Hardware Trojan Attacks on the Reconfigurable Interconnections of Convolutional Neural Networks Accelerators

  • Chen Yang
  • , Jia Hou
  • , Minshun Wu
  • , Kuizhi Mei
  • , Li Geng

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

11 Scopus citations

Abstract

Convolutional neural networks (CNNs) have demonstrated significant superiority in modern artificial intelligence (AI) applications. To accelerate the inference process of CNNs, reconfigurable CNN accelerators that support diverse networks are widely employed for AI systems. Due to ubiquitous deployment of these AI systems, a strong incentive rises for adversaries to attack CNN accelerators via hardware Trojan, which is one of the most important attack models in hardware security domain. This paper proposed a hardware Trojan that attacks the crucial component in CNN accelerators, i.e., reconfigurable interconnection network. This hardware Trojan changes the data paths under activation, resulting in incorrect connection of the arithmetic circuit, thereby causing wrong convolutional computation. Experimental results show that with increasing only 0.27% hardware overhead to the accelerator, the proposed hardware Trojan can be activated to cause a degradation of inference accuracy by 8.93% 86.20%.

Original languageEnglish
Title of host publication2020 IEEE 15th International Conference on Solid-State and Integrated Circuit Technology, ICSICT 2020 - Proceedings
EditorsShaofeng Yu, Xiaona Zhu, Ting-Ao Tang
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781728162355
DOIs
StatePublished - 3 Nov 2020
Event15th IEEE International Conference on Solid-State and Integrated Circuit Technology, ICSICT 2020 - Virtual, Kunming, China
Duration: 3 Nov 20206 Nov 2020

Publication series

Name2020 IEEE 15th International Conference on Solid-State and Integrated Circuit Technology, ICSICT 2020 - Proceedings

Conference

Conference15th IEEE International Conference on Solid-State and Integrated Circuit Technology, ICSICT 2020
Country/TerritoryChina
CityVirtual, Kunming
Period3/11/206/11/20

Fingerprint

Dive into the research topics of 'Hardware Trojan Attacks on the Reconfigurable Interconnections of Convolutional Neural Networks Accelerators'. Together they form a unique fingerprint.

Cite this