Pith. sign in

REVIEW 1 cited by

New Security Challenges on Machine Learning Inference Engine: Chip Cloning and Model Reverse Engineering

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2003.09739 v1 pith:TNT5DRHN submitted 2020-03-21 eess.SP

classification eess.SP
keywords chipcloningengineinferenceweightengineeringgreatlearning
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Machine learning inference engine is of great interest to smart edge computing. Compute-in-memory (CIM) architecture has shown significant improvements in throughput and energy efficiency for hardware acceleration. Emerging non-volatile memory technologies offer great potential for instant on and off by dynamic power gating. Inference engine is typically pre-trained by the cloud and then being deployed to the filed. There are new attack models on chip cloning and neural network model reverse engineering. In this paper, we propose countermeasures to the weight cloning and input-output pair attacks. The first strategy is the weight fine-tune to compensate the analog-to-digital converter (ADC) offset for a specific chip instance while inducing significant accuracy drop for cloned chip instances. The second strategy is the weight shuffle and fake rows insertion to allow accurate propagation of the activations of the neural network only with a key.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. SoK: A Systems Perspective on Compound AI Threats and Countermeasures

    cs.CR 2024-11 conditional novelty 5.0 of 10

    A systematization of software and hardware attacks and defenses for compound AI systems, arguing that cross-layer attack composition reduces the threat model burden on attackers.

Pith tools