用软硬件协同锁保护生成模型,防窃取且开销极小
LLA: Enhancing Security and Privacy for Generative Models with Logic-Locked Accelerators
- 软硬件结合:在神经元嵌入密钥,硬件锁需密钥才可运行
- 抵御各类攻击:对密钥优化攻击有强防御力,性能损失<0.1%
- 适合模型版权方:保护7168位密钥的生成模型部署安全
我们提出LLA,一种针对生成式AI模型的有效知识产权保护方案。该方案通过软硬件协同机制,防范供应链中的多种威胁,包括模型窃取、模型篡改和信息泄露。软件层面,将密钥位嵌入神经元中,触发异常输出以降低模型性能,并采用不变性变换隐藏密钥值;硬件层面,在AI加速器中集成轻量级锁模块,兼容多种数据流模式与工具链。预存秘密密钥的加速器可作为访问知识产权所有者模型服务的许可证。评估结果表明,LLA能抵御广泛的基于查询的密钥优化攻击,同时对7,168位密钥的计算开销不足0.1%。
原文摘要 · Abstract (English)
We introduce LLA, an effective intellectual property (IP) protection scheme for generative AI models. LLA leverages the synergy between hardware and software to defend against various supply chain threats, including model theft, model corruption, and information leakage. On the software side, it embeds key bits into neurons that can trigger outliers to degrade performance and applies invariance transformations to obscure the key values. On the hardware side, it integrates a lightweight locking module into the AI accelerator while maintaining compatibility with various dataflow patterns and toolchains. An accelerator with a pre-stored secret key acts as a license to access the model services provided by the IP owner. The evaluation results show that LLA can withstand a broad range of oracle-guided key optimization attacks, while incurring a minimal computational overhead of less than 0.1% for 7,168 key bits.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。