(An) adversarial side channel attack on neural processing unit기계학습 전용 프로세서에 대한 시간 부채널 공격

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 416
  • Download : 0
Neural Processing Unit (NPU) is a processor to use machine learning efficiently on embedded devices. In comparison to CPU and GPU, research on NPU has drawn less attention among security researchers. Some of the NPUs have adopted a new optimization technique called ”zero-skipping”, which skips all operations with zero-valued operands using a hardware circuit. This technique significantly increases the performance of NPU by decreasing the processing time; however, there have been no studies on investigating the side-effect of such an optimization technique. Can an attacker steal useful information by exploiting the reduced time? To answer this question, we conduct a first study on investigating the feasibility of a side-channel attack on NPUs with the zero-skipping feature. We investigate the relationship between the number of zero-valued operands and the output class in the binary classification model. For this, we conducted a series of experiments on several binary classification models based on neural networks such as CNN and ResNet v1 with MNIST, CIFAR-10, and FVC_2000_DB4_B datasets. As a result, we discovered that the extreme numbers of zero-valued operands, whether they are small or large, are highly biased to a specific output class. From this observation, we propose an adversarial input generation algorithm and demonstrate the feasibility of a timing side-channel attack on NPUs with the zero-skipping feature.
Advisors
Kim, Yongdaeresearcher김용대researcher
Description
한국과학기술원 :정보보호대학원,
Publisher
한국과학기술원
Issue Date
2021
Identifier
325007
Language
eng
Description

학위논문(석사) - 한국과학기술원 : 정보보호대학원, 2021.2,[iv, 26 p. :]

Keywords

Machine Learning▼aSide Channel Attack▼aNeural Processing Unit▼aAdversarial Example▼aHardware Security; 기계학습▼a시간 부채널 공격▼a신경망 처리 장치▼a적대적 예제 생성▼a하드웨어 보안

URI
http://hdl.handle.net/10203/296192
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=957318&flag=dissertation
Appears in Collection
IS-Theses_Master(석사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0