DeepHammer: Depleting the Intelligence of Deep Neural Networks through Targeted Chain of Bit Flips

Security of machine learning is increasingly becoming a major concern due to\nthe ubiquitous deployment of deep learning in many security-sensitive domains.\nMany prior studies have shown external attacks such as adversarial examples\nthat tamper with the integrity of DNNs using maliciously crafted inputs.\nHowever, the security implication of internal threats (i.e., hardware\nvulnerability) to DNN models has not yet been well understood. In this paper,\nwe demonstrate the first hardware-based attack on quantized deep neural\nnetworks-DeepHammer-that deterministically induces bit flips in model weights\nto compromise DNN inference by exploiting the rowhammer vulnerability.\nDeepHammer performs aggressive bit search in the DNN model to identify the most\nvulnerable weight bits that are flippable under system constraints. To trigger\ndeterministic bit flips across multiple pages within reasonable amount of time,\nwe develop novel system-level techniques that enable fast deployment of victim\npages, memory-efficient rowhammering and precise flipping of targeted bits.\nDeepHammer can deliberately degrade the inference accuracy of the victim DNN\nsystem to a level that is only as good as random guess, thus completely\ndepleting the intelligence of targeted DNN systems. We systematically\ndemonstrate our attacks on real systems against 12 DNN architectures with 4\ndifferent datasets and different application domains. Our evaluation shows that\nDeepHammer is able to successfully tamper DNN inference behavior at run-time\nwithin a few minutes. We further discuss several mitigation techniques from\nboth algorithm and system levels to protect DNNs against such attacks. Our work\nhighlights the need to incorporate security mechanisms in future deep learning\nsystem to enhance the robustness of DNN against hardware-based deterministic\nfault injections.\n

Paper

Similar papers

© 2026 NYSGPT2525 LLC