Imperceptible Misclassification Attack on Deep Learning Accelerator by Glitch Injection

被引:22
|
作者
Liu, Wenye [1 ]
Chang, Chip-Hong [1 ]
Zhang, Fan [2 ]
Lou, Xiaoxuan [2 ]
机构
[1] Nanyang Technol Univ, Sch Elect & Elect Engn, Singapore, Singapore
[2] Zhejiang Univ, Coll Comp Sci & Technol, Hangzhou, Zhejiang, Peoples R China
关键词
NEURAL-NETWORKS;
D O I
10.1109/dac18072.2020.9218577
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The convergence of edge computing and deep learning empowers endpoint hardwares or edge devices to perform inferences locally with the help of deep neural network (DNN) accelerator. This trend of edge intelligence invites new attack vectors, which are methodologically different from the well-known software oriented deep learning attacks like the input of adversarial examples. Current studies of threats on DNN hardware focus mainly on model parameters interpolation. Such kind of manipulation is not stealthy as it will leave non-erasable traces or create conspicuous output patterns. In this paper, we present and investigate an imperceptible misclassification attack on DNN hardware by introducing infrequent instantaneous glitches into the clock signal. Comparing with falsifying model parameters by permanent faults, corruption of targeted intermediate results of convolution layer(s) by disrupting associated computations intermittently leaves no trace. We demonstrated our attack on nine state-of-the-art ImageNet models running on Xilinx FPGA based deep learning accelerator. With no knowledge about the models, our attack can achieve over 98% misclassification on 8 out of 9 models with only 10% glitches launched into the computation clock cycles. Given the model details and inputs, all the test images applied to ResNet50 can be successfully misclassified with no more than 1.7% glitch injection.
引用
收藏
页数:6
相关论文
共 50 条
  • [41] Modeling Deep Learning Accelerator Enabled GPUs
    Raihan, Md Aamir
    Goli, Negar
    Aamodt, Tor M.
    [J]. 2019 IEEE INTERNATIONAL SYMPOSIUM ON PERFORMANCE ANALYSIS OF SYSTEMS AND SOFTWARE (ISPASS), 2019, : 79 - 92
  • [42] Data scheduling and placement in deep learning accelerator
    Seyedeh Yasaman Hosseini Mirmahaleh
    Midia Reshadi
    Nader Bagherzadeh
    Ahmad Khademzadeh
    [J]. Cluster Computing, 2021, 24 : 3651 - 3669
  • [43] An OpenCLTM Deep Learning Accelerator on Arria 10
    Aydonat, Utku
    O'Connell, Shane
    Capalija, Davor
    Ling, Andrew C.
    Chiu, Gordon R.
    [J]. FPGA'17: PROCEEDINGS OF THE 2017 ACM/SIGDA INTERNATIONAL SYMPOSIUM ON FIELD-PROGRAMMABLE GATE ARRAYS, 2017, : 55 - 64
  • [44] ReRAM-based Accelerator for Deep Learning
    Li, Bing
    Song, Linghao
    Chen, Fan
    Qian, Xuehai
    Chen, Yiran
    Li, Hai
    [J]. PROCEEDINGS OF THE 2018 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION (DATE), 2018, : 815 - 820
  • [45] An Imperceptible Data Augmentation Based Blackbox Clean-Label Backdoor Attack on Deep Neural Networks
    Xu, Chaohui
    Liu, Wenye
    Zheng, Yue
    Wang, Si
    Chang, Chip-Hong
    [J]. IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS I-REGULAR PAPERS, 2023, 70 (12) : 5011 - 5024
  • [46] GlitchNet: A Glitch Detection and Removal System for SEIS Records Based on Deep Learning
    Xu, Wuchuan
    Zhu, Qiwen
    Zhao, Li
    [J]. SEISMOLOGICAL RESEARCH LETTERS, 2022, 93 (05) : 2804 - 2817
  • [47] A Deep Learning-Based Classification Scheme for False Data Injection Attack Detection in Power System
    Ding, Yucheng
    Ma, Kang
    Pu, Tianjiao
    Wang, Xinying
    Li, Ran
    Zhang, Dongxia
    [J]. ELECTRONICS, 2021, 10 (12)
  • [48] LESSON: Multi-Label Adversarial False Data Injection Attack for Deep Learning Locational Detection
    Tian, Jiwei
    Shen, Chao
    Wang, Buhong
    Xia, Xiaofang
    Zhang, Meng
    Lin, Chenhao
    Li, Qian
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (05) : 4418 - 4432
  • [49] DeepPayload: Black-box Backdoor Attack on Deep Learning Models through Neural Payload Injection
    Li, Yuanchun
    Hua, Liayi
    Wang, Haoyu
    Chen, Chunyang
    Liu, Yunxin
    [J]. 2021 IEEE/ACM 43RD INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE 2021), 2021, : 263 - 274
  • [50] Federated Deep Learning Model for False Data Injection Attack Detection in Cyber Physical Power Systems
    Kausar, Firdous
    Deo, Sambrdhi
    Hussain, Sajid
    Ul Haque, Zia
    [J]. Energies, 2024, 17 (21)