NeuroAttack: Undermining Spiking Neural Networks Security through Externally Triggered Bit-Flips
arXiv:2005.08041 · doi:10.1109/IJCNN48605.2020.9207351
Abstract
Due to their proven efficiency, machine-learning systems are deployed in a wide range of complex real-life problems. More specifically, Spiking Neural Networks (SNNs) emerged as a promising solution to the accuracy, resource-utilization, and energy-efficiency challenges in machine-learning systems. While these systems are going mainstream, they have inherent security and reliability issues. In this paper, we propose NeuroAttack, a cross-layer attack that threatens the SNNs integrity by exploiting low-level reliability issues through a high-level attack. Particularly, we trigger a fault-injection based sneaky hardware backdoor through a carefully crafted adversarial input noise. Our results on Deep Neural Networks (DNNs) and SNNs show a serious integrity threat to state-of-the art machine-learning techniques.
Accepted for publication at the 2020 International Joint Conference on Neural Networks (IJCNN)
References in corpus (5)
- Spiking Neural Networks Hardware Implementations and Challenges: a Survey
- BindsNET: A machine learning-oriented spiking neural networks library in Python
- Robust Machine Learning Systems: Challenges, Current Trends, Perspectives, and the Road Ahead
- Is Spiking Secure? A Comparative Study on the Security Vulnerabilities of Spiking and Deep Neural Networks
- ReD-CaNe: A Systematic Methodology for Resilience Analysis and Design of Capsule Networks under Approximations
Cited by in corpus (7)
- Hardware and Software Optimizations for Accelerating Deep Neural Networks: Survey of Current Trends, Challenges, and the Road Ahead
- Q-SpiNN: A Framework for Quantizing Spiking Neural Networks
- Towards Energy-Efficient and Secure Edge AI: A Cross-Layer Framework
- ReSpawn: Energy-Efficient Fault-Tolerance for Spiking Neural Networks considering Unreliable Memories
- Embodied Neuromorphic Artificial Intelligence for Robotics: Perspectives, Challenges, and Research Development Stack
- Attacking Graph Neural Networks with Bit Flips: Weisfeiler and Lehman Go Indifferent
- Special Session: Towards an Agile Design Methodology for Efficient, Reliable, and Secure ML Systems