Voltage Noise-Based Adversarial Attacks on Machine Learning Inference in Multi-Tenant FPGA Accelerators

被引:0
|
作者
Majumdar, Saikat [1 ]
Teodorescu, Radu [1 ]
机构
[1] Ohio State Univ, Dept Comp Sci & Engn, Columbus, OH 43210 USA
基金
美国国家科学基金会;
关键词
D O I
10.1109/HOST55342.2024.10545401
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Deep neural network (DNN) classifiers are known to be vulnerable to adversarial attacks, in which a model is induced to misclassify an input into the wrong class. These attacks affect virtually all state-of-the-art DNN models. While most adversarial attacks work by altering the classifier input, recent variants have also targeted the model parameters. This paper focuses on a new attack vector on DNN models that leverages computation errors, rather than memory errors, deliberately introduced during DNN inference to induce misclassification. In particular, it examines errors introduced by voltage noise into FPGA-based accelerators as the attack mechanism. In an advancement over prior work, the paper demonstrates that targeted attacks are possible, even when randomly occurring faults are used. It presents an approach for precisely characterizing the distribution of faults under noise of individual input devices, by examining classification errors in select inputs. It then shows how, by fine-tuning the parameters of the attack (noise levels and target DNN layers) the attacker can produce the desired misclassification class, without altering the original input. We demonstrate the attack on an FPGA device and show the attack success rate ranges between 80% and 99.5% depending on the DNN model and dataset.
引用
收藏
页码:80 / 85
页数:6
相关论文
共 50 条
  • [41] Quantifying the Impact of Adversarial Evasion Attacks on Machine Learning Based Android Malware Classifiers
    Abaid, Zainab
    Kaafar, Mohamed Ali
    Jha, Sanjay
    2017 IEEE 16TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2017, : 375 - 384
  • [42] Adversarial Attacks on Machine Learning-Based State Estimation in Power Distribution Systems
    Afrin, Afia
    Ardakanian, Omid
    PROCEEDINGS OF THE 2023 THE 14TH ACM INTERNATIONAL CONFERENCE ON FUTURE ENERGY SYSTEMS, E-ENERGY 2023, 2023, : 446 - 458
  • [43] Adversarial Machine Learning for Image-Based Radio Frequency Fingerprinting: Attacks and Defenses
    Papangelo, Lorenzo
    Pistilli, Maurizio
    Sciancalepore, Savio
    Oligeri, Gabriele
    Piro, Giuseppe
    Boggia, Gennaro
    IEEE COMMUNICATIONS MAGAZINE, 2024, 62 (11) : 108 - 113
  • [44] Rigorous Evaluation of Machine Learning-based Intrusion Detection Against Adversarial Attacks
    Gungor, Onat
    Li, Elvin
    Shang, Zhengli
    Guo, Yutong
    Chen, Jing
    Davis, Johnathan
    Rosing, Tajana
    2024 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2024, : 152 - 158
  • [45] Adversarial attacks against supervised machine learning based network intrusion detection systems
    Alshahrani, Ebtihaj
    Alghazzawi, Daniyal
    Alotaibi, Reem
    Rabie, Osama
    PLOS ONE, 2022, 17 (10):
  • [46] RETRACTED: Reinforcement learning-based controller for adaptive workflow scheduling in multi-tenant cloud computing (Retracted Article)
    Kumar, D. Suresh
    Kannan, R. Jagadeesh
    INTERNATIONAL JOURNAL OF ELECTRICAL ENGINEERING EDUCATION, 2020,
  • [47] Intelligent Resource Allocation Algorithm for 6G Multi-tenant Network Slicing Based on Deep Reinforcement Learning
    Guan W.-Q.
    Zhang H.-J.
    Lu Z.-M.
    Beijing Youdian Daxue Xuebao/Journal of Beijing University of Posts and Telecommunications, 2020, 43 (06): : 132 - 139
  • [48] Security for Machine Learning-based Systems: Attacks and Challenges during Training and Inference
    Khalid, Faiq
    Hanif, Muhammad Abdullah
    Rehman, Semeen
    Shafique, Muhammad
    2018 INTERNATIONAL CONFERENCE ON FRONTIERS OF INFORMATION TECHNOLOGY (FIT 2018), 2018, : 327 - 332
  • [49] Machine Learning Attacks on Voltage Over-scaling-based Lightweight Authentication
    Su, Haihan
    Zhang, Jiliang
    PROCEEDINGS OF THE 2018 ASIAN HARDWARE ORIENTED SECURITY AND TRUST SYMPOSIUM (ASIANHOST), 2018, : 50 - 55
  • [50] Adversarial attacks on machine learning-based cyber security systems: a survey of techniques and defences
    Patel, Pratik S.
    Panchal, Pooja
    INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2025, 17 (1-2)