paper-with-me

홈 › Papers

EMShepherd: Detecting Adversarial Samples via Side-channel Leakage

2023-03-27 · Ruyi Ding, Cheng Gongye, Siyue Wang, Aidong Ding, Yunsi Fei

Deep Neural Networks (DNN) are vulnerable to adversarial perturbations-small changes crafted deliberately on the input to mislead the model for wrong predictions. Adversarial attacks have disastrous consequences for deep learning-empowered critical applications. Existing defense and detection techniques both require extensive knowledge of the model, testing inputs, and even execution details. They are not viable for general deep learning implementations where the model internal is unknown, a common 'black-box' scenario for model users. Inspired by the fact that electromagnetic (EM) emanations of a model inference are dependent on both operations and data and may contain footprints of different input classes, we propose a framework, EMShepherd, to capture EM traces of model execution, perform processing on traces and exploit them for adversarial detection. Only benign samples and their EM traces are used to train the adversarial detector: a set of EM classifiers and class-specific unsupervised anomaly detectors. When the victim model system is under attack by an adversarial example, the model execution will be different from executions for the known classes, and the EM trace will be different. We demonstrate that our air-gapped EMShepherd can effectively detect different adversarial attacks on a commonly used FPGA deep learning accelerator for both Fashion MNIST and CIFAR-10 datasets. It achieves a 100% detection rate on most types of adversarial samples, which is comparable to the state-of-the-art 'white-box' software-based detectors.

📄 PDF Abstract BibTeX arXiv:2303.15571

Code (0)

등록된 구현이 없습니다.

Tasks

Deep Learning

Similar Papers 제목 키워드 기반

Adversarial Sample Detection via Channel Pruning

2021-06-18 · ICML Workshop AML 2021 7 · Zuohui Chen, Renxuan Wang, Yao Lu, Jingyang Xiang 외

Adversarial attacks are the main security issue of deep neural networks. Detecting adversarial samples is an effective mechanism for defending adversarial attacks. Previous works on detecting adversarial samples show su…

Detecting Adversarial Samples Using Density Ratio Estimates

2017-05-05 · Lovedeep Gondara

Machine learning models, especially based on deep architectures are used in everyday applications ranging from self driving cars to medical diagnostics. It has been shown that such models are dangerously susceptible to a…

Density Ratio EstimationSelf-Driving Cars

Defending Against Adversarial Attacks by Leveraging an Entire GAN

2018-05-27 · Gokula Krishnan Santhanam, Paulina Grnarova

Recent work has shown that state-of-the-art models are highly vulnerable to adversarial perturbations of the input. We propose cowboy, an approach to detecting and defending against adversarial attacks by using both the …

Evasion of IoT Malware Detection via Dummy Code Injection

2026-02-09 · Sahar Zargarzadeh, Mohammad Islam arxiv

The Internet of Things (IoT) has revolutionized connectivity by linking billions of devices worldwide. However, this rapid expansion has also introduced severe security vulnerabilities, making IoT devices attractive targ…

Intrusion DetectionAnomaly DetectionMalware Detection

Probabilistic Modeling of Deep Features for Out-of-Distribution and Adversarial Detection

2019-09-25 · Nilesh A. Ahuja, Ibrahima Ndiour, Trushant Kalyanpur, Omesh Tickoo

We present a principled approach for detecting out-of-distribution (OOD) and adversarial samples in deep neural networks. Our approach consists in modeling the outputs of the various layers (deep features) with parametri…

Adversarial Attack