paper-with-me

홈 › Papers

Bit-Flip Fault Attack: Crushing Graph Neural Networks via Gradual Bit Search

2025-07-07 · Sanaz Kazemi Abharian, Sai Manoj Pudukotai Dinakarrao arxiv

Graph Neural Networks (GNNs) have emerged as a powerful machine learning method for graph-structured data. A plethora of hardware accelerators has been introduced to meet the performance demands of GNNs in real-world applications. However, security challenges of hardware-based attacks have been generally overlooked. In this paper, we investigate the vulnerability of GNN models to hardware-based fault attack, wherein an attacker attempts to misclassify output by modifying trained weight parameters through fault injection in a memory device. Thus, we propose Gradual Bit-Flip Fault Attack (GBFA), a layer-aware bit-flip fault attack, selecting a vulnerable bit in each selected weight gradually to compromise the GNN's performance by flipping a minimal number of bits. To achieve this, GBFA operates in two steps. First, a Markov model is created to predict the execution sequence of layers based on features extracted from memory access patterns, enabling the launch of the attack within a specific layer. Subsequently, GBFA identifies vulnerable bits within the selected weights using gradient ranking through an in-layer search. We evaluate the effectiveness of the proposed GBFA attack on various GNN models for node classification tasks using the Cora and PubMed datasets. Our findings show that GBFA significantly degrades prediction accuracy, and the variation in its impact across different layers highlights the importance of adopting a layer-aware attack strategy in GNNs. For example, GBFA degrades GraphSAGE's prediction accuracy by 17% on the Cora dataset with only a single bit flip in the last layer.

📄 PDF Abstract BibTeX arXiv:2507.05531

Code (0)

등록된 구현이 없습니다.

Tasks

Node Classification

Similar Papers 제목 키워드 기반

Bit-Flip Attack: Crushing Neural Network with Progressive Bit Search

2019-03-28 · ICCV 2019 10 · Adnan Siraj Rakin, Zhezhi He, Deliang Fan

Several important security issues of Deep Neural Network (DNN) have been raised recently associated with different applications and components. The most widely investigated security concern of DNN is from its malicious i…

Attacking Graph Neural Networks with Bit Flips: Weisfeiler and Lehman Go Indifferent

2023-11-02 · Lorenz Kummer, Samir Moustafa, Nils N. Kriege, Wilfried N. Gansterer

Prior attacks on graph neural networks have mostly focused on graph poisoning and evasion, neglecting the network's weights and biases. Traditional weight-based fault injection attacks, such as bit flip attacks used for …

Graph Neural NetworkGraph Property PredictionProperty Prediction

HASHTAG: Hash Signatures for Online Detection of Fault-Injection Attacks on Deep Neural Networks

2021-11-02 · Mojan Javaheripi, Farinaz Koushanfar

We propose HASHTAG, the first framework that enables high-accuracy detection of fault-injection attacks on Deep Neural Networks (DNNs) with provable bounds on detection performance. Recent literature in fault-injection a…

Fault Detection

Bit-Flip Attacks on Vision-Language-Action Models: Action-Decoding Architecture Shapes the Vulnerability

2026-08-16 · Yudong Gao, Linghan Chen, Wenhan Wu, Mia Zhou 외 arxiv

Quantized Vision-Language-Action (VLA) models expose a weight-fault surface: Rowhammer-style faults can corrupt deployed INT8 bits. We present the first bit-flip attack on a VLA: a few gradient-selected flips reduce clos…

Targeted Bit-Flip Attacks on LLM-Based Agents

2026-03-07 · Jialai Wang, Ya Wen, Zhongmou Liu, Yuxiao Wu 외 arxiv

Targeted bit-flip attacks (BFAs) exploit hardware faults to manipulate model parameters, posing a significant security threat. While prior work targets single-step inference models (e.g., image classifiers), LLM-based ag…