AROMA: Evaluating Deep Learning Systems for Stealthy Integrity Attacks on Multi-tenant Accelerators

被引:0
|
作者
Chen, Xiangru [1 ]
Merugu, Maneesh [1 ]
Zhang, Jiaqi [1 ]
Ray, Sandip [1 ]
机构
[1] Univ Florida, POB 32611, Gainesville, FL 32611 USA
关键词
Integrity attack; neural networks; multi-tenant device; evaluation tool;
D O I
10.1145/3579033
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Multi-tenant applications have been proliferating in recent years, supported by the emergence of computingas-service paradigms. Unfortunately, multi-tenancy induces new security vulnerabilities due to spatial or temporal co-location of applications with possibly malicious intent. In this article, we consider a special class of stealthy integrity attacks on multi-tenant deep learning accelerators. One interesting conclusion is that it is possible to perform targeted integrity attacks on kernel weights of deep learning systems such that it remains functional but mis-labels specific categories of input data through standard RowHammer attacks by only changing 0.0009% of the total weights. We develop an automated framework, AROMA, to evaluate the impact of multi-tenancy on security of deep learning accelerators against integrity attacks on memory systems. We present extensive evaluations on AroMa to demonstrate its effectiveness.
引用
收藏
页数:17
相关论文
共 50 条
  • [41] Reinforcement Learning for Resource Management in Multi-tenant Serverless Platforms
    Qiu, Haoran
    Mao, Weichao
    Patke, Archit
    Wang, Chen
    Franke, Hubertus
    Kalbarczyk, Zbigniew T.
    Basar, Tamer
    Iyer, Ravishankar K.
    PROCEEDINGS OF THE 2022 2ND EUROPEAN WORKSHOP ON MACHINE LEARNING AND SYSTEMS (EUROMLSYS '22), 2022, : 20 - 28
  • [42] A Platform Architecture for Multi-Tenant Blockchain-Based Systems
    Weber, Ingo
    Lu, Qinghua
    An Binh Tran
    Deshmukh, Amit
    Gorski, Marek
    Strazds, Markus
    2019 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ARCHITECTURE (ICSA), 2019, : 101 - 110
  • [43] Using Intrusive Microservices to Enable Deep Customization of Multi-Tenant SaaS
    Chauvel, Franck
    Solberg, Arnor
    2018 11TH INTERNATIONAL CONFERENCE ON THE QUALITY OF INFORMATION AND COMMUNICATIONS TECHNOLOGY (QUATIC), 2018, : 30 - 37
  • [44] Triton: Software-Defined Threat Model for Secure Multi-Tenant ML Inference Accelerators
    Banerjee, Sarbartha
    Wei, Shijia
    Ramrakhyani, Prakash
    Tiwari, Mohit
    PROCEEDINGS OF THE 12TH INTERNATIONAL WORKSHOP ON HARDWARE AND ARCHITECTURAL SUPPORT FOR SECURITY AND PRIVACY, HASP 2023, 2023, : 19 - 28
  • [45] NestDNN: Resource-Aware Multi-Tenant On-Device Deep Learning for Continuous Mobile Vision
    Fang, Biyi
    Zeng, Xiao
    Zhang, Mi
    MOBICOM'18: PROCEEDINGS OF THE 24TH ANNUAL INTERNATIONAL CONFERENCE ON MOBILE COMPUTING AND NETWORKING, 2018, : 115 - 127
  • [46] Deep reinforcement learning for application scheduling in resource-constrained, multi-tenant serverless computing environments
    Mampage, Anupama
    Karunasekera, Shanika
    Buyya, Rajkumar
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2023, 143 : 277 - 292
  • [47] Stealthy Integrity Attacks for a Class of Nonlinear Cyber-Physical Systems
    Zhang, Kangkang
    Keliris, Christodoulos
    Parisini, Thomas
    Polycarpou, Marios M.
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2022, 67 (12) : 6723 - 6730
  • [48] Towards the Detection of Mobile DDoS Attacks in 5G Multi-Tenant Networks
    Mamolar, Ana Serrano
    Pervez, Zeeshan
    Wang, Qi
    Alcaraz-Calero, Jose M.
    2019 EUROPEAN CONFERENCE ON NETWORKS AND COMMUNICATIONS (EUCNC), 2019, : 273 - 277
  • [49] LoopBreaker: Disabling Interconnects to Mitigate Voltage-Based Attacks in Multi-Tenant FPGAs
    Nassar, Hassan
    AlZughbi, Hanna
    Gnad, Dennis R. E.
    Bauer, Lars
    Tahoori, Mehdi B.
    Henkel, Jorg
    2021 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER AIDED DESIGN (ICCAD), 2021,
  • [50] Exploring Remote Power Attacks Targeting Parallel Data Encryption On Multi-Tenant FPGAs
    Zhu, Yankun
    Zhou, Jindong
    Zhou, Pingqiang
    PROCEEDINGS OF THE GREAT LAKES SYMPOSIUM ON VLSI 2023, GLSVLSI 2023, 2023, : 57 - 62