Imperceptible Misclassification Attack on Deep Learning Accelerator by Glitch Injection

被引:22
|
作者
Liu, Wenye [1 ]
Chang, Chip-Hong [1 ]
Zhang, Fan [2 ]
Lou, Xiaoxuan [2 ]
机构
[1] Nanyang Technol Univ, Sch Elect & Elect Engn, Singapore, Singapore
[2] Zhejiang Univ, Coll Comp Sci & Technol, Hangzhou, Zhejiang, Peoples R China
关键词
NEURAL-NETWORKS;
D O I
10.1109/dac18072.2020.9218577
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The convergence of edge computing and deep learning empowers endpoint hardwares or edge devices to perform inferences locally with the help of deep neural network (DNN) accelerator. This trend of edge intelligence invites new attack vectors, which are methodologically different from the well-known software oriented deep learning attacks like the input of adversarial examples. Current studies of threats on DNN hardware focus mainly on model parameters interpolation. Such kind of manipulation is not stealthy as it will leave non-erasable traces or create conspicuous output patterns. In this paper, we present and investigate an imperceptible misclassification attack on DNN hardware by introducing infrequent instantaneous glitches into the clock signal. Comparing with falsifying model parameters by permanent faults, corruption of targeted intermediate results of convolution layer(s) by disrupting associated computations intermittently leaves no trace. We demonstrated our attack on nine state-of-the-art ImageNet models running on Xilinx FPGA based deep learning accelerator. With no knowledge about the models, our attack can achieve over 98% misclassification on 8 out of 9 models with only 10% glitches launched into the computation clock cycles. Given the model details and inputs, all the test images applied to ResNet50 can be successfully misclassified with no more than 1.7% glitch injection.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] Research on NVIDIA Deep Learning Accelerator
    Zhou, Gaofeng
    Zhou, Jianyang
    Lin, Haijun
    [J]. PROCEEDINGS OF 2018 12TH IEEE INTERNATIONAL CONFERENCE ON ANTI-COUNTERFEITING, SECURITY, AND IDENTIFICATION (ASID), 2018, : 192 - 195
  • [22] Fault Injection Attack on Deep Neural Network
    Liu, Yannan
    Wei, Lingxiao
    Luo, Bo
    Xu, Qiang
    [J]. 2017 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER-AIDED DESIGN (ICCAD), 2017, : 131 - 138
  • [23] Clock glitch fault injection attack on an FPGA-based non-autonomous chaotic oscillator
    Talal Bonny
    Qassim Nasir
    [J]. Nonlinear Dynamics, 2019, 96 : 2087 - 2101
  • [24] Explaining Image Misclassification in Deep Learning via Adversarial Examples
    Haffar, Rami
    Jebreel, Najeeb Moharram
    Domingo-Ferrer, Josep
    Sanchez, David
    [J]. MODELING DECISIONS FOR ARTIFICIAL INTELLIGENCE (MDAI 2021), 2021, 12898 : 323 - 334
  • [25] Clock glitch fault injection attack on an FPGA-based non-autonomous chaotic oscillator
    Bonny, Talal
    Nasir, Qassim
    [J]. NONLINEAR DYNAMICS, 2019, 96 (03) : 2087 - 2101
  • [26] Explaining Misclassification and Attacks in Deep Learning via Random Forests
    Haffar, Rami
    Domingo-Ferrer, Josep
    Sanchez, David
    [J]. MODELING DECISIONS FOR ARTIFICIAL INTELLIGENCE (MDAI 2020), 2020, 12256 : 273 - 285
  • [27] Modified Red Fox Optimizer With Deep Learning Enabled False Data Injection Attack Detection
    Alamro, Hayam
    Mahmood, Khalid
    Aljameel, Sumayh S.
    Yafoz, Ayman
    Alsini, Raed
    Mohamed, Abdullah
    [J]. IEEE ACCESS, 2023, 11 : 79256 - 79264
  • [28] Review of deep learning-based false data injection attack detection in power systems
    Li, Zhuo
    Xie, Yaobin
    Wu, Qianqiong
    Zhang, Youwei
    [J]. Dianli Xitong Baohu yu Kongzhi/Power System Protection and Control, 2024, 52 (19): : 175 - 187
  • [29] Deep learning based method for false data injection attack detection in AC smart islands
    Dehghani, Moslem
    Kavousi-Fard, Abdollah
    Dabbaghjamanesh, Morteza
    Avatefipour, Omid
    [J]. IET Generation, Transmission and Distribution, 2020, 14 (24): : 5816 - 5822
  • [30] Deep Learning in Cybersecurity: A Hybrid BERT-LSTM Network for SQL Injection Attack Detection
    Liu, Yixian
    Dai, Yupeng
    [J]. IET INFORMATION SECURITY, 2024, 2024