HyperTheft: Thieving Model Weights from TEE-Shielded Neural Networks via Ciphertext Side Channels
Yuanyuan Yuan, Zhibo Liu, Sen Deng, Yanzuo Chen, Shuai Wang, Yinqian Zhang, Zhendong Su
摘要
Trusted execution environments (TEEs) are widely employed to protect deep neural networks (DNNs) from untrusted hosts (e.g., hypervisors). By shielding DNNs as fully black-box via encryption, TEEs mitigate model weight leakage and its follow-up white-box attacks. However, this paper uncovers that the confidentiality of TEEshielded DNNs can be violated due to an emerging threat towards TEEs: ciphertext side channels of TEEs create weight-dependent observations during a DNN's execution. Despite the potential of inferring DNN weights from ciphertext side channels, existing techniques are inapplicable due to their over-strong requirements and the high precision required by DNN weights. A DNN can have millions of weight elements, and even a few incorrectly recovered weight elements may make the DNN non-functional. We propose a novel viewpoint that focuses on the functionality of DNN weights, rather than each weight element's exact value. Accordingly, we design HyperTheft to directly generate weights that are functionality-equivalent to the victim DNN using ciphertext side channels. HyperTheft is established for highly practical settings; it exhibits the weakest requirement compared to prior methods. When only knowing a victim DNN's input type and task type (which are public and denote the minimal information required to use a DNN), HyperTheft can recover its weight using ciphertext side channels logged during the victim DNN's one execution. The whole procedure does not require attackers to 1) query the
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper16
- TEE.Fail: Breaking Trusted Execution Environments via DDR5 Memory Bus InterpositionJalen Chuang, Alexander Seto, Nicolás Berrios, Stephan van Schaik 等S&P 2026 · 被引用 29 次
- Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory AliasingJesse De Meulemeester, David F. Oswald, Ingrid Verbauwhede, Jo Van BulckS&P 2026 · 被引用 20 次
- SNPeek: Side-Channel Analysis for Privacy Applications on Confidential VMsRuiyi Zhang, Albert Cheu, Adrià Gascón, Daniel Moghimi 等NDSS 2026 · 被引用 7 次
- TensorShield: Safeguarding On-Device Inference by Shielding Critical DNN Tensors with TEETong Sun, Bowen Jiang, Hailong Lin, Borui Li 等CCS 2025 · 被引用 3 次
- BreakFAST: Confused Deputy Attack on Infinity Fabric to Break AMD SEV-SNPPhilipp Giersfeld, Benedict Schlüter, Shweta ShindeS&P 2026 · 被引用 1 次
它引用的顶会 Paper29
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter 等USENIX Security 2016 · 被引用 2,088 次
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song 等S&P 2022 · 被引用 1,049 次
相关 Paper
- CipherSteal: Stealing Input Data from TEE-Shielded Neural Networks with Ciphertext Side ChannelsYuanyuan Yuan, Zhibo Liu, Sen Deng, Yanzuo Chen 等S&P 2025
- Mitigating Ciphertext Side-Channel Attacks against TEE-Shielded Neural NetworksQianhui Dai, Zhen Huang, Guoxing Chen, Yan Meng 等CCS 2026
- DNN Latency Sequencing: Extracting DNN Architectures from Intel SGX Enclaves with Single-Stepping AttacksMinkyung Park, Zelun Kong, DaveTian, Z. Berkay Celik 等NDSS 2026
- GroupCover: A Secure, Efficient and Scalable Inference Framework for On-device Model Protection based on TEEsZheng Zhang, Na Wang, Ziqi Zhang, Yao Zhang 等ICML 2024 · 被引用 13 次
- Cache Telepathy: Leveraging Shared Resource Attacks to Learn DNN ArchitecturesMengjia Yan, Christopher W. Fletcher, Josep TorrellasUSENIX Security 2020
