Defense against ML-based Power Side-channel Attacks on DNN Accelerators with Adversarial Attacks
Xiaobei Yan, Chip Hong Chang, Tianwei Zhang

TL;DR
This paper introduces AIAShield, a novel defense mechanism against power side-channel attacks on FPGA-based AI accelerators, using adversarial noise crafted via neural architecture search to significantly reduce information leakage with minimal overhead.
Contribution
AIAShield combines hardware-based adversarial noise generation with algorithmic obfuscation using neural architecture search to enhance security against power side-channel attacks.
Findings
AIAShield effectively reduces side-channel information leakage.
The method incurs minimal performance overhead.
It outperforms existing defense solutions on NVDLA.
Abstract
Artificial Intelligence (AI) hardware accelerators have been widely adopted to enhance the efficiency of deep learning applications. However, they also raise security concerns regarding their vulnerability to power side-channel attacks (SCA). In these attacks, the adversary exploits unintended communication channels to infer sensitive information processed by the accelerator, posing significant privacy and copyright risks to the models. Advanced machine learning algorithms are further employed to facilitate the side-channel analysis and exacerbate the privacy issue of AI accelerators. Traditional defense strategies naively inject execution noise to the runtime of AI models, which inevitably introduce large overheads. In this paper, we present AIAShield, a novel defense methodology to safeguard FPGA-based AI accelerators and mitigate model extraction threats via power-based SCAs. The…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPhysical Unclonable Functions (PUFs) and Hardware Security · Cryptographic Implementations and Security · Electrostatic Discharge in Electronics
