Defending Bit-Flip Attack through DNN Weight Reconstruction
Jingtao Li, Adnan Siraj Rakin, Yan Xiong, Liangliang Chang, Zhezhi He, Deliang Fan, Chaitali Chakrabarti
摘要
Recent studies show that adversarial attacks on neural network weights, aka, Bit-Flip Attack (BFA), can degrade Deep Neural Network’s (DNN) prediction accuracy severely. In this work, we propose a novel weight reconstruction method as a countermeasure to such BFAs. Specifically, during inference, the weights are reconstructed such that the weight perturbation due to BFA is minimized or diffused to the neighboring weights. We have successfully demonstrated that our method can significantly improve the DNN robustness against random and gradient-based BFA variants. Even under the most aggressive attacks (i.e., greedy progressive bit search), our method maintains a test accuracy of 60% on ImageNet after 5 iterations while the baseline accuracy drops to below 1%.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper12
- Yes, One-Bit-Flip Matters! Universal DNN Model Inference Depletion with Runtime Code Fault InjectionShaofeng Li, Xinyu Wang, Minhui Xue, Haojin Zhu 等USENIX Security 2024 · 被引用 32 次
- NNSplitter: An Active Defense Solution for DNN Model via Automated Weight ObfuscationTong Zhou, Yukui Luo, Shaolei Ren, Xiaolin XuICML 2023 · 被引用 30 次
- Forget and Rewire: Enhancing the Resilience of Transformer-based Models against Bit-Flip AttacksNajmeh Nazari, Hosein Mohammadi Makrani, Chongzhou Fang, Hossein Sayadi 等USENIX Security 2024 · 被引用 21 次
- Improving Robustness Against Stealthy Weight Bit-Flip Attacks by Output Code MatchingOzan Özdenizci, Robert LegensteinCVPR 2022 · 被引用 11 次
- SAVE: Software-Implemented Fault Tolerance for Model Inference against GPU Memory Bit FlipsWenxin Zheng, Bin Xu, Jinyu Gu, Haibo ChenUSENIX ATC 2025 · 被引用 8 次
相关 Paper
- Defending and Harnessing the Bit-Flip Based Adversarial Weight AttackZhezhi He, Adnan Siraj Rakin, Jingtao Li, Chaitali Chakrabarti 等CVPR 2020
- Bit-Flip Attack: Crushing Neural Network With Progressive Bit SearchAdnan Siraj Rakin, Zhezhi He, Deliang FanICCV 2019 · 被引用 309 次
- One-bit Flip is All You Need: When Bit-flip Attack Meets Model TrainingJianshuo Dong, Han Qiu, Yiming Li, Tianwei Zhang 等ICCV 2023 · 被引用 33 次
- HammerDodger: A Lightweight Defense Framework against RowHammer Attack on DNNsCheng Gongye, Yukui Luo, Xiaolin Xu, Yunsi FeiDAC 2023 · 被引用 5 次
- TBT: Targeted Neural Network Attack With Bit TrojanAdnan Siraj Rakin, Zhezhi He, Deliang FanCVPR 2020
