Pith. sign in

REVIEW

Bias Busters: Robustifying DL-based Lithographic Hotspot Detectors Against Backdooring Attacks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2004.12492 v1 pith:BFUB55GN submitted 2020-04-26 cs.LG cs.CRstat.ML

classification cs.LGcs.CRstat.ML
keywords trainingattacksdefensehotspotbackdoorbackdooringdatadl-based
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Deep learning (DL) offers potential improvements throughout the CAD tool-flow, one promising application being lithographic hotspot detection. However, DL techniques have been shown to be especially vulnerable to inference and training time adversarial attacks. Recent work has demonstrated that a small fraction of malicious physical designers can stealthily "backdoor" a DL-based hotspot detector during its training phase such that it accurately classifies regular layout clips but predicts hotspots containing a specially crafted trigger shape as non-hotspots. We propose a novel training data augmentation strategy as a powerful defense against such backdooring attacks. The defense works by eliminating the intentional biases introduced in the training data but does not require knowledge of which training samples are poisoned or the nature of the backdoor trigger. Our results show that the defense can drastically reduce the attack success rate from 84% to ~0%.

Discussion (0). Sign in to comment.

Pith tools