CAREER: Physical Side-Channels Beyond Cryptography: Transforming the Side-Channel Framework for Deep Learning
CAREER: Physical Side-Channels Beyond Cryptography: Transforming the Side-Channel Framework for Deep Learning
批准号:
1943245
负责人:
Aydin Aysu
金额:
$43.87万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2020
资助国家:
美国
项目状态:
未结题
起止时间:
2020-10-01 至 2025-09-30
中文摘要
机器学习(ML)分类器很难开发,并且用于自动驾驶等安全关键型应用。因此,暴露ML分类器的细节会导致知识产权盗窃,也更容易被对手愚弄。不幸的是,ML分类器的实现可能会泄露有关其内部工作的信息。该项目的主要研究目标是开发安全的ML分类器实现。这项工作专门解决了ML分类器物理实现的基本电磁和功率侧信道漏洞。该项目的智力价值是将物理侧信道分析框架扩展到密码学之外,以保护深度神经网络(NN)分类器。虽然对NN模型提取的数学分析和数字侧通道进行了研究,但物理侧通道在很大程度上尚未探索。研究任务是设计物理侧信道弹性NN组件,将开发的组件集成到一个高层次的合成框架中,用于自动生成受保护的NN硬件加速器,并评估/基准侧信道安全和对策overheads.The更广泛的影响,这个项目包括传播出版物,分发开源硬件和软件,并桥接NN和硬件安全的研究。该项目还旨在开发一门大学课程,通过动手实验教授NN的硬件安全性。这项工作也可能有助于维持美国在人工智能领域的领导地位的行政命令,通过评估美国国家标准与技术研究所(NIST)提出的人工智能标准的安全性。该项目将使用一个具有多个备份服务器的存储库来存储和记录数据,主要成果和软硬件产品将通过万维网资源公开提供。关于项目资料库的进一步信息可在https://research.ece.ncsu.edu/aaysu/research/MLSec-CAREER-nsf.html上查阅。该储存库将在项目期间和项目完成后的5年内积极维护。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Machine Learning (ML) classifiers are hard to develop and are used in safety-critical applications like autonomous driving. Exposing the details of an ML classifier thus results in intellectual property theft and also makes it easier to be fooled by adversaries. Unfortunately, the implementation of an ML classifier may leak information about its inner workings. The primary research goal of this project is to develop secure ML classifier implementations. This work specifically addresses the fundamental electromagnetic and power side-channel vulnerabilities of physical implementations of ML classifiers.The intellectual merit of the project is to extend the physical side-channel analysis framework beyond cryptography for securing deep neural network (NN) classifiers. Although there is research on the mathematical analysis and digital side-channels of NN model extraction, physical side-channels are largely unexplored. The research tasks are to design physical side-channel resilient NN components, to integrate the developed components into a high-level synthesis framework for automatic generation of protected NN hardware accelerators, and to evaluate/benchmark side-channel security and countermeasure overheads.The broader impact of this project includes disseminating publications, distributing open-source hardware and software, and bridging the research on NNs and hardware security. The project also aims developing a college course to teach hardware security for NNs with hands-on experiments. This work may also help the Executive Order on Maintaining American Leadership in Artificial Intelligence, by evaluating the security of the Artificial Intelligence standards being put forward by the National Institute of Standards and Technology (NIST).This project will use a repository with multiple back-up servers to store and log the data, and the major results and hardware and software products will be made publicly available by using resources over the world wide web. Further information on the project repository will be made accessible at https://research.ece.ncsu.edu/aaysu/research/MLSec-CAREER-nsf.html. The repository is intended to be actively maintained for the duration of the project and 5 years after its completion.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Hardware-Software Co-design for Side-Channel Protected Neural Network Inference
用于侧通道保护神经网络推理的硬件-软件协同设计
DOI:
10.1109/host55118.2023.10133716
发表时间:
2023
期刊:
2023 IEEE International Symposium on Hardware Oriented Security and Trust (HOST
影响因子:
--
作者:
[Dubey, Anuj, Cammarota, Rosario, Varna, Avinash, Kumar, Raghavan, Aysu, Aydin]
通讯作者:
Aysu, Aydin
DOI:
10.46586/tches.v2022.i1.506-556
发表时间:
2021-11
期刊:
IACR Trans. Cryptogr. Hardw. Embed. Syst.
影响因子:
--
作者:
[Anuj Dubey;Afzal Ahmad;M. A. Pasha;Rosario Cammarota;Aydin Aysu]
通讯作者:
Anuj Dubey;Afzal Ahmad;M. A. Pasha;Rosario Cammarota;Aydin Aysu
DOI:
10.1145/3400302.3415649
发表时间:
2020-06
期刊:
2020 IEEE/ACM International Conference On Computer Aided Design (ICCAD)
影响因子:
--
作者:
[Anuj Dubey;Rosario Cammarota;Aydin Aysu]
通讯作者:
Anuj Dubey;Rosario Cammarota;Aydin Aysu
DOI:
10.1145/3465377
发表时间:
2021-09
期刊:
ACM Journal on Emerging Technologies in Computing Systems (JETC)
影响因子:
--
作者:
[Anuj Dubey;Rosario Cammarota;Vikram B. Suresh;Aydin Aysu]
通讯作者:
Anuj Dubey;Rosario Cammarota;Vikram B. Suresh;Aydin Aysu
DOI:
10.1145/3526241.3530828
发表时间:
2022
期刊:
GLSVLSI '22: Proceedings of the Great Lakes Symposium on VLSI 2022
影响因子:
--
作者:
[Calhoun, Ashley, Ortega, Erick, Yaman, Ferhat, Dubey, Anuj, Aysu, Aydin]
通讯作者:
Aysu, Aydin
共 6 条
SaTC: CORE: Small: An Automated Framework for Mitigating Single-Trace Side-Channel Leakage
-
批准号:2241879
-
项目类别:Standard Grant
-
资助金额:$33.98万
-
财政年份:2023
-
负责人:Aydin Aysu
-
依托单位:
SHF: Small: A New Approach for Hardware Design of High-Precision Discrete Gaussian Sampling
-
批准号:2146881
-
项目类别:Continuing Grant
-
资助金额:$19.98万
-
财政年份:2022
-
负责人:Aydin Aysu
-
依托单位:
CRII: SaTC: Secure Instruction Set Extensions for Lattice-Based Post-Quantum Cryptosystems
-
批准号:1850373
-
项目类别:Standard Grant
-
资助金额:$17.48万
-
财政年份:2019
-
负责人:Aydin Aysu
-
依托单位:
国内基金
海外基金
面向智能电网基础设施Cyber-Physical安全的自治愈基础理论研究
-
批准号:61300132
-
项目类别:青年科学基金项目
-
资助金额:23.0万元
-
批准年份:2013
-
负责人:王竹晓
-
依托单位: