SEALing Neural Network Models in Encrypted Deep Learning Accelerators
Pengfei Zuo, Yu Hua, Ling Liang, Xinfeng Xie, Xing Hu, Yuan Xie
摘要
Deep learning (DL) accelerators suffer from a new security problem, i.e., being vulnerable to physical access based attacks. An adversary can easily obtain the entire neural network (NN) model by physically snooping the memory bus that connects the accelerator chip with DRAM memory. Therefore, memory encryption becomes important for DL accelerators to improve their security. Nevertheless, we observe that traditional memory encryption techniques that have been efficiently used in CPU systems cause significant performance degradation when directly used in DL accelerators, due to the big bandwidth gap between the memory bus and the encryption engine. To address this problem, our paper proposes SEAL, a Secure and Efficient Accelerator scheme for deep Learning to enhance the performance of encrypted DL accelerators by improving the data access bandwidth. Specifically, SEAL leverages a criticality-aware smart encryption scheme that identifies partial data having no impact on the security of NN models and allows them to bypass the encryption engine, thus reducing the amount of data to be encrypted without affecting security. Extensive experimental results demonstrate that, compared with existing memory encryption techniques, SEAL achieves 1.34 – 1.4× overall performance improvement.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Securator: A Fast and Secure Neural Processing UnitNivedita Shrivastava, Smruti Ranjan SarangiHPCA 2023 · 被引用 16 次
- TensorTEE: Unifying Heterogeneous TEE Granularity for Efficient Secure Collaborative Tensor ComputingHusheng Han, Xinyao Zheng, Yuanbo Wen, Yifan Hao 等ASPLOS 2024 · 被引用 12 次
- HuffDuff: Stealing Pruned DNNs from Sparse AcceleratorsDingqing Yang, Prashant J. Nair, Mieszko LisASPLOS 2023 · 被引用 10 次
- Older and Wiser: The Marriage of Device Aging and Intellectual Property Protection of DNNsNing Lin, Shaocong Wang, Yue Zhang, Yangu He 等DAC 2024 · 被引用 3 次
- SeDA: Secure and Efficient DNN Accelerators with Hardware/Software SynergyWei Xuan, Zhongrui Wang, Lang Feng, Ning Lin 等DAC 2025 · 被引用 3 次
它引用的顶会 Paper2
相关 Paper
- SRA: a secure ReRAM-based DNN acceleratorLei Zhao, Youtao Zhang, Jun YangDAC 2022 · 被引用 6 次
- GuardNN: secure accelerator architecture for privacy-preserving deep learningWeizhe Hua, Muhammad Umar, Zhiru Zhang, G. Edward SuhDAC 2022 · 被引用 28 次
- MGX: near-zero overhead memory protection for data-intensive acceleratorsWeizhe Hua, Muhammad Umar, Zhiru Zhang, G. Edward SuhISCA 2022 · 被引用 27 次
- SecureLoop: Design Space Exploration of Secure DNN AcceleratorsKyungmi Lee, Mengjia Yan, Joel S. Emer, Anantha P. ChandrakasanMICRO 2023 · 被引用 4 次
- Cheetah: Optimizing and Accelerating Homomorphic Encryption for Private InferenceBrandon Reagen, Wooseok Choi, Yeongil Ko, Vincent T. Lee 等HPCA 2021 · 被引用 147 次
