NeuroPots: Realtime Proactive Defense against Bit-Flip Attacks in Neural Networks
Qi Liu, Jieming Yin, Wujie Wen, Chengmo Yang, Shi Sha
摘要
Deep neural networks (DNNs) are becoming ubiquitous in various safety-and security-sensitive applications such as selfdriving cars and financial systems. Recent studies revealed that bit-flip attacks (BFAs) can destroy DNNs' functionality via DRAM rowhammer -by precisely injecting a few bit-flips into the quantized model parameters, attackers can either degrade the model accuracy to random guessing, or misclassify certain inputs into a target class. BFAs can cause catastrophic consequences if left undetected. However, detecting BFAs is challenging because bit-flips can occur on any weights in a DNN model, leading to a large detection surface. Unlike prior works that attempt to "patch" vulnerabilities of DNN models, our work is inspired by the idea of "honeypot". Specifically, we propose a proactive defense concept named NeuroPots, which embeds a few "honey neurons" as crafted vulnerabilities into the DNN model to lure the attacker into injecting faults in them, thus making detection and model recovery efficient. We utilize NeuroPots to develop a trapdoor-enabled defense framework. We design a honey neuron selection strategy, and propose two methods for embedding trapdoors into the DNN model. Furthermore, since the majority of injected bit flips will concentrate in the trapdoors, we use a checksum-based detection approach to efficiently detect faults in them, and rescue the model accuracy by "refreshing" those faulty trapdoors. Our experiments show that trapdoor-enabled defense achieves high detection performance and effectively recovers a compromised model at a low cost across a variety of DNN models and datasets.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Forget and Rewire: Enhancing the Resilience of Transformer-based Models against Bit-Flip AttacksNajmeh Nazari, Hosein Mohammadi Makrani, Chongzhou Fang, Hossein Sayadi 等USENIX Security 2024 · 被引用 21 次
- Siloz: Leveraging DRAM Isolation Domains to Prevent Inter-VM RowhammerKevin Loughlin, Jonah Rosenblum, Stefan Saroiu, Alec Wolman 等SOSP 2023 · 被引用 13 次
- Securing Graph Neural Networks in MLaaS: A Comprehensive Realization of Query-based Integrity VerificationBang Wu, Xingliang Yuan, Shuo Wang, Qi Li 等S&P 2024 · 被引用 13 次
- GPUBreach: Privilege Escalation Attacks on GPUs Using RowhammerChris S. Lin, Yuqin Yan, Guozhen Ding, Joyce Qu 等S&P 2026 · 被引用 8 次
- Attacking Graph Neural Networks with Bit Flips: Weisfeiler and Leman Go IndifferentLorenz Kummer, Samir Moustafa, Sebastian Schrittwieser, Wilfried N. Gansterer 等KDD 2024 · 被引用 1 次
它引用的顶会 Paper15
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu 等S&P 2018 · 被引用 867 次
- Bit-Flip Attack: Crushing Neural Network With Progressive Bit SearchAdnan Siraj Rakin, Zhezhi He, Deliang FanICCV 2019 · 被引用 309 次
- Another Flip in the Wall of Rowhammer DefensesDaniel Gruss, Moritz Lipp, Michael Schwarz, Daniel Genkin 等S&P 2018 · 被引用 288 次
- Terminal Brain Damage: Exposing the Graceless Degradation in Deep Neural Networks Under Hardware Fault AttacksSanghyun Hong, Pietro Frigo, Yigitcan Kaya, Cristiano Giuffrida 等USENIX Security 2019 · 被引用 255 次
- ProFlip: Targeted Trojan Attack with Progressive Bit FlipsHuili Chen, Cheng Fu, Jishen Zhao, Farinaz KoushanfarICCV 2021 · 被引用 95 次
相关 Paper
- Gotta Catch'Em All: Using Honeypots to Catch Adversarial Attacks on Neural NetworksShawn Shan, Emily Wenger, Bolun Wang, Bo Li 等CCS 2020 · 被引用 67 次
- HammerDodger: A Lightweight Defense Framework against RowHammer Attack on DNNsCheng Gongye, Yukui Luo, Xiaolin Xu, Yunsi FeiDAC 2023 · 被引用 5 次
- TBT: Targeted Neural Network Attack With Bit TrojanAdnan Siraj Rakin, Zhezhi He, Deliang FanCVPR 2020
- One-bit Flip is All You Need: When Bit-flip Attack Meets Model TrainingJianshuo Dong, Han Qiu, Yiming Li, Tianwei Zhang 等ICCV 2023 · 被引用 33 次
- DeepHammer: Depleting the Intelligence of Deep Neural Networks through Targeted Chain of Bit FlipsFan Yao, Adnan Siraj Rakin, Deliang FanUSENIX Security 2020
