CSpace  > 中国科学院计算技术研究所期刊论文  > 英文
Practical Attacks on Deep Neural Networks by Memory Trojaning
Hu, Xing1; Zhao, Yang2; Deng, Lei3; Liang, Ling3; Zuo, Pengfei4; Ye, Jing1; Lin, Yingyan2; Xie, Yuan3
2021-06-01
发表期刊IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS
ISSN0278-0070
卷号40期号:6页码:1230-1243
摘要Deep neural network (DNN) accelerators are widely deployed in computer vision, speech recognition, and machine translation applications, in which attacks on DNNs have become a growing concern. This article focuses on exploring the implications of hardware Trojan attacks on DNNs. Trojans are one of the most challenging threat models in hardware security where adversaries insert malicious modifications to the original integrated circuits (ICs), leading to malfunction once being triggered. Such attacks can be conducted by adversaries because modern ICs commonly include third-party intellectual property (IP) blocks. Previous studies design hardware Trojans to attack DNNs with the assumption that adversaries have full knowledge or manipulation of the DNN systems' victim model and toolchain in addition to the hardware platforms, yet such a threat model is strict, limiting their practical adoption. In this article, we propose a memory Trojan methodology that implants the malicious logics merely into the memory controllers of DNN systems without the necessity of toolchain manipulation or accessing to the victim model and thus is feasible for practical uses. Specifically, we locate the input image data among the massive volume of memory traffics based on memory access patterns and propose a Trojan trigger mechanism based on detecting the geometric feature in input images. Extensive experiments show that the proposed trigger mechanism is effective even in the presence of environmental noises and preprocessing operations. Furthermore, we design and implement the payload and verify that the proposed Trojan technique can effectively conduct both untargeted and targeted attacks on DNNs.
关键词Trojan horses Hardware Integrated circuit modeling Computational modeling Security Payloads Convolutional neural networks (CNNs) deep learning accelerator deep learning attack hardware Trojan
DOI10.1109/TCAD.2020.2995347
收录类别SCI
语种英语
资助项目National Science Foundation[1725447] ; National Science Foundation[1730309]
WOS研究方向Computer Science ; Engineering
WOS类目Computer Science, Hardware & Architecture ; Computer Science, Interdisciplinary Applications ; Engineering, Electrical & Electronic
WOS记录号WOS:000652792400018
出版者IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
引用统计
被引频次:16[WOS]   [WOS记录]     [WOS相关记录]
文献类型期刊论文
条目标识符http://119.78.100.204/handle/2XEOYT63/17567
专题中国科学院计算技术研究所期刊论文_英文
通讯作者Deng, Lei
作者单位1.Chinese Acad Sci, Inst Comp Technol, State Key Lab Comp Architecture, Beijing 100190, Peoples R China
2.Rice Univ, Dept Elect & Comp Engn, Houston, TX 77005 USA
3.Univ Calif Santa Barbara, Dept Elect & Comp Engn, Santa Barbara, CA 93106 USA
4.Huazhong Univ Sci & Technol, Dept Comp Sci & Technol, Wuhan 430074, Peoples R China
推荐引用方式
GB/T 7714
Hu, Xing,Zhao, Yang,Deng, Lei,et al. Practical Attacks on Deep Neural Networks by Memory Trojaning[J]. IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS,2021,40(6):1230-1243.
APA Hu, Xing.,Zhao, Yang.,Deng, Lei.,Liang, Ling.,Zuo, Pengfei.,...&Xie, Yuan.(2021).Practical Attacks on Deep Neural Networks by Memory Trojaning.IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS,40(6),1230-1243.
MLA Hu, Xing,et al."Practical Attacks on Deep Neural Networks by Memory Trojaning".IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS 40.6(2021):1230-1243.
条目包含的文件
条目无相关文件。
个性服务
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Hu, Xing]的文章
[Zhao, Yang]的文章
[Deng, Lei]的文章
百度学术
百度学术中相似的文章
[Hu, Xing]的文章
[Zhao, Yang]的文章
[Deng, Lei]的文章
必应学术
必应学术中相似的文章
[Hu, Xing]的文章
[Zhao, Yang]的文章
[Deng, Lei]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。