Telepathic Headache: Mitigating Cache Side-Channel Attacks on Convolutional Neural Networks

被引:1
|
作者
Chabanne, Herve [1 ,2 ]
Danger, Jean-Luc [2 ]
Guiga, Linda [1 ,2 ]
Kuhne, Ulrich [2 ]
机构
[1] Idemia, Paris, France
[2] Telecom Paris, Paris, France
关键词
Side-channel attack; CNN protection; Model extraction;
D O I
10.1007/978-3-030-78372-3_14
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Convolutional Neural Networks (CNNs) are the target of several side-channel attacks aiming at recovering their parameters and hyper-parameters. Attack vectors include monitoring of the cache, power consumption analysis and execution time measurements. These attacks often rely on the knowledge of a certain - large - set of hyper-parameters among which the victim model lies. The goal of the potential attacker is then to reduce that search space or even deduce the correct architecture. One such attack, Cache Telepathy by Yan et al., monitors access to a common matrix multiplication algorithm, GeMM (Generalized Matrix Multiply), in order to determine the victim model's hyper-parameters. In this paper, we propose to change the order in which the computations are made and add randomness to the said computations in order to mitigate Cache Telepathy. The security analysis of our protection shows that the Cache Telepathy attack on a protected VGG-16 has an increased search space: from 16 to 2(22).
引用
收藏
页码:363 / 392
页数:30
相关论文
共 50 条
  • [1] Parasite: Mitigating Physical Side-Channel Attacks Against Neural Networks
    Chabanne, Herve
    Danger, Jean-Luc
    Guiga, Linda
    Kuhne, Ulrich
    [J]. SECURITY, PRIVACY, AND APPLIED CRYPTOGRAPHY ENGINEERING, SPACE 2021, 2022, 13162 : 148 - 167
  • [2] Cache Side-Channel Attacks and Defenses
    Zhang, Weijuan
    Bai, Lu
    Ling, Yuqing
    Lan, Xiao
    Jia, Xiaoqi
    [J]. Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2023, 60 (01): : 206 - 222
  • [3] CONDENSE: A Moving Target Defense Approach for Mitigating Cache Side-Channel Attacks
    Dai, Chenxi
    Adegbija, Tosiron
    [J]. IEEE CONSUMER ELECTRONICS MAGAZINE, 2020, 9 (03) : 114 - 119
  • [4] SCAAT: Secure Cache Alternative Address Table for mitigating cache logical side-channel attacks
    Shalabi, Ameer
    Ghasempouri, Tara
    Ellervee, Peeter
    Raik, Jaan
    [J]. 2020 23RD EUROMICRO CONFERENCE ON DIGITAL SYSTEM DESIGN (DSD 2020), 2020, : 213 - 217
  • [5] The investigation of neural networks performance in side-channel attacks
    Yinan Kong
    Ehsan Saeedi
    [J]. Artificial Intelligence Review, 2019, 52 : 607 - 623
  • [6] TinyPower: Side-Channel Attacks with Tiny Neural Networks
    Li, Haipeng
    Ninan, Mabon
    Wang, Boyang
    Emmert, John M.
    [J]. 2024 IEEE INTERNATIONAL SYMPOSIUM ON HARDWARE ORIENTED SECURITY AND TRUST, HOST, 2024, : 320 - 331
  • [7] The investigation of neural networks performance in side-channel attacks
    Kong, Yinan
    Saeedi, Ehsan
    [J]. ARTIFICIAL INTELLIGENCE REVIEW, 2019, 52 (01) : 607 - 623
  • [8] Cache Side-Channel Attacks in Cloud Computing
    Younis, Younis
    Kifayat, Kashif
    Merabti, Madjid
    [J]. PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON CLOUD SECURITY MANAGEMENT (ICCSM-2014), 2014, : 138 - 146
  • [9] On the Performance of Convolutional Neural Networks for Side-Channel Analysis
    Picek, Stjepan
    Samiotis, Ioannis Petros
    Kim, Jaehun
    Heuser, Annelie
    Bhasin, Shivam
    Legay, Axel
    [J]. SECURITY, PRIVACY, AND APPLIED CRYPTOGRAPHY ENGINEERING, SPACE 2018, 2018, 11348 : 157 - 176
  • [10] Convolutional Neural Networks for Profiled Side-Channel Analysis
    Hou, Shourong
    Zhou, Yujie
    Liu, Hongming
    [J]. RADIOENGINEERING, 2019, 28 (03) : 651 - 658