SecureVolt: Enhancing Deep Neural Networks Security via Undervolting
SecureVolt: Enhancing Deep Neural Networks Security via Undervolting
复制标题
DOI:
10.1109/tcad.2023.3296379
复制
发表时间:
2023-12
影响因子:
2.9
通讯作者:
Md. Shohidul Islam;Ihsen Alouani;Khaled N. Khasawneh
中科院分区:
文献类型:
--
作者:
Md. Shohidul Islam;Ihsen Alouani;Khaled N. Khasawneh
Deep neural networks (DNNs) are shown to be vulnerable to adversarial attacks; carefully crafted additive noise that undermines DNNs integrity. Previously proposed defenses against these attacks require substantial overheads, making it challenging to deploy these solutions in power and computational resource-constrained devices, such as embedded systems and the Edge. In this article, we explore the use of voltage over-scaling (VOS) as a lightweight and efficient defense against adversarial attacks. Specifically, we exploit the stochastic timing violations of VOS within computing elements to implement a moving-target defense for DNNs. Our experimental results demonstrate that VOS guarantees effective defense against different attack methods, does not require any software/hardware modifications, and offers a by-product reduction in power consumption. We propose a space exploration to identify a possible tradeoff between robustness, accuracy, and power gains. Furthermore, we observe the behavior of models’ epistemic uncertainty under variable undervolting aggressiveness. Our experiments show that model uncertainty analysis is coherent with the observation in our robustness/accuracy exploration.