DeepHammer: Depleting the Intelligence of Deep Neural Networks through Targeted Chain of Bit Flips

被引:0
|
作者
Yao, Fan [1 ]
Rakin, Adnan Siraj [2 ]
Fan, Deliang [2 ]
机构
[1] Univ Cent Florida, Orlando, FL 32816 USA
[2] Arizona State Univ, Tempe, AZ 85287 USA
基金
美国国家科学基金会;
关键词
HARDWARE;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security of machine learning is increasingly becoming a major concern due to the ubiquitous deployment of deep learning in many security-sensitive domains. Many prior studies have shown external attacks such as adversarial examples that tamper the integrity of DNNs using maliciously crafted inputs. However, the security implication of internal threats (i.e., hardware vulnerabilities) to DNN models has not yet been well understood. In this paper, we demonstrate the first hardware-based attack on quantized deep neural networks-DeepHammer-that deterministically induces bit flips in model weights to compromise DNN inference by exploiting the rowhammer vulnerability. DeepHammer performs an aggressive bit search in the DNN model to identify the most vulnerable weight bits that are flippable under system constraints. To trigger deterministic bit flips across multiple pages within a reasonable amount of time, we develop novel system-level techniques that enable fast deployment of victim pages, memory-efficient rowhammering and precise flipping of targeted bits. DeepHammer can deliberately degrade the inference accuracy of the victim DNN system to a level that is only as good as random guess, thus completely depleting the intelligence of targeted DNN systems. We systematically demonstrate our attacks on real systems against 11 DNN architectures with 4 datasets corresponding to different application domains. Our evaluation shows that DeepHammer is able to successfully tamper DNN inference behavior at run-time within a few minutes. We further discuss several mitigation techniques from both algorithm and system levels to protect DNNs against such attacks. Our work highlights the need to incorporate security mechanisms in future machine learning systems to enhance the robustness of DNN against hardware-based deterministic fault injections.
引用
收藏
页码:1463 / 1480
页数:18
相关论文
共 50 条
  • [11] Bit Fusion: Bit-Level Dynamically Composable Architecture for Accelerating Deep Neural Networks
    Sharma, Hardik
    Park, Jongse
    Suda, Naveen
    Lai, Liangzhen
    Chau, Benson
    Chandra, Vikas
    Esmaeilzadeh, Hadi
    2018 ACM/IEEE 45TH ANNUAL INTERNATIONAL SYMPOSIUM ON COMPUTER ARCHITECTURE (ISCA), 2018, : 764 - 775
  • [12] Neural Cache: Bit-Serial In-Cache Acceleration of Deep Neural Networks
    Eckert, Charles
    Wang, Xiaowei
    Wang, Jingcheng
    Subramaniyan, Arun
    Iyer, Ravi
    Sylvester, Dennis
    Blaauw, David
    Das, Reetuparna
    2018 ACM/IEEE 45TH ANNUAL INTERNATIONAL SYMPOSIUM ON COMPUTER ARCHITECTURE (ISCA), 2018, : 383 - 396
  • [13] Neural Cache: Bit-Serial In-Cache Acceleration of Deep Neural Networks
    Eckert, Charles
    Wang, Xiaowei
    Wang, Jingcheng
    Subramaniyan, Arun
    Iyer, Ravi
    Sylvester, Dennis
    Blaauw, David
    Das, Reetuparna
    IEEE MICRO, 2019, 39 (03) : 11 - 19
  • [14] OPTIMIZING THE BIT ALLOCATION FOR COMPRESSION OF WEIGHTS AND ACTIVATIONS OF DEEP NEURAL NETWORKS
    Zhe, Wang
    Lin, Jie
    Chandrasekhar, Vijay
    Girod, Bernd
    2019 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2019, : 3826 - 3830
  • [15] EncoDeep: Realizing Bit-flexible Encoding for Deep Neural Networks
    Samragh, Mohammad
    Javaheripi, Mojan
    Koushanfar, Farinaz
    ACM TRANSACTIONS ON EMBEDDED COMPUTING SYSTEMS, 2020, 19 (06)
  • [16] Bit Prudent In-Cache Acceleration of Deep Convolutional Neural Networks
    Wang, Xiaowei
    Yu, Jiecao
    Augustine, Charles
    Iyer, Ravi
    Das, Reetuparna
    2019 25TH IEEE INTERNATIONAL SYMPOSIUM ON HIGH PERFORMANCE COMPUTER ARCHITECTURE (HPCA), 2019, : 81 - 93
  • [17] Toponym matching through deep neural networks
    Santos, Rui
    Murrieta-Flores, Patricia
    Calado, Pavel
    Martins, Bruno
    INTERNATIONAL JOURNAL OF GEOGRAPHICAL INFORMATION SCIENCE, 2018, 32 (02) : 324 - 348
  • [18] Uncertainty Propagation through Deep Neural Networks
    Abdelaziz, Ahmed Hussen
    Watanabe, Shinji
    Hershey, John R.
    Vincent, Emanuel
    Kolossa, Dorothea
    16TH ANNUAL CONFERENCE OF THE INTERNATIONAL SPEECH COMMUNICATION ASSOCIATION (INTERSPEECH 2015), VOLS 1-5, 2015, : 3561 - 3565
  • [19] ATTL: An Automated Targeted Transfer Learning with Deep Neural Networks
    Ahamed, Sayyed Farid
    Aggarwal, Priyanka
    Shetty, Sachin
    Lanus, Erin
    Freeman, Laura J.
    2021 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2021,
  • [20] Multi-Targeted Poisoning Attack in Deep Neural Networks
    Kwon H.
    Cho S.
    IEICE Transactions on Information and Systems, 2022, E105D (11): : 1916 - 1920