A New Paradigm for Immunization of Deep Neural Networks Against Replication Attacks Based on Spintronics

Mohammad Hadi Rezayati,Mohammad Hossein Moaiyeri,Abdolah Amirany,Kian Jafari
DOI: https://doi.org/10.1109/tcsii.2024.3371154
2024-01-01
Abstract:The rapid advancement of deep neural networks (DNNs) has necessitated exploring emerging technologies. In addition, the growing significance of security arises from the escalating risks of intellectual property (IP) infringement and reverse engineering threats. This paper introduces an efficient strategy for safeguarding DNNs using spintronic technology. In the proposed approach, the stochastic characteristics of magnetic tunnel junctions (MTJs) are harnessed to alter the behavior and performance of DNN activation functions. This manipulation is designed to fortify the networks against model replication and reverse engineering. Under normal circumstances, DNN functions normally, maintaining the desired accuracy. However, if an unauthorized intrusion occurs, the behavior of the ReLU activation function undergoes a random modification and deviates from its conventional decision-making point based on an MTJ-based control circuit. Consequently, the network’s accuracy drastically drops, making it useless and unreplicable. The proposed circuit has been designed and post-layout simulated using TSMC 40nm CMOS technology. Comprehensive analyses have also been conducted, encompassing various DNNs and datasets, to validate the efficacy of the proposed method against model replication attacks. The results highlight the high efficacy of this approach in thwarting such adversarial endeavors.
engineering, electrical & electronic
What problem does this paper attempt to address?