USENIX Security2023Top-tier venue
Aegis: Mitigating Targeted Bit-flip Attacks against Deep Neural Networks
Jialai Wang, Ziyuan Zhang, Meiqi Wang, Han Qiu, Tianwei Zhang, Qi Li, Zongpeng Li, Tao Wei, Chao Zhang
Abstract
Bit-flip attacks (BFAs) have attracted substantial attention recently, in which an adversary could tamper with a small number of model parameter bits to break the integrity of DNNs. To mitigate such threats, a batch of defense methods are proposed, focusing on the untargeted scenarios. Unfortunately, they either require extra trustworthy applications or make models more vulnerable to targeted BFAs. Countermeasures against targeted BFAs, stealthier and more purposeful by nature, are far from well established. In this work, we propose Aegis, a novel defense method to mitigate targeted BFAs. The core observation is that existing targeted attacks focus on flipping critical bits in certain important layers. Thus, we design a dynamic-exit mechanism to attach extra internal classifiers (ICs) to hidden layers. This mechanism enables input samples to early-exit from different layers, which effectively upsets the adversary's attack plans. Moreover, the dynamic-exit mechanism randomly selects ICs for predictions during each inference to significantly increase the attack cost for the adaptive attacks where all defense mechanisms are transparent to the adversary. We further propose a robustness training strategy to adapt ICs to the attack scenarios by simulating BFAs during the IC training phase, to increase model robustness. Extensive evaluations over four well-known datasets and two popular DNN structures reveal that Aegis could effectively mitigate different state-of-the-art targeted attacks, reducing attack success rate by 5-10, significantly outperforming existing defense methods.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 390b9f3d-c89d-47f3-9000-1cdec5a6cd3cCited by top-tier papers12
- Yes, One-Bit-Flip Matters! Universal DNN Model Inference Depletion with Runtime Code Fault InjectionShaofeng Li, Xinyu Wang, Minhui Xue, Haojin Zhu et al.USENIX Security 2024 · 32 citations
- Forget and Rewire: Enhancing the Resilience of Transformer-based Models against Bit-Flip AttacksNajmeh Nazari, Hosein Mohammadi Makrani, Chongzhou Fang, Hossein Sayadi et al.USENIX Security 2024 · 21 citations
- Securing Graph Neural Networks in MLaaS: A Comprehensive Realization of Query-based Integrity VerificationBang Wu, Xingliang Yuan, Shuo Wang, Qi Li et al.S&P 2024 · 13 citations
- SAVE: Software-Implemented Fault Tolerance for Model Inference against GPU Memory Bit FlipsWenxin Zheng, Bin Xu, Jinyu Gu, Haibo ChenUSENIX ATC 2025 · 8 citations
- Improving LLM-based Log Parsing by Learning from Errors in Reasoning TracesJialai Wang, Juncheng Lu, Jie Yang, Junjie Wang et al.ASE 2025 · 2 citations
Builds on34
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Supervised Contrastive LearningPrannay Khosla, Piotr Teterwak, Chen Wang, Aaron Sarna et al.NeurIPS 2020 · 7,049 citations
- What Makes for Good Views for Contrastive Learning?Yonglong Tian, Chen Sun, Ben Poole, Dilip Krishnan et al.NeurIPS 2020 · 1,631 citations
- Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by BackdooringYossi Adi, Carsten Baum, Moustapha Cissé, Benny Pinkas et al.USENIX Security 2018 · 832 citations
- Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural NetworksYige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu et al.ICLR 2021 · 548 citations
Related papers
- BitShield: Defending Against Bit-Flip Attacks on DNN ExecutablesYanzuo Chen, Yuanyuan Yuan, Zhibo Liu, Sihang Hu et al.NDSS 2025
- HammerDodger: A Lightweight Defense Framework against RowHammer Attack on DNNsCheng Gongye, Yukui Luo, Xiaolin Xu, Yunsi FeiDAC 2023 · 5 citations
- Compiled Models, Built-In Exploits: Uncovering Pervasive Bit-Flip Attack Surfaces in DNN ExecutablesYanzuo Chen, Zhibo Liu, Yuanyuan Yuan, Sihang Hu et al.NDSS 2025
- Improving Robustness Against Stealthy Weight Bit-Flip Attacks by Output Code MatchingOzan Özdenizci, Robert LegensteinCVPR 2022 · 11 citations
- Defending Bit-Flip Attack through DNN Weight ReconstructionJingtao Li, Adnan Siraj Rakin, Yan Xiong, Liangliang Chang et al.DAC 2020 · 55 citations
