CLEANN: Accelerated Trojan Shield for Embedded Neural Networks

09/04/2020
by   Mojan Javaheripi, et al.
20

We propose CLEANN, the first end-to-end framework that enables online mitigation of Trojans for embedded Deep Neural Network (DNN) applications. A Trojan attack works by injecting a backdoor in the DNN while training; during inference, the Trojan can be activated by the specific backdoor trigger. What differentiates CLEANN from the prior work is its lightweight methodology which recovers the ground-truth class of Trojan samples without the need for labeled data, model retraining, or prior assumptions on the trigger or the attack. We leverage dictionary learning and sparse approximation to characterize the statistical behavior of benign data and identify Trojan triggers. CLEANN is devised based on algorithm/hardware co-design and is equipped with specialized hardware to enable efficient real-time execution on resource-constrained embedded platforms. Proof of concept evaluations on CLEANN for the state-of-the-art Neural Trojan attacks on visual benchmarks demonstrate its competitive advantage in terms of attack resiliency and execution overhead.

READ FULL TEXT

page 2

page 5

research
11/02/2021

HASHTAG: Hash Signatures for Online Detection of Fault-Injection Attacks on Deep Neural Networks

We propose HASHTAG, the first framework that enables high-accuracy detec...
research
10/25/2019

An End-to-End HW/SW Co-Design Methodology to Design Efficient Deep Neural Network Systems using Virtual Models

End-to-end performance estimation and measurement of deep neural network...
research
04/22/2020

Towards Real-Time DNN Inference on Mobile Platforms with Model Pruning and Compiler Optimization

High-end mobile platforms rapidly serve as primary computing devices for...
research
05/05/2023

RARES: Runtime Attack Resilient Embedded System Design Using Verified Proof-of-Execution

Modern society is getting accustomed to the Internet of Things (IoT) and...
research
02/01/2021

Forensicability of Deep Neural Network Inference Pipelines

We propose methods to infer properties of the execution environment of m...
research
11/22/2020

Third ArchEdge Workshop: Exploring the Design Space of Efficient Deep Neural Networks

This paper gives an overview of our ongoing work on the design space exp...
research
07/16/2021

Efficient automated U-Net based tree crown delineation using UAV multi-spectral imagery on embedded devices

Delineation approaches provide significant benefits to various domains, ...

Please sign up or login with your details

Forgot password? Click here to reset