arXiv:2510.24985cs.CRcs.AI2025-10中稿 · ICCD 2025被引 3

用FPGA加速防御模型比特翻转攻击,提升效率与能效。

FaRAccel: FPGA-Accelerated Defense Architecture for Efficient Bit-Flip Attack Resilience in Transformer Models

  • 在FPGA上构建动态重连机制,实时优化激活路径。
  • 推理延迟降低57%,能耗减少43%,保持原方法抗攻击能力。
  • 适合部署在资源受限的AI硬件平台,如边缘设备。

遗忘重连(FaR)方法通过动态重连线性层中的关键参数,有效抵御基于Transformer模型的比特翻转攻击(BFAs)。然而,该方法在运行时修改激活路径,带来显著的性能与内存开销,且缺乏硬件优化。为此,我们提出FaRAccel——一种基于FPGA的新型硬件加速架构,专为卸载和优化FaR操作而设计。FaRAccel集成可重构逻辑实现动态激活重路由,并轻量级存储重连配置,实现低延迟推理与极小能量开销。我们在多个Transformer模型上评估了FaRAccel,结果表明其在保持原始FaR鲁棒性的同时,显著降低推理延迟并提升能效。据我们所知,这是首个面向Transformer模型比特翻转攻击的硬件加速防御方案,有效弥合算法韧性与真实AI平台高效部署之间的差距。

原文摘要 · Abstract (English)

Forget and Rewire (FaR) methodology has demonstrated strong resilience against Bit-Flip Attacks (BFAs) on Transformer-based models by obfuscating critical parameters through dynamic rewiring of linear layers. However, the application of FaR introduces non-negligible performance and memory overheads, primarily due to the runtime modification of activation pathways and the lack of hardware-level optimization. To overcome these limitations, we propose FaRAccel, a novel hardware accelerator architecture implemented on FPGA, specifically designed to offload and optimize FaR operations. FaRAccel integrates reconfigurable logic for dynamic activation rerouting, and lightweight storage of rewiring configurations, enabling low-latency inference with minimal energy overhead. We evaluate FaRAccel across a suite of Transformer models and demonstrate substantial reductions in FaR inference latency and improvement in energy efficiency, while maintaining the robustness gains of the original FaR methodology. To the best of our knowledge, this is the first hardware-accelerated defense against BFAs in Transformers, effectively bridging the gap between algorithmic resilience and efficient deployment on real-world AI platforms.

FPGA加速模型防御Transformer安全比特翻转攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。