SecureVolt: Enhancing Deep Neural Networks Security via Undervolting

SecureVolt: Enhancing Deep Neural Networks Security via Undervolting
复制标题

DOI:
10.1109/tcad.2023.3296379
复制
发表时间:
2023-12
影响因子:
2.9
通讯作者:
Md. Shohidul Islam;Ihsen Alouani;Khaled N. Khasawneh
Md. Shohidul Islam;Ihsen Alouani;Khaled N. Khasawneh
中科院分区:
计算机科学3区
文献类型:
--
作者:
Md. Shohidul Islam;Ihsen Alouani;Khaled N. Khasawneh

文献摘要

相似文献

深度神经网络(DNN)被证明容易受到敌意攻击;精心设计的加性噪声破坏了DNN的完整性。以前提出的针对这些攻击的防御需要大量的管理费用,这使得在电力和计算资源受限的设备(如嵌入式系统和Edge)中部署这些解决方案具有挑战性。在这篇文章中,我们将探索使用电压过比例(VOS)作为一种轻量级、高效的防御对手攻击的方法。具体地说,我们利用计算单元中VOS的随机定时冲突来实现DNN的移动目标防御。实验结果表明,VOS保证了对不同攻击方法的有效防御,不需要任何软硬件修改,并提供了一种降低功耗的副产品。我们提出了一种空间探索,以确定稳健性、准确性和功率增益之间的可能折衷。此外,我们观察了模型的认知不确定性在可变欠电压攻击性下的行为。我们的实验表明,在我们的稳健性/准确性探索中,模型不确定性分析与观测是一致的。
Deep neural networks (DNNs) are shown to be vulnerable to adversarial attacks; carefully crafted additive noise that undermines DNNs integrity. Previously proposed defenses against these attacks require substantial overheads, making it challenging to deploy these solutions in power and computational resource-constrained devices, such as embedded systems and the Edge. In this article, we explore the use of voltage over-scaling (VOS) as a lightweight and efficient defense against adversarial attacks. Specifically, we exploit the stochastic timing violations of VOS within computing elements to implement a moving-target defense for DNNs. Our experimental results demonstrate that VOS guarantees effective defense against different attack methods, does not require any software/hardware modifications, and offers a by-product reduction in power consumption. We propose a space exploration to identify a possible tradeoff between robustness, accuracy, and power gains. Furthermore, we observe the behavior of models’ epistemic uncertainty under variable undervolting aggressiveness. Our experiments show that model uncertainty analysis is coherent with the observation in our robustness/accuracy exploration.