In plain words: It maps what is worth stealing on AI chips—like model weights—and compares it to the secrets guarded in crypto hardware, then reviews how glitches can fool neural networks. This shows AI chips need their threat models, since targets differ from crypto keys.
Abstract
This chapter is on the security assessment of artificial intelligence (AI) and neural network (NN) accelerators in the face of fault injection attacks. More specifically, it discusses the assets on these platforms and compares them with ones known and well-studied in the field of cryptographic systems. This is a crucial step that must be taken in order to define the threat models precisely. With respect to that, fault attacks mounted on NNs and AI accelerators are explored.
Shahin Tajik, Fatemeh Ganji
arXiv:2008.07072 · cs.CR, cs.LG · submitted Aug 17, 2020 · updated Feb 11, 2021
abstract · pdf · html