Skip to main navigation Skip to search Skip to main content

Blind Data Adversarial Bit-flip Attack against Deep Neural Networks

  • Behnam Ghavami
  • , Mani Sadati
  • , Mohammad Shahidzadeh
  • , Zhenman Fang
  • , Lesley Shannon

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Because of their high accuracy, deep neural net-works (DNNs) have achieved amazing success in security-critical systems such as medical devices. It has recently been demon-strated that Adversarial Bit Flip Attacks (BFAs) against DNN hardware by flipping a very small number of bits can result in catastrophic accuracy loss. The reliance on test data, however, is a significant drawback of previous state-of-the-art bit-flip attack methods. This is frequently not possible with applications containing sensitive or proprietary data. In this paper, we propose Blind Data Adversarial Bit-flip Attack (BDFA), a novel technique to enable BFA against DNN hardware without any access to the training or testing data. This is achieved by optimizing for a synthetic dataset, which is engineered to match the statistics of batch normalization across different layers of the network and the targeted label. Experimental results show that BDFA could decrease the accuracy of ResNet50 significantly from 75.96% to 13.94% with only 4 bits flips.

Original languageEnglish (US)
Title of host publicationProceedings - 2022 25th Euromicro Conference on Digital System Design, DSD 2022
EditorsHimar Fabelo, Samuel Ortega, Amund Skavhaug
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages899-904
Number of pages6
ISBN (Electronic)9781665474047
DOIs
StatePublished - 2022
Externally publishedYes
Event25th Euromicro Conference on Digital System Design, DSD 2022 - Maspalomas, Spain
Duration: Aug 31 2022Sep 2 2022

Publication series

NameProceedings - 2022 25th Euromicro Conference on Digital System Design, DSD 2022

Conference

Conference25th Euromicro Conference on Digital System Design, DSD 2022
Country/TerritorySpain
CityMaspalomas
Period8/31/229/2/22

Bibliographical note

Publisher Copyright:
© 2022 IEEE.

Fingerprint

Dive into the research topics of 'Blind Data Adversarial Bit-flip Attack against Deep Neural Networks'. Together they form a unique fingerprint.

Cite this