paper-with-me

Papers

Open DNN Box by Power Side-Channel Attack

2019-07-21 · Yun Xiang, Zhuangzhi Chen, Zuohui Chen, Zebin Fang, Haiyang Hao, Jinyin Chen, Yi Liu, Zhefu Wu, Qi Xuan, Xiaoniu Yang

Deep neural networks are becoming popular and important assets of many AI companies. However, recent studies indicate that they are also vulnerable to adversarial attacks. Adversarial attacks can be either white-box or black-box. The white-box attacks assume full knowledge of the models while the black-box ones assume none. In general, revealing more internal information can enable much more powerful and efficient attacks. However, in most real-world applications, the internal information of embedded AI devices is unavailable, i.e., they are black-box. Therefore, in this work, we propose a side-channel information based technique to reveal the internal information of black-box models. Specifically, we have made the following contributions: (1) we are the first to use side-channel information to reveal internal network architecture in embedded devices; (2) we are the first to construct models for internal parameter estimation; and (3) we validate our methods on real-world devices and applications. The experimental results show that our method can achieve 96.50\% accuracy on average. Such results suggest that we should pay strong attention to the security problem of many AI applications, and further propose corresponding defensive strategies in the future.

📄 PDF Abstract BibTeX arXiv:1907.10406

Code (0)

등록된 구현이 없습니다.

Tasks

parameter estimation

Similar Papers 제목 키워드 기반

Power side-channel leakage localization through adversarial training of deep neural networks

2024-10-29 · Jimmy Gammell, Anand Raghunathan, Kaushik Roy

Supervised deep learning has emerged as an effective tool for carrying out power side-channel attacks on cryptographic implementations. While increasingly-powerful deep learning-based attacks are regularly published, com…

Deep LearningModel Selection

What Was Your Prompt? A Remote Keylogging Attack on AI Assistants

2024-03-14 · Roy Weiss, Daniel Ayzenshteyn, Guy Amit, Yisroel Mirsky

AI assistants are becoming an integral part of society, used for asking advice or help in personal and confidential issues. In this paper, we unveil a novel side-channel that can be used to read encrypted responses from …

Language ModelingLanguage ModellingLarge Language ModelSentence+1

Adversarial Attacks with Multiple Antennas Against Deep Learning-Based Modulation Classifiers

2020-07-31 · Brian Kim, Yalin E. Sagduyu, Tugba Erpek, Kemal Davaslioglu 외

We consider a wireless communication system, where a transmitter sends signals to a receiver with different modulation types while the receiver classifies the modulation types of the received signals using its deep learn…

Diversity

SCNet: A Neural Network for Automated Side-Channel Attack

2020-08-02 · Guanlin Li, Chang Liu, Han Yu, Yanhong Fan 외

The side-channel attack is an attack method based on the information gained about implementations of computer systems, rather than weaknesses in algorithms. Information about system characteristics such as power consumpt…

Leaky Nets: Recovering Embedded Neural Network Models and Inputs through Simple Power and Timing Side-Channels -- Attacks and Defenses

2021-03-26 · Saurav Maji, Utsav Banerjee, Anantha P. Chandrakasan

With the recent advancements in machine learning theory, many commercial embedded micro-processors use neural network models for a variety of signal processing applications. However, their associated side-channel securit…

Learning Theory