Side-Channel-Assisted Reverse-Engineering of Encrypted DNN Hardware Accelerator IP and Attack Surface Exploration
Cheng Gongye, Yukui Luo, Xiaolin Xu, Yunsi Fei
摘要
Deep Neural Networks (DNNs) have revolutionized numerous application domains with their unparalleled performance. As the models become larger and more complex, hardware DNN accelerators are increasingly popular. Field-Programmable Gate Array (FPGA)-based DNN accelerators offer near-Application Specific Integrated Circuit (ASIC) efficiency and exceptional flexibility, establishing them as one of the primary hardware platforms for rapidly evolving deep learning implementations, particularly on edge devices. This prominence renders them lucrative targets for attackers. Existing attacks aimed at compromising the confidentiality of DNN models deployed on FPGA DNN accelerators often assume complete knowledge of the accelerators. However, this assumption does not hold for real-world, proprietary, high-performance FPGA DNN accelerators. In this study, we introduce a comprehensive and effective reverse-engineering methodology for demystifying FPGA DNN accelerator soft Intellectual Property (IP) cores. We demonstrate its application on the cutting-edge AMD-Xilinx Deep Learning Processing Unit (DPU). Our method relies on schematic analysis and, innovatively, electromagnetic (EM) side-channel analysis to reveal the data flow and scheduling of the DNN accelerators. To the best of our knowledge, this research is the first successful endeavor to reverse-engineer a commercial encrypted DNN accelerator IP. Moreover, we investigate attack surfaces exposed by the reverse-engineering findings, including the successful recovery of DNN model architectures and extraction of model parameters. These outcomes pose a significant threat to real-world commercial FPGA-DNN acceleration systems. We discuss potential countermeasures and offer recommendations for FPGA-based IP protection.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper11
- SoK: Neural Network Extraction Through Physical Side ChannelsPéter Horváth, Dirk Lauret, Zhuoran Liu, Lejla BatinaUSENIX Security 2024 · 被引用 11 次
- Graph in the Vault: Protecting Edge GNN Inference with Trusted Execution EnvironmentRuyi Ding, Tianhong Xu, Aidong Adam Ding, Yunsi FeiDAC 2025 · 被引用 4 次
- AmpereBleed: Exploiting On-chip Current Sensors for Circuit-Free Attacks on ARM-FPGA SoCsXin Zhang, Yi Yang, Jiajun Zou, Qingni Shen 等DAC 2025 · 被引用 2 次
- Hoss: Fast Oblivious Semantic Search with Heterogeneous GPU-CPU-TEE ArchitectureJianzhang Du, Weijie Huang, Chenghong Wang, Nicolas Tsagareli 等CCS 2026
- Hardware and Software Platform InferenceCheng Zhang, Hanna Foerster, Robert D. Mullins, Yiren Zhao 等ICML 2025
相关 Paper
- Reverse-Engineering Deep Neural Networks Using Floating-Point Timing Side-ChannelsCheng Gongye, Yunsi Fei, Thomas WahlDAC 2020 · 被引用 39 次
- DeepCache: Revisiting Cache Side-Channel Attacks in Deep Neural Networks ExecutablesZhibo Liu, Yuanyuan Yuan, Yanzuo Chen, Sihang Hu 等CCS 2024 · 被引用 3 次
- DNN Latency Sequencing: Extracting DNN Architectures from Intel SGX Enclaves with Single-Stepping AttacksMinkyung Park, Zelun Kong, DaveTian, Z. Berkay Celik 等NDSS 2026
- DeepStrike: Remotely-Guided Fault Injection Attacks on DNN Accelerator in Cloud-FPGAYukui Luo, Cheng Gongye, Yunsi Fei, Xiaolin XuDAC 2021 · 被引用 42 次
- DnD: A Cross-Architecture Deep Neural Network DecompilerRuoyu Wu, Taegyu Kim, Dave (Jing) Tian, Antonio Bianchi 等USENIX Security 2022
