DeepStrike: Remotely-Guided Fault Injection Attacks on DNN Accelerator in Cloud-FPGA
Yukui Luo, Cheng Gongye, Yunsi Fei, Xiaolin Xu
Abstract
As Field-programmable gate arrays (FPGAs) are widely adopted in clouds to accelerate Deep Neural Networks (DNN), such virtualization environments have posed many new security issues. This work investigates the integrity of DNN FPGA accelerators in clouds. It proposes DeepStrike, a remotely-guided attack based on power glitching fault injections targeting DNN execution. We characterize the vulnerabilities of different DNN layers against fault injections on FPGAs and leverage time-to-digital converter (TDC) sensors to precisely control the timing of fault injections. Experimental results show that our proposed attack can successfully disrupt the FPGA DSP kernel and misclassify the target victim DNN application.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Pentimento: Data Remanence in Cloud FPGAsColin Drewes, Olivia Weng, Andres Meza, Alric Althoff et al.ASPLOS 2024 · 2 citations
- SoK: Colluding Adversaries in Machine Learning PipelinesVasisht Duddu, Lipeng He, Asim Waheed, N. AsokanUSENIX Security 2026
- NeuroPots: Realtime Proactive Defense against Bit-Flip Attacks in Neural NetworksQi Liu, Jieming Yin, Wujie Wen, Chengmo Yang et al.USENIX Security 2023
Builds on5
- FPGA-Based Remote Power Side-Channel AttacksMark Zhao, G. Edward SuhS&P 2018 · 301 citations
- Virtualizing FPGAs in the CloudYue Zha, Jing LiASPLOS 2020 · 92 citations
- Deep-Dup: An Adversarial Weight Duplication Attack Framework to Crush Deep Neural Network in Multi-Tenant FPGAAdnan Siraj Rakin, Yukui Luo, Xiaolin Xu, Deliang FanUSENIX Security 2021 · 64 citations
- Imperceptible Misclassification Attack on Deep Learning Accelerator by Glitch InjectionWenye Liu, Chip-Hong Chang, Fan Zhang, Xiaoxuan LouDAC 2020 · 51 citations
- DeepHammer: Depleting the Intelligence of Deep Neural Networks through Targeted Chain of Bit FlipsFan Yao, Adnan Siraj Rakin, Deliang FanUSENIX Security 2020
Related papers
- Side-Channel-Assisted Reverse-Engineering of Encrypted DNN Hardware Accelerator IP and Attack Surface ExplorationCheng Gongye, Yukui Luo, Xiaolin Xu, Yunsi FeiS&P 2024 · 25 citations
- DeepCache: Revisiting Cache Side-Channel Attacks in Deep Neural Networks ExecutablesZhibo Liu, Yuanyuan Yuan, Yanzuo Chen, Sihang Hu et al.CCS 2024 · 3 citations
- DeepShuffle: A Lightweight Defense Framework against Adversarial Fault Injection Attacks on Deep Neural Networks in Multi-Tenant Cloud-FPGAYukui Luo, Adnan Siraj Rakin, Deliang Fan, Xiaolin XuS&P 2024 · 4 citations
- DARPT: defense against remote physical attack based on TDC in multi-tenant scenarioFan Zhang, Zhiyong Wang, Haoting Shen, Bolin Yang et al.DAC 2022 · 8 citations
- GlitchFHE: Attacking Fully Homomorphic Encryption Using Fault InjectionLakshmi Likhitha Mankali, Mohammed Nabeel, Faiq Raees, Michail Maniatakos et al.USENIX Security 2025
