arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

通过嵌入式神经网络中的物理故障注入触发隐秘特征图后门

Triggering Stealthy Feature Map Backdoors via Physical Fault Injection in Embedded Neural Networks

Steyn Hommes, Vincent Dankbaar, Tanguy Stekke, Xiaomeng Wang, Lisanne Weidmann, Senna van Hoek, Durba Chatterjee, Lejla Batina, Zhuoran Liu

arXiv 2607.09473首次发表:更新:

AI 中文总结

研究通过物理故障注入对嵌入式神经网络发动攻击,提出跨层次攻击连接物理与算法层面。给出精确故障注入方法,实现端到端特征图级后门攻击,触发器仅在物理故障下激活,证明该攻击可突破现有防御,凸显新攻击向量及跨层防御需求。

AI 中文摘要

对嵌入式神经网络实现的故障注入攻击主要集中于通过破坏权重或中间计算来导致错误分类,而忽略了它们与算法对抗性威胁的相互作用。在这项工作中,我们提出了一种跨层次攻击,将实现层面的物理故障与算法层面的对抗性攻击联系起来。通过在神经网络推理过程中表征故障引起的数据扰动,我们将故障注入与后门学习相连接,实现了联合利用实现层面和算法层面漏洞的系统级攻击。具体而言,我们提出了一种精确的故障注入方法,在执行过程中将目标寄存器值可靠地操纵到易处理状态。利用这种故障注入精度,我们提出了一种新颖的端到端特征图级后门攻击,其中物理诱导的中间扰动充当隐秘触发器。与传统的基于输入的后门不同,我们的触发器仅在物理故障下激活,使神经网络表现出对抗性行为,在损害系统完整性的同时在正常操作期间保持良性。我们证明这种物理触发的后门可以安装在嵌入式神经网络平台上,并且对通常假设输入空间触发器的现有后门防御仍然有效。我们使用电磁故障注入在ARM Cortex-M4微控制器上实现的卷积神经网络上展示了攻击的实用性,这是受限嵌入式应用的常见平台。我们的结果突出了硬件和算法层面交叉处的一种新颖攻击向量,强调了跨抽象层次进行防御的必要性。

英文摘要

Fault injection (FI) attacks on embedded neural network (NN) implementations primarily focus on inducing misclassification by corrupting weights or intermediate computations, overlooking their interaction with algorithmic adversarial threats. In this work, we present a cross-level attack that bridges implementation-level physical faults to algorithm-level adversarial attacks. By characterizing fault-induced data perturbations during NN inference, we connect FI with backdoor learning, enabling system-level attacks that jointly exploit implementation- and algorithm-level vulnerabilities. Specifically, we propose a precise fault-injection method that reliably manipulates targeted register values to tractable states during execution. Leveraging this level of FI precision, we propose a novel end-to-end feature map-level backdoor attack, where physically induced intermediate perturbations serve as stealthy triggers. Unlike conventional input-based backdoors, our trigger is activated only under physical faults, causing the NN to exhibit adversarial behavior that compromises system integrity while remaining benign during normal operation. We demonstrate that such physically triggered backdoors can be mounted on embedded NN platforms and remain effective against existing backdoor defenses that typically assume input-space triggers. We showcase the attack practicality using electromagnetic FI on convolutional neural networks implemented on ARM Cortex-M4 microcontroller, which is a common platform for constrained embedded applications. Our results highlight a novel attack vector at the intersection of hardware and algorithmic levels, stressing the need for defenses across abstraction levels.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑