Collaborative Research: SaTC: CORE: Small: Understanding and Taming Deterministic Model Bit Flip attacks in Deep Neural Networks
Collaborative Research: SaTC: CORE: Small: Understanding and Taming Deterministic Model Bit Flip attacks in Deep Neural Networks
批准号:
2019536
负责人:
Fan Yao
金额:
$25.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-10-01 至 2024-09-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Deep neural network (DNN) is widely deployed for a variety of decision-making tasks such as access control, medical diagnostics, and autonomous driving. Compromise of DNN models can severely disrupt inference behavior, leading to catastrophic outcomes for security and safety-sensitive applications. While a tremendous amount of efforts have been made to secure DNNs against external adversaries (e.g., adversarial examples), internal adversaries that tamper DNN model integrity through exploiting hardware threats (i.e., fault injection attacks) can raise unprecedented concerns. This project aims to offer insights into DNN security issues due to hardware-based fault attacks, and explore ways to promote the robustness and security of future deep learning system against such internal adversaries. This project targets one critical research topic, namely securing deep learning systems against hardware-based model tampering. Recent advances in hardware fault attacks (e.g., rowhammer) can deterministically inject faults to DNN models, causing bit flips in key DNN parameters including model weights. Such threats can be extremely dangerous as they could potentially enable malicious manipulation of prediction outcomes in the inference stage by the adversary. The project seeks to systematically understand the practicality and severity of DNN model bit flip attacks in real systems and investigate software/architecture level protection techniques to secure DNNs against internal tampering. The study focuses on quantized DNNs which exhibit higher robustness against model tampering. This project will incorporate the following research efforts: (1) Investigate the vulnerability of quantized DNNs to deterministic bit flipping of model weights concerning various attack objectives; (2) Explore algorithmic approaches to enhance the intrinsic robustness of quantized DNN models; (3) Design effective and efficient system and architecture level defense mechanisms to comprehensively defeat DNN model bit flip attacks. This project will result in the dissemination of shared data, attack artifacts, algorithms and tools to the broader hardware security and AI security community.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(8)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/host54066.2022.9840266
发表时间:
2022-06
期刊:
2022 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)
影响因子:
--
作者:
[Kunbei Cai;Zhenkai Zhang;F. Yao]
通讯作者:
Kunbei Cai;Zhenkai Zhang;F. Yao
DOI:
10.1145/3466752.3480054
发表时间:
2021-10
期刊:
MICRO-54: 54th Annual IEEE/ACM International Symposium on Microarchitecture
影响因子:
--
作者:
[Md Hafizul Islam Chowdhuryy;M. Rashed;Amro Awad;Rickard Ewetz;Fan Yao]
通讯作者:
Md Hafizul Islam Chowdhuryy;M. Rashed;Amro Awad;Rickard Ewetz;Fan Yao
DOI:
10.1109/tpami.2021.3112932
发表时间:
2020-07
期刊:
IEEE Transactions on Pattern Analysis and Machine Intelligence
影响因子:
23.6
作者:
[A. S. Rakin;Zhezhi He;Jingtao Li;Fan Yao;C. Chakrabarti;Deliang Fan]
通讯作者:
A. S. Rakin;Zhezhi He;Jingtao Li;Fan Yao;C. Chakrabarti;Deliang Fan
DOI:
10.1109/seed51797.2021.00019
发表时间:
2021-09
期刊:
2021 International Symposium on Secure and Private Execution Environment Design (SEED)
影响因子:
--
作者:
[Kunbei Cai;Md Hafizul Islam Chowdhuryy;Zhenkai Zhang;Fan Yao]
通讯作者:
Kunbei Cai;Md Hafizul Islam Chowdhuryy;Zhenkai Zhang;Fan Yao
DOI:
10.1109/spw54247.2022.9833894
发表时间:
2022-05
期刊:
2022 IEEE Security and Privacy Workshops (SPW)
影响因子:
--
作者:
[Sisheng Liang;Zihao Zhan;Fan Yao;Long Cheng;Zhenkai Zhang]
通讯作者:
Sisheng Liang;Zihao Zhan;Fan Yao;Long Cheng;Zhenkai Zhang
共 8 条
CAREER: Understanding and Ensuring Secure-by-design Microarchitecture in Modern Era of Computing
-
批准号:2340777
-
项目类别:Continuing Grant
-
资助金额:$55.69万
-
财政年份:2024
-
负责人:Fan Yao
-
依托单位:
CNS Core: Small: Towards Secure-By-Design Integration of Emerging Non-Volatile Memory in Future Systems
-
批准号:2008339
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2020
-
负责人:Fan Yao
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: