HDLock: exploiting privileged encoding to protect hyperdimensional computing models against IP stealing
Shijin Duan, Shaolei Ren, Xiaolin Xu
Abstract
Hyperdimensional Computing (HDC) is facing infringement issues due to straightforward computations. This work, for the first time, raises a critical vulnerability of HDC --- an attacker can reverse engineer the entire model, only requiring the unindexed hypervector memory. To mitigate this attack, we propose a defense strategy, namely HDLock, which significantly increases the reasoning cost of encoding. Specifically, HDLock adds extra feature hypervector combination and permutation in the encoding module. Compared to the standard HDC model, a two-layer-key HDLock can increase the adversarial reasoning complexity by 10 order of magnitudes without inference accuracy loss, with only 21% latency overhead.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on2
Related papers
- HyperAttack: An Efficient Attack Framework for HyperDimensional ComputingFangxin Liu, Haomin Li, Yongbiao Chen, Tao Yang et al.DAC 2023 · 15 citations
- PRID: Model Inversion Privacy Attacks in Hyperdimensional Learning SystemsAlejandro Hernández-Cano, Rosario Cammarota, Mohsen ImaniDAC 2021 · 30 citations
- StocHD: Stochastic Hyperdimensional System for Efficient and Robust Learning from Raw DataPrathyush Poduval, Zhuowen Zou, M. Hassan Najafi, Houman Homayoun et al.DAC 2021 · 34 citations
- Adaptive neural recovery for highly robust brain-like representationPrathyush Poduval, Yang Ni, Yeseong Kim, Kai Ni et al.DAC 2022 · 8 citations
- VAE-HDC: Efficient and Secure Hyper-dimensional Encoder Leveraging Variation Analog EntropyBoyang Cheng, Jianbo Liu, Steven Davis, Zephan M. Enciso et al.DAC 2024 · 1 citation
