HammerDodger: A Lightweight Defense Framework against RowHammer Attack on DNNs

HammerDodger: A Lightweight Defense Framework against RowHammer Attack on DNNs
复制标题

DOI:
10.1109/dac56929.2023.10247671
复制
发表时间:
2023-07
期刊:
2023 60th ACM/IEEE Design Automation Conference (DAC)
影响因子:
--
通讯作者:
Gongye Cheng;Yukui Luo;Xiaolin Xu;Yunsi Fei
Gongye Cheng;Yukui Luo;Xiaolin Xu;Yunsi Fei
中科院分区:
其他
文献类型:
--
作者:
Gongye Cheng;Yukui Luo;Xiaolin Xu;Yunsi Fei

文献摘要

相似文献

Rowhammer攻击已成为深层神经网络(DNNS)的严重安全问题。一些精心诱发的位液浮标降低了DNN模型的预测准确性,以随机猜测。这项工作提出了一个轻巧的防御框架,可检测并减轻对抗性叉式攻击。我们采用动态的渠道改组方案来向攻击呈现移动目标,并开发具有可忽略的性能损失的基于逻辑的模型完整性监视器。 DNN模型的参数和体系结构保持不变,可确保轻巧的部署并使该框架与商品模型兼容。我们证明,我们的框架可以保护各种DNN模型免受Rowhammer攻击。
RowHammer attacks have become a serious security problem on deep neural networks (DNNs). Some carefully induced bit-flips degrade the prediction accuracy of DNN models to random guesses. This work proposes a lightweight defense framework that detects and mitigates adversarial bit-flip attacks. We employ a dynamic channel-shuffling obfuscation scheme to present moving targets to the attack, and develop a logits-based model integrity monitor with negligible performance loss. The parameters and architecture of DNN models remain unchanged, which ensures lightweight deployment and makes the framework compatible with commodity models. We demonstrate that our framework can protect various DNN models against RowHammer attacks.