HammerDodger: A Lightweight Defense Framework against RowHammer Attack on DNNs
HammerDodger: A Lightweight Defense Framework against RowHammer Attack on DNNs
复制标题
DOI:
10.1109/dac56929.2023.10247671
复制
发表时间:
2023-07
期刊:
影响因子:
--
通讯作者:
Gongye Cheng;Yukui Luo;Xiaolin Xu;Yunsi Fei
中科院分区:
文献类型:
--
作者:
Gongye Cheng;Yukui Luo;Xiaolin Xu;Yunsi Fei
RowHammer attacks have become a serious security problem on deep neural networks (DNNs). Some carefully induced bit-flips degrade the prediction accuracy of DNN models to random guesses. This work proposes a lightweight defense framework that detects and mitigates adversarial bit-flip attacks. We employ a dynamic channel-shuffling obfuscation scheme to present moving targets to the attack, and develop a logits-based model integrity monitor with negligible performance loss. The parameters and architecture of DNN models remain unchanged, which ensures lightweight deployment and makes the framework compatible with commodity models. We demonstrate that our framework can protect various DNN models against RowHammer attacks.