USENIX Security2024Top-tier venue
Tossing in the Dark: Practical Bit-Flipping on Gray-box Deep Neural Networks for Runtime Trojan Injection
Zihao Wang, Di Tang, XiaoFeng Wang, Wei He, Zhaoyang Geng, Wenhao Wang
Abstract
Although Trojan attacks on deep neural networks (DNNs) have been extensively studied, the threat of run-time Trojan injection has only recently been brought to attention. Unlike data poisoning attacks that target the training stage of a DNN model, a run-time attack executes an exploit such as Rowhammer on memory to flip the bits of the target model and thereby implant a Trojan. This threat is stealthier but more challenging, as it requires flipping a set of bits in the target model to introduce an effective Trojan without noticeably downgrading the model's accuracy. This has been achieved only under the less realistic assumption that the target model is fully shared with the adversary through memory, thus enabling them to flip bits across all model layers, including the last few layers. For the first time, we have investigated run-time Trojan Injection under a more realistic gray-box scenario. In this scenario, a model is perceived in an encoder-decoder manner: the encoder is public and shared through memory, while the decoder is private and so considered to be black-box and inaccessible to unauthorized parties. To address the unique challenge posed by the black-box decoder to Trojan injection in this scenario, we developed a suite of innovative techniques. Using these techniques, we constructed our gray-box attack, Groan, which stands out as both effective and stealthy. Our experiments show that Groan is capable of injecting a highly effective Trojan into the target model, while also largely preserving its performance, even in the presence of state-of-theart memory protection.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e2ba9396-2df2-4bba-aa1f-323817ae173dCited by top-tier papers5
- SoK: Systematizing a Decade of Architectural Rowhammer Defenses Through the Lens of Streaming AlgorithmsMichael Jaemin Kim, Seungmin Baek, Jumin Kim, Hwayong Nam et al.S&P 2026 · 6 citations
- PVAC: A Rowhammer Mitigation Architecture Exploiting Per-Victim-Row CountingJumin Kim, Seungmin Baek, Hwayong Nam, Minbok Wi et al.ISCA 2026 · 5 citations
- SilentStriker: Toward Stealthy Bit-Flip Attacks on Large Language ModelsHaotian Xu, Qingsong Peng, Jie Shi, Huadi Zheng et al.NeurIPS 2025 · 4 citations
- Rounding-Guided Backdoor Injection in Deep Learning Model QuantizationXiangxiang Chen, Peixin Zhang, Jun Sun, Wenhai Wang et al.NDSS 2026 · 4 citations
- Has the Two-Decade-Old Prophecy Come True? Artificial Bad Intelligence Triggered by Merely a Single-Bit Flip in Large Language ModelsYu Yan, Siqi Lu, Yang Gao, Zhaoxuan Li et al.WWW 2026 · 1 citation
Builds on37
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu et al.ICCV 2021 · 31,683 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- An Empirical Study of Training Self-Supervised Vision TransformersXinlei Chen, Saining Xie, Kaiming HeICCV 2021 · 2,340 citations
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li et al.S&P 2019 · 1,801 citations
Related papers
- DeepVenom: Persistent DNN Backdoors Exploiting Transient Weight Perturbations in MemoriesKunbei Cai, Md Hafizul Islam Chowdhuryy, Zhenkai Zhang, Fan YaoS&P 2024 · 14 citations
- DeepHammer: Depleting the Intelligence of Deep Neural Networks through Targeted Chain of Bit FlipsFan Yao, Adnan Siraj Rakin, Deliang FanUSENIX Security 2020
- TBT: Targeted Neural Network Attack With Bit TrojanAdnan Siraj Rakin, Zhezhi He, Deliang FanCVPR 2020
- ProFlip: Targeted Trojan Attack with Progressive Bit FlipsHuili Chen, Cheng Fu, Jishen Zhao, Farinaz KoushanfarICCV 2021 · 95 citations
- Terminal Brain Damage: Exposing the Graceless Degradation in Deep Neural Networks Under Hardware Fault AttacksSanghyun Hong, Pietro Frigo, Yigitcan Kaya, Cristiano Giuffrida et al.USENIX Security 2019 · 255 citations
