TNPU: Supporting Trusted Execution with Tree-less Integrity Protection for Neural Processing Unit
Sunho Lee, Jungwoo Kim, Seonjin Na, Jongse Park, Jaehyuk Huh
摘要
As neural processing units (NPUs) for machine learning inference have been incorporated into a wide range of system-on-a-chips, NPUs are processing more and more mission-critical computations such as autonomous driving. With the increasing application scenarios, securing NPU operations from potential attacks has become crucial for the safety of the entire system. To address the security challenges of NPU operations, this study investigates how the trusted execution technology can be extended to harden the NPU execution by hardware supports. This paper proposes trusted NPU (TNPU) which supports trusted execution for NPUs integrated in a processor. For securing NPUs, a key performance challenge is in the encryption and integrity protection for external memory. This work proposes a novel tree-less integrity protection by exploiting the data flow semantics of DNN computation. The tree-less integrity protection maintains a version number for each tensor or sub-tensor inside the CPU enclave which drives the NPU computation. By exploiting the data flow of tensor updates, a per-tensor version number can efficiently verify the recency of the data in the tensor. The tree-less integrity protection eliminates performance losses by counter and hash cache misses, which are major performance overheads of hardware-based memory protection. Our evaluation with simulated NPUs shows that the performance overheads for trusted NPUs can be significantly reduced from the prior tree-based design, improving the performance of a single NPU by 10.0% and 7.5% on average over the prior one with two different NPU configurations. When the number of NPUs is increased to three, the performance gains further improve, achieving on average 13.3% and 8.7% improvements.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper18
- GuardNN: secure accelerator architecture for privacy-preserving deep learningWeizhe Hua, Muhammad Umar, Zhiru Zhang, G. Edward SuhDAC 2022 · 被引用 28 次
- MGX: near-zero overhead memory protection for data-intensive acceleratorsWeizhe Hua, Muhammad Umar, Zhiru Zhang, G. Edward SuhISCA 2022 · 被引用 27 次
- Securator: A Fast and Secure Neural Processing UnitNivedita Shrivastava, Smruti Ranjan SarangiHPCA 2023 · 被引用 16 次
- sNPU: Trusted Execution Environments on Integrated NPUsErhu Feng, Dahu Feng, Dong Du, Yubin Xia 等ISCA 2024 · 被引用 13 次
- Plutus: Bandwidth-Efficient Memory Security for GPUsRahaf Abdullah, Huiyang Zhou, Amro AwadHPCA 2023 · 被引用 13 次
相关 Paper
- Common Counters: Compressed Encryption Counters for Secure GPU MemorySeonjin Na, Sunho Lee, Yeonjae Kim, Jongse Park 等HPCA 2021 · 被引用 34 次
- SoftVN: efficient memory protection via software-provided version numbersMuhammad Umar, Weizhe Hua, Zhiru Zhang, G. Edward SuhISCA 2022 · 被引用 12 次
- SAGE: Software-based Attestation for GPU ExecutionAndrei Ivanov, Benjamin Rothenberger, Arnaud Dethise, Marco Canini 等USENIX ATC 2023 · 被引用 1 次
- Guardain: Protecting Emerging Generative AI Workloads on Heterogeneous NPUAritra Dhar, Clément Thorens, Lara Magdalena Lazier, Lukas CavigelliS&P 2025
- ASGARD: Protecting On-Device Deep Neural Networks with Virtualization-Based Trusted Execution EnvironmentsMyungsuk Moon, Minhee Kim, Joonkyo Jung, Dokyung SongNDSS 2025
