Entropy-Based Modeling for Estimating Adversarial Bit-flip Attack Impact on Binarized Neural Network

Entropy-Based Modeling for Estimating Adversarial Bit-flip Attack Impact on Binarized Neural Network
复制标题

DOI:
10.1145/3394885.3431594
复制
发表时间:
2021-01
期刊:
2021 26th Asia and South Pacific Design Automation Conference (ASP-DAC)
影响因子:
--
通讯作者:
N. Khoshavi;S. Sargolzaei;Yu Bi;A. Roohi
N. Khoshavi;S. Sargolzaei;Yu Bi;A. Roohi
中科院分区:
其他
文献类型:
--
作者:
N. Khoshavi;S. Sargolzaei;Yu Bi;A. Roohi

文献摘要

被引文献

相似文献

在过去的几年里,对有效处理深度学习(DL)模型的高需求推动了芯片设计公司的市场。然而,新的深度芯片架构,一个共同的术语,指的是DL硬件加速器,已经稍微注意到量化神经网络(QNN)的安全性要求,而黑/白色盒对抗攻击可能会危及推理加速器的完整性。因此,在本文中,QNN拓扑结构的弹性黑盒攻击的全面研究。在这里,不同的攻击场景上执行FPGA处理器的协同设计,并广泛分析收集的结果,以给出不同类型的攻击对QNN拓扑结构的影响程度的估计。具体来说,我们评估了QNN加速器对设备运行寿命中可能发生的位翻转攻击(BFA)的敏感性。在图像分类过程中,在整个QNN或每个单独的层上均匀分布的时间注入BFA。所获得的结果被用来建立基于熵的模型,可以利用该模型来构建弹性QNN架构,以对抗位翻转攻击。
Over past years, the high demand to efficiently process deep learning (DL) models has driven the market of the chip design companies. However, the new Deep Chip architectures, a common term to refer to DL hardware accelerator, have slightly paid attention to the security requirements in quantized neural networks (QNNs), while the black/white -box adversarial attacks can jeopardize the integrity of the inference accelerator. Therefore in this paper, a comprehensive study of the resiliency of QNN topologies to black-box attacks is examined. Herein, different attack scenarios are performed on an FPGA-processor co-design, and the collected results are extensively analyzed to give an estimation of the impact’s degree of different types of attacks on the QNN topology. To be specific, we evaluated the sensitivity of the QNN accelerator to a range number of bit-flip attacks (BFAs) that might occur in the operational lifetime of the device. The BFAs are injected at uniformly distributed times either across the entire QNN or per individual layer during the image classification. The acquired results are utilized to build the entropy-based model that can be leveraged to construct resilient QNN architectures to bit-flip attacks.