Pith. sign in

REVIEW 1 cited by

Bandwidth Utilization Side-Channel on ML Inference Accelerators

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2110.07157 v1 pith:SNCUN3CE submitted 2021-10-14 cs.CR

classification cs.CR
keywords acceleratorsinferenceperformanceside-channeladdressattacksbandwidthconfidential
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Accelerators used for machine learning (ML) inference provide great performance benefits over CPUs. Securing confidential model in inference against off-chip side-channel attacks is critical in harnessing the performance advantage in practice. Data and memory address encryption has been recently proposed to defend against off-chip attacks. In this paper, we demonstrate that bandwidth utilization on the interface between accelerators and the weight storage can serve a side-channel for leaking confidential ML model architecture. This side channel is independent of the type of interface, leaks even in the presence of data and memory address encryption and can be monitored through performance counters or through bus contention from an on-chip unprivileged process.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. SoK: A Systems Perspective on Compound AI Threats and Countermeasures

    cs.CR 2024-11 conditional novelty 5.0 of 10

    A systematization of software and hardware attacks and defenses for compound AI systems, arguing that cross-layer attack composition reduces the threat model burden on attackers.

Pith tools