arXiv:2503.21793cs.NEcs.AI2025-03被引 6

攻击者用特定脉冲信号触发神经形态芯片中的恶意硬件木马,导致系统永久误判。

Input-Triggered Hardware Trojan Attack on Spiking Neural Networks

  • 用特定脉冲输入激活单个神经元中的隐藏木马
  • 木马触发后神经元持续放电,污染整个网络输出
  • 攻击面积小、功耗低,难以被传统检测手段发现

基于脉冲神经网络(SNNs)的类脑计算因其低功耗优势成为传统人工神经网络(ANNs)的有力替代,但其安全性远未得到充分研究。本文提出一种新型输入触发式硬件木马(HT)攻击,将木马机制浓缩于一个神经元中。攻击通过设计特定脉冲输入,诱导目标神经元产生异常脉冲序列,进而使其永久饱和放电,无法恢复至静息状态。该异常脉冲污染网络整体响应,引发错误决策。我们提出方法选择合适神经元并生成触发输入模式,并在三个类脑计算领域常用基准上通过仿真验证。同时,设计了模拟脉冲神经元与数字SNN加速器的硬件实现,证明该攻击具有极小面积和功耗开销,可轻易规避检测。

原文摘要 · Abstract (English)

Neuromorphic computing based on spiking neural networks (SNNs) is emerging as a promising alternative to traditional artificial neural networks (ANNs), offering unique advantages in terms of low power consumption. However, the security aspect of SNNs is under-explored compared to their ANN counterparts. As the increasing reliance on AI systems comes with unique security risks and challenges, understanding the vulnerabilities and threat landscape is essential as neuromorphic computing matures. In this effort, we propose a novel input-triggered Hardware Trojan (HT) attack for SNNs. The HT mechanism is condensed in the area of one neuron. The trigger mechanism is an input message crafted in the spiking domain such that a selected neuron produces a malicious spike train that is not met in normal settings. This spike train triggers a malicious modification in the neuron that forces it to saturate, firing permanently and failing to recover to its resting state even when the input activity stops. The excessive spikes pollute the network and produce misleading decisions. We propose a methodology to select an appropriate neuron and to generate the input pattern that triggers the HT payload. The attack is illustrated by simulation on three popular benchmarks in the neuromorphic community. We also propose a hardware implementation for an analog spiking neuron and a digital SNN accelerator, demonstrating that the HT has a negligible area and power footprint and, thereby, can easily evade detection.

硬件安全脉冲神经网络木马攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。