Fault-Aware Adversary Attack Analyses and Enhancement for RRAM-Based Neuromorphic Accelerator

Liuting Shang, Sungyong Jung, Fengjun Li, C. Pan
{"title":"Fault-Aware Adversary Attack Analyses and Enhancement for RRAM-Based Neuromorphic Accelerator","authors":"Liuting Shang, Sungyong Jung, Fengjun Li, C. Pan","doi":"10.3389/fsens.2022.896299","DOIUrl":null,"url":null,"abstract":"Neural networks have been widely deployed in sensor networks and IoT systems due to the advance in lightweight design and edge computing as well as emerging energy-efficient neuromorphic accelerators. However, adversary attack has raised a major threat against neural networks, which can be further enhanced by leveraging the natural hard faults in the neuromorphic accelerator that is based on resistive random access memory (RRAM). In this paper, we perform a comprehensive fault-aware attack analysis method for RRAM-based accelerators by considering five attack models based on a wide range of device- and circuit-level nonideal properties. The research on nonideal properties takes into account detailed hardware situations and provides a more accurate perspective on security. Compared to the existing adversary attack strategy that only leverages the natural fault, we propose an initiative attack based on two soft fault injection methods, which do not require a high-precision laboratory environment. In addition, an optimized fault-aware adversary algorithm is also proposed to enhance the attack effectiveness. The simulation results of an MNIST dataset on a classic convolutional neural network have shown that the proposed fault-aware adversary attack models and algorithms achieve a significant improvement in the attacking image classification.","PeriodicalId":93754,"journal":{"name":"Frontiers in sensors","volume":" ","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2022-05-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Frontiers in sensors","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.3389/fsens.2022.896299","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Neural networks have been widely deployed in sensor networks and IoT systems due to the advance in lightweight design and edge computing as well as emerging energy-efficient neuromorphic accelerators. However, adversary attack has raised a major threat against neural networks, which can be further enhanced by leveraging the natural hard faults in the neuromorphic accelerator that is based on resistive random access memory (RRAM). In this paper, we perform a comprehensive fault-aware attack analysis method for RRAM-based accelerators by considering five attack models based on a wide range of device- and circuit-level nonideal properties. The research on nonideal properties takes into account detailed hardware situations and provides a more accurate perspective on security. Compared to the existing adversary attack strategy that only leverages the natural fault, we propose an initiative attack based on two soft fault injection methods, which do not require a high-precision laboratory environment. In addition, an optimized fault-aware adversary algorithm is also proposed to enhance the attack effectiveness. The simulation results of an MNIST dataset on a classic convolutional neural network have shown that the proposed fault-aware adversary attack models and algorithms achieve a significant improvement in the attacking image classification.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于rram的神经形态加速器的故障感知攻击分析与改进
由于轻量级设计和边缘计算以及新兴的高能效神经形态加速器的进步,神经网络已被广泛部署在传感器网络和物联网系统中。然而,对手攻击对神经网络构成了重大威胁,可以通过利用基于电阻随机存取存储器(RRAM)的神经形态加速器中的自然硬故障来进一步增强神经网络。在本文中,我们对基于RRAM的加速器执行了一种全面的故障感知攻击分析方法,通过考虑基于广泛的器件和电路级非理想特性的五个攻击模型。对非理想性质的研究考虑了详细的硬件情况,并提供了一个更准确的安全视角。与现有的仅利用自然故障的对手攻击策略相比,我们提出了一种基于两种软故障注入方法的主动攻击,这两种方法不需要高精度的实验室环境。此外,为了提高攻击的有效性,还提出了一种优化的故障感知对手算法。在经典卷积神经网络上对MNIST数据集的仿真结果表明,所提出的故障感知对手攻击模型和算法在攻击图像分类方面取得了显著改进。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Editorial: Thought leaders in sensor research: volume 1 Electronic tongue made of gelatin self-supporting films on printed electrodes to detect lactose Learning control for body caudal undulation with soft sensory feedback Erratum: AI-boosted CRISPR-Cas13a and total internal reflection fluorescence microscopy system for SARS-CoV-2 detection Evaluation of a point-of-use device used for autoantibody analysis and its potential for following microcystin leucine-arginine exposure
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1