arXiv:2510.24422cs.CRcs.AR2025-10中稿 · VLSID 2026被引 1

攻击基于PUF的二值神经网络,仅几分钟即可恢复密钥和模型。

Attack on a PUF-based Secure Binary Neural Network

  • 通过观察准确率变化,逐位破解PUF密钥
  • 在MNIST上恢复85%密钥,模型准确率达93%
  • 适合研究硬件安全与对抗性攻击的读者

部署在忆阻器交叉阵列上的二值神经网络(BNN)为边缘计算提供节能方案,但因忆阻器非易失性易受物理攻击。近期Rajendran等人提出基于物理不可克隆函数(PUF)的保护机制,通过PUF密钥比特交换权重和偏置矩阵列来保护模型。本文揭示该方案存在漏洞,可被用于恢复PUF密钥。攻击方法受差分密码分析启发,通过监测模型准确率变化逐位重构PUF密钥,最终恢复原始模型参数。在MNIST训练的BNN上,该攻击成功恢复85%的PUF密钥,模型分类准确率达93%,接近原模型96%的水平。攻击仅需数分钟,效率极高。

原文摘要 · Abstract (English)

Binarized Neural Networks (BNNs) deployed on memristive crossbar arrays provide energy-efficient solutions for edge computing but are susceptible to physical attacks due to memristor nonvolatility. Recently, Rajendran et al. (IEEE Embedded Systems Letter 2025) proposed a Physical Unclonable Function (PUF)-based scheme to secure BNNs against theft attacks. Specifically, the weight and bias matrices of the BNN layers were secured by swapping columns based on device's PUF key bits. In this paper, we demonstrate that this scheme to secure BNNs is vulnerable to PUF-key recovery attack. As a consequence of our attack, we recover the secret weight and bias matrices of the BNN. Our approach is motivated by differential cryptanalysis and reconstructs the PUF key bit-by-bit by observing the change in model accuracy, and eventually recovering the BNN model parameters. Evaluated on a BNN trained on the MNIST dataset, our attack could recover 85% of the PUF key, and recover the BNN model up to 93% classification accuracy compared to the original model's 96% accuracy. Our attack is very efficient and it takes a couple of minutes to recovery the PUF key and the model parameters.

硬件安全模型攻击忆阻器PUF

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。