本问题,并且我们提供了对其影响的见解。
Recent efforts to enhance computer-aided design (CAD) flows have seen the proliferation of machine learning (ML)-based techniques. However, despite achieving state-of-the-art performance in many domains, techniques, such as deep learning (DL) are susceptible to various adversarial attacks. In this work, we explore the threat posed by training data poisoning attacks where a malicious insider can try to insert backdoors into a deep neural network (DNN) used as part of the CAD flow. Using a case study on lithographic hotspot detection, we explore how an adversary can contaminate training data with specially crafted, yet meaningful, genuinely labeled, and design rule compliant poisoned clips. Our experiments show that very low poisoned/clean data ratio in training data is sufficient to backdoor the DNN; an adversary can “hide” specific hotspot clips at inference time by including a backdoor trigger shape in the input with ~100% success. This attack provides a novel way for adversaries to sabotage and disrupt the distributed design process. After finding that training data poisoning attacks are feasible and stealthy, we explore a potential ensemble defense against possible data contamination, showing promising attack success reduction. Our results raise fundamental questions about the robustness of DL-based systems in CAD, and we provide insights into the implications of these.