Immunization of binarized deep neural networks against model replication attacks based on stochastic magnetoresistive RAMs
摘要
With the rapid advancement of deep neural networks (DNNs), security has become a critical concern due to the increasing threat of IP theft and reverse engineering in widely deployed DNNs. This paper presents an efficient method to secure the parameters of DNNs using magnetic tunnel junctions (MTJs), characterized by low power consumption, minimal hardware overhead, and rapid accuracy degradation upon intrusion, efficiently countering reverse engineering attempts. The proposed method utilizes the stochastic behavior of MTJs in the sub-critical current regime to secure binarized neural networks against model replication attacks seeking to reverse engineer the network’s synaptic weights. In this method, when the DNNs are not under attack, the weights are updated normally, and the accuracy of the network does not change. However, when DNNs are attacked and compromised, the proposed control and write circuitry updates the weights stochastically, resulting in a significant decrease in accuracy. On average, the accuracy of the tested DNNs declines by approximately 60% compared to the original network accuracy. Our comprehensive simulations showcase the effectiveness of the proposed method in countering model replication attacks and probing attacks, highlighting its superiority over previous approaches. Our proposed method shows that the attacker cannot recover the neural network by changing less than 1% of the network weights.