A Desynchronization-Based Countermeasure Against Side-Channel Analysis of Neural Networks

03/25/2023
by   Jakub Breier, et al.
0

Model extraction attacks have been widely applied, which can normally be used to recover confidential parameters of neural networks for multiple layers. Recently, side-channel analysis of neural networks allows parameter extraction even for networks with several multiple deep layers with high effectiveness. It is therefore of interest to implement a certain level of protection against these attacks. In this paper, we propose a desynchronization-based countermeasure that makes the timing analysis of activation functions harder. We analyze the timing properties of several activation functions and design the desynchronization in a way that the dependency on the input and the activation type is hidden. We experimentally verify the effectiveness of the countermeasure on a 32-bit ARM Cortex-M4 microcontroller and employ a t-test to show the side-channel information leakage. The overhead ultimately depends on the number of neurons in the fully-connected layer, for example, in the case of 4096 neurons in VGG-19, the overheads are between 2.8

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/29/2019

On the rate of convergence of fully connected very deep neural network regression estimates

Recent results in nonparametric regression show that deep learning, i.e....
research
06/01/2018

q-Neurons: Neuron Activations based on Stochastic Jackson's Derivative Operators

We propose a new generic type of stochastic neurons, called q-neurons, t...
research
08/29/2022

Normalized Activation Function: Toward Better Convergence

Activation functions are essential for neural networks to introduce non-...
research
10/29/2019

MaskedNet: The First Hardware Inference Engine Aiming Power Side-Channel Protection

Differential Power Analysis (DPA) has been an active area of research fo...
research
08/15/2020

A Deep Convolutional Neural Network for the Detection of Polyps in Colonoscopy Images

Computerized detection of colonic polyps remains an unsolved issue becau...
research
10/22/2018

CSI Neural Network: Using Side-channels to Recover Your Artificial Neural Network Information

Machine learning has become mainstream across industries. Numerous examp...
research
06/03/2016

Dense Associative Memory for Pattern Recognition

A model of associative memory is studied, which stores and reliably retr...

Please sign up or login with your details

Forgot password? Click here to reset