arXiv:2411.16712cs.CRcs.AR2024-11被引 6

光神经网络加速器遭硬件后门攻击,导致识别准确率下降超80%。

SafeLight: Enhancing Security in Optical Convolutional Neural Network Accelerators

  • 通过操控10%微环谐振器实现对光神经网络的隐蔽攻击
  • 攻击使卷积神经网络准确率下降最高达80.46%
  • 提出防御方法可有效恢复被降低的模型性能

深度学习的迅猛发展推动了计算硬件革新,尤其在提升深度神经网络中高耗能的乘加运算效率方面。硅光子集成系统作为能效极高的平台,具备光速计算与通信能力,使光学神经网络(ONN)成为加速卷积神经网络(CNN)等模型的变革性技术。然而,光学硬件日益复杂也带来了新安全隐患,特别是硬件木马(HT)攻击的风险。尽管ONN平台备受关注,但针对其受HT影响的研究仍不足。本文深入分析了此类攻击对基于ONN加速器的CNN模型性能的影响。具体而言,我们展示了在最先进的非相干ONN加速器中,通过攻击微环谐振器(MRs),仅需干预10%的MRs即可导致各类CNN模型分类准确率下降7.49%至80.46%。随后,我们提出了增强ONN加速器抗攻击能力的技术,并验证最优方案可有效恢复准确率损失。

原文摘要 · Abstract (English)

The rapid proliferation of deep learning has revolutionized computing hardware, driving innovations to improve computationally expensive multiply-and-accumulate operations in deep neural networks. Among these innovations are integrated silicon-photonic systems that have emerged as energy-efficient platforms capable of achieving light speed computation and communication, positioning optical neural network (ONN) platforms as a transformative technology for accelerating deep learning models such as convolutional neural networks (CNNs). However, the increasing complexity of optical hardware introduces new vulnerabilities, notably the risk of hardware trojan (HT) attacks. Despite the growing interest in ONN platforms, little attention has been given to how HT-induced threats can compromise performance and security. This paper presents an in-depth analysis of the impact of such attacks on the performance of CNN models accelerated by ONN accelerators. Specifically, we show how HTs can compromise microring resonators (MRs) in a state-of-the-art non-coherent ONN accelerator and reduce classification accuracy across CNN models by up to 7.49% to 80.46% by just targeting 10% of MRs. We then propose techniques to enhance ONN accelerator robustness against these attacks and show how the best techniques can effectively recover the accuracy drops.

光神经网络硬件安全后门攻击加速器

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。