Cache Telepathy: Leveraging Shared Resource Attacks to Learn DNN\n Architectures

Кэш-телепатия: использование атак на общие ресурсы для выявления архитектур DNN
Mengjia Yan, Christopher W. Fletcher, Josep Torrellas
2018-08-14

Cache side-channel attackDNN architecture stealingFlush+ReloadPrime+ProbeTiled GEMM
Deep Neural Networks (DNNs) are fast becoming ubiquitous for their ability to\nattain good accuracy in various machine learning tasks. A DNN's architecture\n(i.e., its hyper-parameters) broadly determines the DNN's accuracy and\nperformance, and is often confidential. Attacking a DNN in the cloud to obtain\nits architecture can potentially provide major commercial value. Further,\nattaining a DNN's architecture facilitates other, existing DNN attacks.\n This paper presents Cache Telepathy: a fast and accurate mechanism to steal a\nDNN's architecture using the cache side channel. Our attack is based on the\ninsight that DNN inference relies heavily on tiled GEMM (Generalized Matrix\nMultiply), and that DNN architecture parameters determine the number of GEMM\ncalls and the dimensions of the matrices used in the GEMM functions. Such\ninformation can be leaked through the cache side channel.\n This paper uses Prime+Probe and Flush+Reload to attack VGG and ResNet DNNs\nrunning OpenBLAS and Intel MKL libraries. Our attack is effective in helping\nobtain the architectures by very substantially reducing the search space of\ntarget DNN architectures. For example, for VGG using OpenBLAS, it reduces the\nsearch space from more than $10^{35}$ architectures to just 16.\n
1
Cache Telepathy infers confidential DNN architectures through cache side-channel leakage during inference.
2
For VGG running on OpenBLAS, the attack reduces the candidate architecture space from more than 10^35 possibilities to 16.
3
Prime+Probe and Flush+Reload attacks were demonstrated against VGG and ResNet models using OpenBLAS and Intel MKL.
4
Recovering a DNN architecture can facilitate additional attacks and potentially expose commercially valuable proprietary designs.
5
The attack exploits tiled GEMM behavior: architecture parameters determine GEMM call counts and matrix dimensions observable through cache activity.

Cloud-hosted deep neural network (DNN) inference implementations, specifically VGG and ResNet models running with OpenBLAS and Intel MKL

Leakage of DNN architecture parameters through cache side channels, including inference-dependent GEMM call counts and matrix dimensions

Publication Details
Publication Date
2018-08-14
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Mengjia Yan
Christopher W. Fletcher
Josep Torrellas
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%