发表机构
University of Florida; University of Texas at Dallas; Rensselaer Polytechnic Institute(佛罗里达大学; 德克萨斯大学达拉斯分校; 伦斯勒理工学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对深度神经网络易受比特翻转攻击的问题,提出BARE-AI运行时框架,利用轻量级硬件监视器捕获激活统计并检测、定位和缓解攻击,在多种模型和攻击下实现高检测率与低开销,适用于安全关键边缘应用。
AI 中文摘要
深度神经网络(DNN)是许多安全关键系统不可或缺的组成部分,然而它们仍然极易受到比特翻转攻击(BFA)的影响,在这种攻击中,少量内存级扰动即可大幅降低精度。现有防御措施要么带来显著的硬件开销,要么依赖重新训练,要么无法抵御针对性翻转。我们提出BARE-AI,一个在推理期间检测、定位并缓解BFA的运行时框架。BARE-AI引入了AI性能计数器(APC),即加速器数据通路中的轻量级硬件监视器,用于捕获每层激活统计信息,如稀疏度、熵、峰度和频谱偏移。这些数据由层安全评估预测单元(PULSE)分析,PULSE是一个紧凑的检测器,离线训练为分类器集成,并在芯片上实现为小型神经引擎。为实现可解释性和恢复,BARE-AI引入了激活偏移指数(ASI)用于层级故障定位,以及基于z分数的修复方法,将异常权重重置为干净层统计值。在CNN、视觉Transformer和大语言模型上,针对随机、定向、自适应和基于幅度的BFA,BARE-AI在视觉模型上实现了高达98%的检测准确率,在语言模型上实现了74%至95%的检测准确率,将CNN和ViT恢复到接近干净的准确率,并为LLM提供部分恢复。在28nm工艺下综合,该监控基础设施的能耗开销低于3%,面积开销低于4%,延迟开销约为10%,并具有可配置的工作点,可将延迟开销降低至约6%。与纠错码不同,纠错码的冗余度随容忍翻转次数增加而增长,BARE-AI的开销无论攻击强度如何都保持恒定,使其非常适合资源受限的安全关键边缘应用,如自主系统、能源和医疗保健。
英文摘要
Deep Neural Networks (DNNs) are integral to many safety critical systems, yet they remain highly vulnerable to bit-flip attacks (BFAs), where a few memory level perturbations can drastically degrade accuracy. Existing defenses incur significant hardware overhead, depend on retraining, or fail against targeted flips. We propose BARE-AI, a runtime framework that detects, localizes, and mitigates BFAs during inference. BARE-AI introduces AI Performance Counters (APCs), lightweight hardware monitors in the accelerator datapath that capture per-layer activation statistics such as sparsity, entropy, kurtosis, and spectral shift. These are analyzed by the Predictive Unit for Layer Security Evaluation (PULSE), a compact detector trained offline as an ensemble of classifiers and realized on-chip as a small neural engine. For explainability and recovery, BARE-AI introduces an Activation Shift Index (ASI) for layer level fault localization and a z-score based repair that resets anomalous weights toward clean layer statistics. Across CNNs, Vision Transformers, and Large Language Models under random, targeted, adaptive, and magnitude based BFAs, BARE-AI achieves up to 98% detection accuracy on vision models and 74% to 95% on language models, restores near clean accuracy for CNNs and ViTs, and provides partial recovery for LLMs. Synthesized at 28nm, the monitoring infrastructure incurs under 3% energy, under 4% area, and about 10% latency overhead, with a configurable operating point that reduces latency overhead to about 6%. Unlike error correcting codes, whose redundancy grows with the number of tolerated flips, BARE-AI's overhead remains constant regardless of attack strength, making it attractive for resource constrained, safety critical edge applications such as autonomous systems, energy, and healthcare.