CAREER: Dependable and Secure Machine Learning Acceleration from Untrusted Hardware
CAREER: Dependable and Secure Machine Learning Acceleration from Untrusted Hardware
批准号:
2349538
负责人:
Wujie Wen
金额:
$60.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-10-01 至 2028-09-30
中文摘要
在机器学习(ML)模型和计算硬件的进步推动下,智能正在成为从云到边缘的家喻户晓的品牌,改变着各行各业。对于以安全为主要要求的智能系统,例如自动驾驶汽车和无医生诊所,确保推理的可靠性至关重要。不幸的是,目前的硬件无法提供这样的承诺。推理执行可能受到对硬件组件(如存储器、逻辑)的被动故障或主动物理故障攻击的干扰。虽然从数据的角度进行了相关研究,但硬件方面的问题则不同,而且探讨得更少。这个CAREER项目旨在创建一个新的范例,保护ML执行免受被动硬件故障和主动故障攻击,重点是通过设计将推理可靠性主动扎根于ML处理。与之前的反应式硬件漏洞修复或基于硬件安全的解决方案不同,这些解决方案没有紧密地拥抱ML的独特属性,该项目的新颖之处在于ML处理内部的新功能开发,即“多用途神经元”,以及ML算法,硬件架构和硬件安全的跨层探索。该项目更广泛的意义和重要性在于:1)为确保安全、医疗保健、自动化系统和其他领域的加速人工智能(AI)服务的信任根源提供实用的解决方案; 2)推进AI算法、硬件和安全设计之间的交互的最新技术; 3)提供丰富的教育机会和外展活动,以培养和吸引来自代表性不足的群体和K-12社区的学生。该项目旨在通过算法-硬件-安全协同设计为硬件加速器开发以“多用途神经元”为中心的ML推理保护方法,并保证通用性,可扩展性,可行性和耐用性。该项目包括三个方面:1)通过“编码神经元”和硬件优化来提高离线容错能力,而无需假设预先存在固定的攻击(通用性); 2)通过“保护神经元”、专用训练方法和硬件设计在线缓解多个故障(可扩展性); 3)通过基于“蜂蜜神经元”和信任执行环境的真实的实时主动解决方案,抵御强大的自适应攻击(耐久性)。对推理准确性、延迟和硬件开销的影响将在所有目标中最小化(可行性)。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Fueled by the advancements of machine learning (ML) models and computing hardware, intelligence is becoming a household brand from cloud to edge, transforming every walk of life. For intelligent systems with safety and security as their primary requirements, such as autonomous vehicles and doctorless clinics, ensuring inference dependability is essential. Unfortunately, current hardware cannot provide such a promise. The inference execution can be disturbed by either passive faults or active physical fault attacks on hardware components like memory, logic. While there have been relevant studies from the perspective of data, the problem in the context of hardware is different and far less explored. This CAREER project aims to create a new paradigm of safeguarding ML execution against both passive hardware faults and active fault attacks, with a focus on proactively rooting inference dependability into ML processing by design. Unlike prior reactive hardware bug repair or hardware security-based solutions, which do not closely embrace ML's distinct properties, the project's novelties lie in the new capability development inside ML processing, namely "Multi-Purposed Neuron", and the cross-layer exploration of ML algorithm, hardware architecture and hardware security centered around this. The project's broader significance and importance are: 1) yield practical solutions for ensuring the root of trust of accelerated artificial intelligence (AI) services in security, healthcare, automated systems, and other domains; 2) advance the state-of-the-art on the interactions among AI algorithm, hardware, and security design; 3) provide abundant educational opportunities and outreach activities to nurture and attract students from underrepresented groups and the K-12 community. The project seeks to develop "Multi-Purposed Neuron"-centered ML inference protection methodologies for hardware accelerators through algorithm-hardware-security co-design, with guarantees of generality, scalability, feasibility, and durability. The project consists of three thrusts: 1) Improve fault tolerance offline through "Coded Neurons" and hardware optimization without assuming a fixed attack available prior (Generality); 2) Mitigate multiple faults online via "Guarded Neurons", dedicated training methods and hardware design (Scalability); 3) Defend against strong and adaptive attacks by real time proactive solutions built upon "Honey Neurons" and Trust Execution Environment (Durability). The impact on inference accuracy, latency and hardware overhead will be minimized across all thrusts (Feasibility).This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CAREER: Dependable and Secure Machine Learning Acceleration from Untrusted Hardware
-
批准号:2238873
-
项目类别:Continuing Grant
-
资助金额:$60.0万
-
财政年份:2023
-
负责人:Wujie Wen
-
依托单位:
SPX: Collaborative Research: Scalable Neural Network Paradigms to Address Variability in Emerging Device based Platforms for Large Scale Neuromorphic Computing
-
批准号:2401544
-
项目类别:Standard Grant
-
资助金额:$35.55万
-
财政年份:2023
-
负责人:Wujie Wen
-
依托单位:
Collaborative Research: SaTC: CORE: Medium: Accelerating Privacy-Preserving Machine Learning as a Service: From Algorithm to Hardware
-
批准号:2247891
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2023
-
负责人:Wujie Wen
-
依托单位:
Collaborative Research: SaTC: CORE: Medium: Accelerating Privacy-Preserving Machine Learning as a Service: From Algorithm to Hardware
-
批准号:2348733
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2023
-
负责人:Wujie Wen
-
依托单位:
EAGER: Invisible Shield: Can Compression Harden Deep Neural Networks Universally Against Adversarial Attacks?
-
批准号:2011260
-
项目类别:Standard Grant
-
资助金额:$14.92万
-
财政年份:2019
-
负责人:Wujie Wen
-
依托单位:
SHF: Small: Collaborative Research: Retraining-free Concurrent Test and Diagnosis in Emerging Neural Network Accelerators
-
批准号:2011236
-
项目类别:Standard Grant
-
资助金额:$23.5万
-
财政年份:2019
-
负责人:Wujie Wen
-
依托单位:
SPX: Collaborative Research: Scalable Neural Network Paradigms to Address Variability in Emerging Device based Platforms for Large Scale Neuromorphic Computing
-
批准号:1919182
-
项目类别:Standard Grant
-
资助金额:$35.55万
-
财政年份:2019
-
负责人:Wujie Wen
-
依托单位:
SPX: Collaborative Research: Scalable Neural Network Paradigms to Address Variability in Emerging Device based Platforms for Large Scale Neuromorphic Computing
-
批准号:2006748
-
项目类别:Standard Grant
-
资助金额:$35.55万
-
财政年份:2019
-
负责人:Wujie Wen
-
依托单位:
SHF: Small: Collaborative Research: Retraining-free Concurrent Test and Diagnosis in Emerging Neural Network Accelerators
-
批准号:1910022
-
项目类别:Standard Grant
-
资助金额:$23.5万
-
财政年份:2019
-
负责人:Wujie Wen
-
依托单位:
EAGER: Invisible Shield: Can Compression Harden Deep Neural Networks Universally Against Adversarial Attacks?
-
批准号:1840813
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2018
-
负责人:Wujie Wen
-
依托单位:
海外基金