⚡ 本页包含 AI 生成的分析内容,仅供参考
针对神经网络硬件加速器在低功耗IoT节点中面临功耗侧信道攻击的风险,提出了一种基于阈值实现(Threshold Implementation)的加速器设计,同时保护模型参数和输入数据不被泄露。该工作在硬件层面实现了对神经网络计算的掩码防护,有效抵御基于功耗的侧信道攻击。
Indian Institute of Science, Bengaluru, India 3 Analog Devices, Wilmington, MA 1 2 Neural network (NN) hardware accelerators are being widely deployed on low-power IoT nodes for energy-efficient decision making. Embedded NN implementations can use locally stored proprietary models, and may operate over private inputs (e.g., health monitors with patient-specific biomedical classifiers [6]), which must not be disclosed. Side-channel attacks (SCA) are a major concern in embedded systems where physical access to the operating hardware can allow attackers to recover secret data by exploiting information leakage through power consumption, timing and electromagnetic emissions [1,7,8]. As shown in Fig. 34.3.1, SCA on embedded NN implementations can reveal the model parameters [9] as well as the inputs [10]. To address these concerns, we present an energy-efficient ASIC solution for protecting both the model parameters and the input
Saurav Maji1, Utsav Banerjee2, Samuel H. Fuller1,3, Anantha P. Chandrakasan1
Massachusetts Institute of Technology, Cambridge, MA