Abstract
Because of their high accuracy, deep neural net-works (DNNs) have achieved amazing success in security-critical systems such as medical devices. It has recently been demon-strated that Adversarial Bit Flip Attacks (BFAs) against DNN hardware by flipping a very small number of bits can result in catastrophic accuracy loss. The reliance on test data, however, is a significant drawback of previous state-of-the-art bit-flip attack methods. This is frequently not possible with applications containing sensitive or proprietary data. In this paper, we propose Blind Data Adversarial Bit-flip Attack (BDFA), a novel technique to enable BFA against DNN hardware without any access to the training or testing data. This is achieved by optimizing for a synthetic dataset, which is engineered to match the statistics of batch normalization across different layers of the network and the targeted label. Experimental results show that BDFA could decrease the accuracy of ResNet50 significantly from 75.96% to 13.94% with only 4 bits flips.
| Original language | English (US) |
|---|---|
| Title of host publication | Proceedings - 2022 25th Euromicro Conference on Digital System Design, DSD 2022 |
| Editors | Himar Fabelo, Samuel Ortega, Amund Skavhaug |
| Publisher | Institute of Electrical and Electronics Engineers Inc. |
| Pages | 899-904 |
| Number of pages | 6 |
| ISBN (Electronic) | 9781665474047 |
| DOIs | |
| State | Published - 2022 |
| Externally published | Yes |
| Event | 25th Euromicro Conference on Digital System Design, DSD 2022 - Maspalomas, Spain Duration: Aug 31 2022 → Sep 2 2022 |
Publication series
| Name | Proceedings - 2022 25th Euromicro Conference on Digital System Design, DSD 2022 |
|---|
Conference
| Conference | 25th Euromicro Conference on Digital System Design, DSD 2022 |
|---|---|
| Country/Territory | Spain |
| City | Maspalomas |
| Period | 8/31/22 → 9/2/22 |
Bibliographical note
Publisher Copyright:© 2022 IEEE.
Fingerprint
Dive into the research topics of 'Blind Data Adversarial Bit-flip Attack against Deep Neural Networks'. Together they form a unique fingerprint.Cite this
- APA
- Standard
- Harvard
- Vancouver
- Author
- BIBTEX
- RIS