DeepNcode: Encoding-Based Protection against Bit-Flip Attacks on Neural Networks
Velčický, Patrik, Breier, Jakub, Kovačević, Mladen, Hou, Xiaolu
–arXiv.org Artificial Intelligence
Fault injection attacks are a potent threat against embedded implementations of neural network models. Several attack vectors have been proposed, such as misclassification, model extraction, and trojan/backdoor planting. Most of these attacks work by flipping bits in the memory where quantized model parameters are stored. In this paper, we introduce an encoding-based protection method against bit-flip attacks on neural networks, titled DeepNcode. We experimentally evaluate our proposal with several publicly available models and datasets, by using state-of-the-art bit-flip attacks: BFA, T-BFA, and TA-LBF. Our results show an increase in protection margin of up to $7.6\times$ for $4-$bit and $12.4\times$ for $8-$bit quantized networks. Memory overheads start at $50\%$ of the original network size, while the time overheads are negligible. Moreover, DeepNcode does not require retraining and does not change the original accuracy of the model.
arXiv.org Artificial Intelligence
Jun-2-2024
- Country:
- Asia
- Europe
- Austria > Vienna (0.14)
- Germany (0.04)
- Serbia > Vojvodina
- South Bačka District > Novi Sad (0.04)
- Slovakia > Bratislava
- Bratislava (0.04)
- North America
- Canada > Newfoundland and Labrador
- Newfoundland > St. John's (0.04)
- United States > California
- San Diego County > San Diego (0.04)
- San Francisco County > San Francisco (0.14)
- Canada > Newfoundland and Labrador
- Genre:
- Research Report > New Finding (1.00)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology: