Voltage Noise-Based Adversarial Attacks on Machine Learning Inference in Multi-Tenant FPGA Accelerators

被引:0
|
作者
Majumdar, Saikat [1 ]
Teodorescu, Radu [1 ]
机构
[1] Ohio State Univ, Dept Comp Sci & Engn, Columbus, OH 43210 USA
基金
美国国家科学基金会;
关键词
D O I
10.1109/HOST55342.2024.10545401
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Deep neural network (DNN) classifiers are known to be vulnerable to adversarial attacks, in which a model is induced to misclassify an input into the wrong class. These attacks affect virtually all state-of-the-art DNN models. While most adversarial attacks work by altering the classifier input, recent variants have also targeted the model parameters. This paper focuses on a new attack vector on DNN models that leverages computation errors, rather than memory errors, deliberately introduced during DNN inference to induce misclassification. In particular, it examines errors introduced by voltage noise into FPGA-based accelerators as the attack mechanism. In an advancement over prior work, the paper demonstrates that targeted attacks are possible, even when randomly occurring faults are used. It presents an approach for precisely characterizing the distribution of faults under noise of individual input devices, by examining classification errors in select inputs. It then shows how, by fine-tuning the parameters of the attack (noise levels and target DNN layers) the attacker can produce the desired misclassification class, without altering the original input. We demonstrate the attack on an FPGA device and show the attack success rate ranges between 80% and 99.5% depending on the DNN model and dataset.
引用
收藏
页码:80 / 85
页数:6
相关论文
共 50 条
  • [1] Fault Recovery from Multi-Tenant FPGA Voltage Attacks
    Moini, Shayan
    Kansagara, Dhruv
    Holcomb, Daniel
    Tessier, Russell
    PROCEEDINGS OF THE GREAT LAKES SYMPOSIUM ON VLSI 2023, GLSVLSI 2023, 2023, : 557 - 562
  • [2] Neighbors From Hell: Voltage Attacks Against Deep Learning Accelerators on Multi-Tenant FPGAs
    Boutros, Andrew
    Hall, Mathew
    Papernot, Nicolas
    Betz, Vaughn
    2020 INTERNATIONAL CONFERENCE ON FIELD-PROGRAMMABLE TECHNOLOGY (ICFPT 2020), 2020, : 103 - 111
  • [3] Mitigating Voltage Attacks in Multi-Tenant FPGAs
    Provelengios, George
    Holcomb, Daniel
    Tessier, Russell
    ACM TRANSACTIONS ON RECONFIGURABLE TECHNOLOGY AND SYSTEMS, 2021, 14 (02)
  • [4] Multi-Tenant FPGA-based Reconfigurable Systems: Attacks and Defenses
    Elnaggar, Rana
    Karri, Ramesh
    Chakrabarty, Krishnendu
    2019 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION (DATE), 2019, : 7 - 12
  • [5] Securing FPGA Accelerators at the Electrical Level for Multi-tenant Platforms
    Tuan Minh La
    Matas, Kaspar
    Khoa Dang Pham
    Koch, Dirk
    2020 30TH INTERNATIONAL CONFERENCE ON FIELD-PROGRAMMABLE LOGIC AND APPLICATIONS (FPL), 2020, : 361 - 362
  • [6] AROMA: Evaluating Deep Learning Systems for Stealthy Integrity Attacks on Multi-tenant Accelerators
    Chen, Xiangru
    Merugu, Maneesh
    Zhang, Jiaqi
    Ray, Sandip
    ACM JOURNAL ON EMERGING TECHNOLOGIES IN COMPUTING SYSTEMS, 2023, 19 (02)
  • [7] A Quantitative Defense Framework against Power Attacks on Multi-tenant FPGA
    Luo, Yukui
    Xu, Xiaolin
    2020 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER AIDED-DESIGN (ICCAD), 2020,
  • [8] LoopBreaker: Disabling Interconnects to Mitigate Voltage-Based Attacks in Multi-Tenant FPGAs
    Nassar, Hassan
    AlZughbi, Hanna
    Gnad, Dennis R. E.
    Bauer, Lars
    Tahoori, Mehdi B.
    Henkel, Jorg
    2021 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER AIDED DESIGN (ICCAD), 2021,
  • [9] Machine Learning Aided Orchestration in Multi-tenant Networks
    Natalino, Carlos
    Raza, Muhammad Rehan
    Rostami, Ahmad
    Ohlen, Peter
    Wosinska, Lena
    Monti, Paolo
    2018 IEEE PHOTONICS SOCIETY SUMMER TOPICAL MEETING SERIES (SUM), 2018, : 125 - 126
  • [10] Triton: Software-Defined Threat Model for Secure Multi-Tenant ML Inference Accelerators
    Banerjee, Sarbartha
    Wei, Shijia
    Ramrakhyani, Prakash
    Tiwari, Mohit
    PROCEEDINGS OF THE 12TH INTERNATIONAL WORKSHOP ON HARDWARE AND ARCHITECTURAL SUPPORT FOR SECURITY AND PRIVACY, HASP 2023, 2023, : 19 - 28