引用本文:邹敏辉,周俊龙,孙晋,汪成亮.基于木马的方式增强RRAM计算系统的安全性.软件学报,2021,32(8):2457-2468
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 2920次   下载 6398 本文二维码信息
码上扫一扫!
分享到: 微信 更多
基于木马的方式增强RRAM计算系统的安全性
邹敏辉1, 周俊龙1, 孙晋1, 汪成亮2
1.南京理工大学 计算机科学与工程学院, 江苏 南京 210094;2.重庆大学 计算机学院, 重庆 400044
摘要:
基于新型存储器件RRAM的计算系统因为能够在内存中执行矩阵点乘向量运算而受到广泛的关注.然而,RRAM计算系统的安全性却未受到足够的重视.攻击者通过访问未授权的RRAM计算系统,进而以黑盒攻击的方式来获取存储于RRAM计算系统中的神经网络模型.以阻止此种攻击为目标,所提出的防御方法是基于良性木马,即当RRAM计算系统未授权时,系统中的木马极容易被激活,进而影响系统的输出预测准确性,从而保证系统不能正常运行;当RRAM计算系统被授权时,系统中的木马极难被误激活,从而系统能够正常运行.实验结果表明,该方法能够使未授权的RRAM计算系统的输出预测准确性降低至15%以下,并且硬件开销小于系统中RRAM硬件的4.5%.
关键词:  RRAM计算系统  木马  安全
DOI:10.13328/j.cnki.jos.006193
分类号:TP309
基金项目:国家自然科学基金(61672115,61802185,61872185);江苏省自然科学基金(BK20190447,BK20180470);教育部中央高校基本科研业务费专项资金(30919011233,30919011402);中国博士后科学基金(2020M680068)
Enhancing Security of RRAM Computing System Based on Trojans
ZOU Min-Hui1, ZHOU Jun-Long1, SUN Jin1, WANG Cheng-Liang2
1.School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing 210094, China;2.College of Computer Science, Chongqing University, Chongqing 400044, China
Abstract:
Computing systems based on the emerging device resistive random-access memory (RRAM) have received a lot of attention due to its capability of performing matrix-vector-multiplications operations in memory. However, the security of the RRAM computing system has not been paid enough attention. An attacker can gain access to the neural network models stored in the RRAM computing system by illegally accessing an unauthorized RRAM computing system and then carrying on a black-box attack. The goal of this study is to thwart such attacks. The defense method proposed in this study is based on benign Trojan, which means that when the RRAM computing system is not authorized, the Trojan in the system are extremely easy to be activated, which in turn affects the prediction accuracy of the system's output, thus ensuring that the system is not able to operate normally; when the RRAM computing system is authorized, the Trojan in the system are extremely difficult to be activated accidently, thus enabling the system to operate normally. It is shown experimentally that the method enables the output prediction accuracy of an unauthorized RRAM computing system to be reduced to less than 15%, with a hardware overhead of less than 4.5% of the RRAM devices in the system.
Key words:  RRAM computing system  Trojan  security

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: