Hardware Trojan Attacks on Neural Networks
Joseph Clements, Yingjie Lao

TL;DR
This paper explores hardware Trojan attacks on neural networks, demonstrating how malicious hardware modifications can covertly manipulate neural network outputs, highlighting security vulnerabilities in AI hardware supply chains.
Contribution
It introduces a novel framework for inserting hardware Trojans into neural network implementations and evaluates their effectiveness on convolutional neural networks.
Findings
Trojan attacks can manipulate neural network outputs with minimal hardware modifications
Injected Trojans are undetectable under standard testing conditions
Effective classification of input triggers achieved with only 0.03% neuron modification
Abstract
With the rising popularity of machine learning and the ever increasing demand for computational power, there is a growing need for hardware optimized implementations of neural networks and other machine learning models. As the technology evolves, it is also plausible that machine learning or artificial intelligence will soon become consumer electronic products and military equipment, in the form of well-trained models. Unfortunately, the modern fabless business model of manufacturing hardware, while economic, leads to deficiencies in security through the supply chain. In this paper, we illuminate these security issues by introducing hardware Trojan attacks on neural networks, expanding the current taxonomy of neural network security to incorporate attacks of this nature. To aid in this, we develop a novel framework for inserting malicious hardware Trojans in the implementation of a…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdversarial Robustness in Machine Learning · Physical Unclonable Functions (PUFs) and Hardware Security · Advanced Malware Detection Techniques
