An Energy-Efficient Neural Network Accelerator With Improved Resilience Against Fault Attacks

被引:1
作者
Maji, Saurav [1 ,2 ]
Lee, Kyungmi [1 ]
Gongye, Cheng [3 ,4 ]
Fei, Yunsi [3 ]
Chandrakasan, Anantha P. [1 ]
机构
[1] MIT, Dept Elect Engn & Comp Sci, Cambridge, MA 02139 USA
[2] Intel Corp, Hillsboro, OR 97124 USA
[3] Northeastern Univ, Dept Elect & Comp Engn, Boston, MA 02115 USA
[4] Nvidia Corp, Santa Clara, CA 95051 USA
关键词
Data authentication; fault attacks (FAs); fault detection; hardware security; neural networks (NNs);
D O I
10.1109/JSSC.2024.3374638
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Embedded neural network (NN) implementations are vulnerable to misclassification under fault attacks (FAs). Clock glitching and injecting strong electromagnetic (EM) pulses are two simple yet detrimental FA techniques that disrupt the NN by: 1) introducing errors in the NN model and 2) corrupting NN computation results. This article introduces the first application-specific integrated circuit (ASIC) demonstration of an energy-efficient NN accelerator equipped with built-in FA detection capabilities. We have integrated lightweight cryptography-based checks for on-chip verification to identify model errors and additionally serve as a fault detection sensor for spotting computational errors. We showcase high error-detection capabilities along with a minimal area overhead of 5.9% and negligible impact on NN accuracy.
引用
收藏
页码:3106 / 3116
页数:11
相关论文
共 40 条
  • [1] A Survey on Fault Attacks on Symmetric Key Cryptosystems
    Baksi, Anubhab
    Bhasin, Shivam
    Breier, Jakub
    Jap, Dirmanto
    Saha, Dhiman
    [J]. ACM COMPUTING SURVEYS, 2023, 55 (04)
  • [2] Poster: Recovering the Input of Neural Networks via Single Shot Side-channel Attacks
    Batina, Lejla
    Bhasin, Shivam
    Jap, Dirmanto
    Picek, Stjepan
    [J]. PROCEEDINGS OF THE 2019 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'19), 2019, : 2657 - 2659
  • [3] Batina L, 2019, PROCEEDINGS OF THE 28TH USENIX SECURITY SYMPOSIUM, P515
  • [4] CRAFT: Lightweight Tweakable Block Cipher with Efficient Protection Against DFA Attacks
    Beierle, Christof
    Leander, Gregor
    Moradi, Amir
    Rasoolzadeh, Shahram
    [J]. IACR TRANSACTIONS ON SYMMETRIC CRYPTOLOGY, 2019, 2019 (01) : 5 - 45
  • [5] How Practical Are Fault Injection Attacks, Really?
    Breier, Jakub
    Hou, Xiaolu
    [J]. IEEE ACCESS, 2022, 10 : 113122 - 113130
  • [6] SNIFF: Reverse Engineering of Neural Networks With Fault Attacks
    Breier, Jakub
    Jap, Dirmanto
    Hou, Xiaolu
    Bhasin, Shivam
    Liu, Yang
    [J]. IEEE TRANSACTIONS ON RELIABILITY, 2022, 71 (04) : 1527 - 1539
  • [7] POSTER: Practical Fault Attack on Deep Neural Networks
    Breier, Jakub
    Hou, Xiaolu
    Jap, Dirmanto
    Ma, Lei
    Bhasin, Shivam
    Liu, Yang
    [J]. PROCEEDINGS OF THE 2018 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'18), 2018, : 2204 - 2206
  • [8] Burel S., 2021, 27th International Symposium on On-Line Testing and Robust System Design (IOLTS), P1
  • [9] Doulcier-Verdier M., 2011, 2011 IEEE International Solid-State Circuits Conference (ISSCC 2011), P274, DOI 10.1109/ISSCC.2011.5746316
  • [10] Dworkin M., 2010, 80038E NIST SP, P1