AROMA: Evaluating Deep Learning Systems for Stealthy Integrity Attacks on Multi-tenant Accelerators

被引:0
|
作者
Chen, Xiangru [1 ]
Merugu, Maneesh [1 ]
Zhang, Jiaqi [1 ]
Ray, Sandip [1 ]
机构
[1] Univ Florida, POB 32611, Gainesville, FL 32611 USA
关键词
Integrity attack; neural networks; multi-tenant device; evaluation tool;
D O I
10.1145/3579033
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Multi-tenant applications have been proliferating in recent years, supported by the emergence of computingas-service paradigms. Unfortunately, multi-tenancy induces new security vulnerabilities due to spatial or temporal co-location of applications with possibly malicious intent. In this article, we consider a special class of stealthy integrity attacks on multi-tenant deep learning accelerators. One interesting conclusion is that it is possible to perform targeted integrity attacks on kernel weights of deep learning systems such that it remains functional but mis-labels specific categories of input data through standard RowHammer attacks by only changing 0.0009% of the total weights. We develop an automated framework, AROMA, to evaluate the impact of multi-tenancy on security of deep learning accelerators against integrity attacks on memory systems. We present extensive evaluations on AroMa to demonstrate its effectiveness.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] Neighbors From Hell: Voltage Attacks Against Deep Learning Accelerators on Multi-Tenant FPGAs
    Boutros, Andrew
    Hall, Mathew
    Papernot, Nicolas
    Betz, Vaughn
    2020 INTERNATIONAL CONFERENCE ON FIELD-PROGRAMMABLE TECHNOLOGY (ICFPT 2020), 2020, : 103 - 111
  • [2] Stealthy Logic Misuse for Power Analysis Attacks in Multi-Tenant FPGAs
    Gnad, Dennis R. E.
    Meyers, Vincent
    Dang, Nguyen Minh
    Schellenberg, Falk
    Moradi, Amir
    Tahoori, Mehdi B.
    PROCEEDINGS OF THE 2021 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION (DATE 2021), 2021, : 1012 - 1015
  • [3] Stealthy-Shutdown: Practical Remote Power Attacks in Multi-Tenant FPGAs
    Luo, Yukui
    Gongye, Cheng
    Ren, Shaolei
    Fei, Yunsi
    Xu, Xiaolin
    2020 IEEE 38TH INTERNATIONAL CONFERENCE ON COMPUTER DESIGN (ICCD 2020), 2020, : 545 - 552
  • [4] Voltage Noise-Based Adversarial Attacks on Machine Learning Inference in Multi-Tenant FPGA Accelerators
    Majumdar, Saikat
    Teodorescu, Radu
    2024 IEEE INTERNATIONAL SYMPOSIUM ON HARDWARE ORIENTED SECURITY AND TRUST, HOST, 2024, : 80 - 85
  • [5] FfDL: A Flexible Multi-tenant Deep Learning Platform
    Jayaram, K. R.
    Muthusamy, Vinod
    Dube, Parijat
    Ishakian, Vatche
    Wang, Chen
    Herta, Benjamin
    Boag, Scott
    Arroyo, Diana
    Tantawi, Asser
    Verma, Archit
    Pollok, Falk
    Khalaf, Rania
    MIDDLEWARE'19: PROCEEDINGS OF THE 2019 MIDDLEWARE'19: 20TH INTERNATIONAL MIDDLEWARE CONFERENCE, 2019, : 82 - 95
  • [6] Elastic Deep Learning in Multi-Tenant GPU Clusters
    Wu, Yidi
    Ma, Kaihao
    Yan, Xiao
    Liu, Zhi
    Cai, Zhenkun
    Huang, Yuzhen
    Cheng, James
    Yuan, Han
    Yu, Fan
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2022, 33 (01) : 144 - 158
  • [7] Mitigating Voltage Attacks in Multi-Tenant FPGAs
    Provelengios, George
    Holcomb, Daniel
    Tessier, Russell
    ACM TRANSACTIONS ON RECONFIGURABLE TECHNOLOGY AND SYSTEMS, 2021, 14 (02)
  • [8] A predictive replication for multi-tenant databases using deep learning
    Abdel Raouf, Ahmed E.
    Abo-alian, Alshaimaa
    Badr, Nagwa L.
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2021, 33 (13):
  • [9] Multi-Tenant FPGA-based Reconfigurable Systems: Attacks and Defenses
    Elnaggar, Rana
    Karri, Ramesh
    Chakrabarty, Krishnendu
    2019 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION (DATE), 2019, : 7 - 12
  • [10] Stealthy SWAPs: Adversarial SWAP Injection in Multi-Tenant Quantum Computing
    Upadhyay, Suryansh
    Ghosh, Swaroop
    PROCEEDINGS OF THE 37TH INTERNATIONAL CONFERENCE ON VLSI DESIGN, VLSID 2024 AND 23RD INTERNATIONAL CONFERENCE ON EMBEDDED SYSTEMS, ES 2024, 2024, : 474 - 479