ModuloNET: Neural Networks Meet Modular Arithmetic for Efficient Hardware Masking

ModuloNET: Neural Networks Meet Modular Arithmetic for Efficient Hardware Masking
复制标题

DOI:
10.46586/tches.v2022.i1.506-556
复制
发表时间:
2021-11
期刊:
IACR Trans. Cryptogr. Hardw. Embed. Syst.
影响因子:
--
通讯作者:
Anuj Dubey;Afzal Ahmad;M. A. Pasha;Rosario Cammarota;Aydin Aysu
Anuj Dubey;Afzal Ahmad;M. A. Pasha;Rosario Cammarota;Aydin Aysu
中科院分区:
其他
文献类型:
--
作者:
Anuj Dubey;Afzal Ahmad;M. A. Pasha;Rosario Cammarota;Aydin Aysu

文献摘要

相似文献

通过对推理引擎的侧信道攻击来窃取经过训练的机器学习(ML)模型的知识产权(IP)正在成为一个主要威胁。事实上,最近的几项工作已经展示了使用这种攻击对模型内部进行逆向工程,但关于构建防御的研究在很大程度上尚未探索。迫切需要有效和安全地将这些防御从密码学(如掩码)转换为ML框架。然而,现有的工作表明,这种防御的直接适应要么提供部分安全性,要么导致高面积开销。为了解决这些局限性,这项工作提出了一个全新的方向来构建本质上与掩蔽更兼容的神经网络。其关键思想是在神经网络中使用模块化算法,然后根据神经网络层的类型,以布尔或算术方式有效地实现掩码。我们在边缘计算友好的二值化神经网络(BNN)上展示了我们的方法,并展示了如何修改这样一个网络的训练和推理,使其在不牺牲准确性的情况下使用模块化算法。然后,我们使用面向域的掩码(DOM)设计新的掩码小工具,以有效地屏蔽ML的独特操作,如激活函数和输出层分类,并在故障扩展探测模型中证明其安全性。最后,我们在FPGA上实现了完全掩蔽的神经网络,量化了它们可以实现类似的延迟,同时将FF和LUT成本分别降低了34.2%和42.6%,并通过高达1M的跟踪证明了它们的一阶侧信道安全性。
Intellectual Property (IP) thefts of trained machine learning (ML) models through side-channel attacks on inference engines are becoming a major threat. Indeed, several recent works have shown reverse engineering of the model internals using such attacks, but the research on building defenses is largely unexplored. There is a critical need to efficiently and securely transform those defenses from cryptography such as masking to ML frameworks. Existing works, however, revealed that a straightforward adaptation of such defenses either provides partial security or leads to high area overheads. To address those limitations, this work proposes a fundamentally new direction to construct neural networks that are inherently more compatible with masking. The key idea is to use modular arithmetic in neural networks and then efficiently realize masking, in either Boolean or arithmetic fashion, depending on the type of neural network layers. We demonstrate our approach on the edge-computing friendly binarized neural networks (BNN) and show how to modify the training and inference of such a network to work with modular arithmetic without sacrificing accuracy. We then design novel masking gadgets using Domain-Oriented Masking (DOM) to efficiently mask the unique operations of ML such as the activation function and the output layer classification, and we prove their security in the glitch-extended probing model. Finally, we implement fully masked neural networks on an FPGA, quantify that they can achieve a similar latency while reducing the FF and LUT costs over the state-of-the-art protected implementations by 34.2% and 42.6%, respectively, and demonstrate their first-order side-channel security with up to 1M traces.