SparseLeakyNets: Classification Prediction Attack Over Sparsity-Aware Embedded Neural Networks Using Timing Side-Channel Information

Saurav Maji,Kyungmi Lee,Anantha P. Chandrakasan
DOI: https://doi.org/10.1109/lca.2024.3397730
IF: 2.3
2024-06-04
IEEE Computer Architecture Letters
Abstract:This letter explores security vulnerabilities in sparsity-aware optimizations for Neural Network (NN) platforms, specifically focusing on timing side-channel attacks introduced by optimizations such as skipping sparse multiplications. We propose a classification prediction attack that utilizes this timing side-channel information to mimic the NN's prediction outcomes. Our techniques were demonstrated for CIFAR-10, MNIST, and biomedical classification tasks using diverse dataflows and processing loads in timing models. The demonstrated results could predict the original classification decision with high accuracy.
computer science, hardware & architecture
What problem does this paper attempt to address?