HDLock: exploiting privileged encoding to protect hyperdimensional computing models against IP stealing
Shijin Duan, Shaolei Ren, Xiaolin Xu
摘要
Hyperdimensional Computing (HDC) is facing infringement issues due to straightforward computations. This work, for the first time, raises a critical vulnerability of HDC --- an attacker can reverse engineer the entire model, only requiring the unindexed hypervector memory. To mitigate this attack, we propose a defense strategy, namely HDLock, which significantly increases the reasoning cost of encoding. Specifically, HDLock adds extra feature hypervector combination and permutation in the encoding module. Compared to the standard HDC model, a two-layer-key HDLock can increase the adversarial reasoning complexity by 10 order of magnitudes without inference accuracy loss, with only 21% latency overhead.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper2
相关 Paper
- HyperAttack: An Efficient Attack Framework for HyperDimensional ComputingFangxin Liu, Haomin Li, Yongbiao Chen, Tao Yang 等DAC 2023 · 被引用 15 次
- PRID: Model Inversion Privacy Attacks in Hyperdimensional Learning SystemsAlejandro Hernández-Cano, Rosario Cammarota, Mohsen ImaniDAC 2021 · 被引用 30 次
- StocHD: Stochastic Hyperdimensional System for Efficient and Robust Learning from Raw DataPrathyush Poduval, Zhuowen Zou, M. Hassan Najafi, Houman Homayoun 等DAC 2021 · 被引用 34 次
- Adaptive neural recovery for highly robust brain-like representationPrathyush Poduval, Yang Ni, Yeseong Kim, Kai Ni 等DAC 2022 · 被引用 8 次
- VAE-HDC: Efficient and Secure Hyper-dimensional Encoder Leveraging Variation Analog EntropyBoyang Cheng, Jianbo Liu, Steven Davis, Zephan M. Enciso 等DAC 2024 · 被引用 1 次
