DeepVenom: Persistent DNN Backdoors Exploiting Transient Weight Perturbations in Memories
Kunbei Cai, Md Hafizul Islam Chowdhuryy, Zhenkai Zhang, Fan Yao
Abstract
Backdoor attacks have raised significant concerns in machine learning (ML) systems. Mainstream ML backdoor attacks typically involve either poisoning the victim’s training samples or pre-training poisoned models for use by victim users. Meanwhile, recent advances in hardware-based threats reveal that ML model integrity at inference-time can be seriously tampered by inducing transient faults in model weights. However, the adversarial impacts of such hardware fault attacks at training time have not been well understood.In this paper, we present DeepVenom, the first end-to-end hardware-based DNN backdoor attack during victim model training. Particularly, DeepVenom can insert a targeted backdoor persistently at the victim model fine-tuning runtime through transient faults in model weight memory (via rowhammer). DeepVenom manifests in two main steps: i) an offline step that identifies weight perturbation transferable to the victim model using an ensemble-based local model bit search algorithm, and ii) an online stage that integrates advanced system-level techniques to efficiently massage weight tensors for precise rowhammer-based bit flips. DeepVenom further employs a novel iterative backdoor boosting mechanism that performs multiple rounds of weight perturbations to stabilize the backdoor. We implement an end-to-end DeepVenom attack in real systems with DDR3/DDR4 memories, and evaluate it using state-of-the-art Convolutional Neural Network and Vision Transformer models. The results show that DeepVenom can effectively generate backdoors in victim’s fine-tuned models with upto 99.8% attack success rate (97.8% on average) using as few as 11 total weight bit flips (maximum 49). The evaluation further demonstrates that DeepVenom is successful under varying victim fine-tuning hyperparameter settings, and is highly robust against catastrophic forgetting. Our work highlights the practicality of training-time backdoors through hardware-based weight perturbation, which represents a new dimension in adversarial machine learning.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5a9907e5-9cd2-4d72-97a0-0f8cad50f8deCited by top-tier papers4
- When Mitigations Backfire: Timing Channel Attacks and Defense for PRAC-Based RowHammer MitigationsJeonghyun Woo, Joyce Qu, Gururaj Saileshwar, Prashant Jayaprakash NairISCA 2025 · 6 citations
- Backdoor Attacks on Neural Networks Via One-Bit FlipXiang Li, Lannan Luo, Qiang ZengICCV 2025 · 1 citation
- Phantom: Privacy-Preserving Deep Neural Network Model Obfuscation in Heterogeneous TEE and GPU SystemJuyang Bai, Md Hafizul Islam Chowdhuryy, Jingtao Li, Fan Yao et al.USENIX Security 2025
- Rowhammer-Based Trojan Injection: One Bit Flip Is Sufficient for Backdooring DNNsXiang Li, Ying Meng, Junming Chen, Lannan Luo et al.USENIX Security 2025
Builds on35
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li et al.S&P 2019 · 1,801 citations
- Trojaning Attack on Neural NetworksYingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee et al.NDSS 2018 · 1,377 citations
- Invisible Backdoor Attack with Sample-Specific TriggersYuezun Li, Yiming Li, Baoyuan Wu, Longkang Li et al.ICCV 2021 · 639 citations
- Latent Backdoor Attacks on Deep Neural NetworksYuanshun Yao, Huiying Li, Haitao Zheng, Ben Y. ZhaoCCS 2019 · 465 citations
Related papers
- DeepHammer: Depleting the Intelligence of Deep Neural Networks through Targeted Chain of Bit FlipsFan Yao, Adnan Siraj Rakin, Deliang FanUSENIX Security 2020
- Terminal Brain Damage: Exposing the Graceless Degradation in Deep Neural Networks Under Hardware Fault AttacksSanghyun Hong, Pietro Frigo, Yigitcan Kaya, Cristiano Giuffrida et al.USENIX Security 2019 · 255 citations
- Deep-TROJ: An Inference Stage Trojan Insertion Algorithm Through Efficient Weight Replacement AttackSabbir Ahmed, Ranyang Zhou, Shaahin Angizi, Adnan Siraj RakinCVPR 2024
- One-bit Flip is All You Need: When Bit-flip Attack Meets Model TrainingJianshuo Dong, Han Qiu, Yiming Li, Tianwei Zhang et al.ICCV 2023 · 33 citations
- DNN-Defender: A Victim-Focused In-DRAM Defense Mechanism for Taming Adversarial Weight Attack on DNNsRanyang Zhou, Sabbir Ahmed, Adnan Siraj Rakin, Shaahin AngiziDAC 2024 · 2 citations
