Sponge Examples: Energy-Latency Attacks on Neural Networks

06/05/2020
by   Ilia Shumailov, et al.
8

The high energy costs of neural network training and inference led to the use of acceleration hardware such as GPUs and TPUs. While this enabled us to train large-scale neural networks in datacenters and deploy them on edge devices, the focus so far is on average-case performance. In this work, we introduce a novel threat vector against neural networks whose energy consumption or decision latency are critical. We show how adversaries can exploit carefully crafted sponge examples, which are inputs designed to maximise energy consumption and latency. We mount two variants of this attack on established vision and language models, increasing energy consumption by a factor of 10 to 200. Our attacks can also be used to delay decisions where a network has critical real-time performance, such as in perception for autonomous vehicles. We demonstrate the portability of our malicious inputs across CPUs and a variety of hardware accelerator chips including GPUs, and an ASIC simulator. We conclude by proposing a defense strategy which mitigates our attack by shifting the analysis of energy consumption in hardware from an average-case to a worst-case perspective.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/14/2022

Energy-Latency Attacks via Sponge Poisoning

Sponge examples are test-time inputs carefully-optimized to increase ene...
research
02/23/2022

EcoFusion: Energy-Aware Adaptive Sensor Fusion for Efficient Autonomous Vehicle Perception

Autonomous vehicles use multiple sensors, large deep-learning models, an...
research
05/31/2022

MAD-EN: Microarchitectural Attack Detection through System-wide Energy Consumption

Microarchitectural attacks have become more threatening the hardware sec...
research
05/06/2023

Energy-Latency Attacks to On-Device Neural Networks via Sponge Poisoning

In recent years, on-device deep learning has gained attention as a means...
research
11/02/2018

Progress and Tradeoffs in Neural Language Models

In recent years, we have witnessed a dramatic shift towards techniques d...
research
05/18/2023

SpikeCP: Delay-Adaptive Reliable Spiking Neural Networks via Conformal Prediction

Spiking neural networks (SNNs) process time-series data via internal eve...
research
09/12/2021

Compute and Energy Consumption Trends in Deep Learning Inference

The progress of some AI paradigms such as deep learning is said to be li...

Please sign up or login with your details

Forgot password? Click here to reset