SoWaF: Shuffling of Weights and Feature Maps: A Novel Hardware Intrinsic Attack (HIA) on Convolutional Neural Network (CNN)

Security of inference phase deployment of Convolutional neural network (CNN)\ninto resource constrained embedded systems (e.g. low end FPGAs) is a growing\nresearch area. Using secure practices, third party FPGA designers can be\nprovided with no knowledge of initial and final classification layers. In this\nwork, we demonstrate that hardware intrinsic attack (HIA) in such a "secure"\ndesign is still possible. Proposed HIA is inserted inside mathematical\noperations of individual layers of CNN, which propagates erroneous operations\nin all the subsequent CNN layers that lead to misclassification. The attack is\nnon-periodic and completely random, hence it becomes difficult to detect. Five\ndifferent attack scenarios with respect to each CNN layer are designed and\nevaluated based on the overhead resources and the rate of triggering in\ncomparison to the original implementation. Our results for two CNN\narchitectures show that in all the attack scenarios, additional latency is\nnegligible (<0.61%), increment in DSP, LUT, FF is also less than 2.36%. Three\nattack scenarios do not require any additional BRAM resources, while in two\nscenarios BRAM increases, which compensates with the corresponding decrease in\nFF and LUTs. To the authors' best knowledge this work is the first to address\nthe hardware intrinsic CNN attack with the attacker does not have knowledge of\nthe full CNN.\n

Paper

References (39)

Scroll for more · 27 remaining

Similar papers

© 2026 NYSGPT2525 LLC