arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

针对嵌入式机器学习的功耗侧信道成员推理攻击

Power Side-Channel Membership Inference Attack on Embedded Machine Learning

Sahan Sanjaya, Prabhat Mishra

arXiv 2610.10909首次发表:更新:

发表机构

University of Florida(佛罗里达大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究提出PSCMIA功耗侧信道成员推理攻击,无需模型输出即可推断嵌入式ML模型的训练数据成员关系,在多数配置下优于仅标签MIA,证明功耗侧信道可暴露成员信息。

AI 中文摘要

成员推理攻击(MIAs)通过判断某个样本是否被用于训练目标模型,威胁机器学习(ML)训练数据的隐私。现有MIAs依赖模型输出,范围从预测概率到预测标签,这一假设对于输出有限或无法访问的设备端ML系统而言可能具有局限性。然而,抑制模型输出并不会消除产生这些输出的数据依赖计算,这些计算仍可通过物理侧信道观测到。我们提出PSCMIA,一种针对嵌入式ML模型的功耗侧信道成员推理攻击,可直接从功耗轨迹推断成员关系,无需预测概率甚至预测标签。我们在多个数据集(MNIST、FMNIST、CIFAR10、CINIC10)、全连接(FC)和卷积神经网络(CNN)架构,以及两个嵌入式平台(STM32F3、XMEGA)上评估PSCMIA。PSCMIA在FC模型上达到高达0.907的ROC-AUC值;对于CNN模型,PSCMIA与基于概率向量的影子MIA之间的ROC-AUC差距为0.006至0.116。在FC和CNN评估中,PSCMIA在16种模型-数据集-硬件配置中的11种上优于仅标签MIA,表明即使通过意外功耗侧信道泄漏无法获取传统模型输出,物理执行仍可暴露成员关系信息。

英文摘要

Membership inference attacks (MIAs) threaten the privacy of machine learning (ML) training data by determining whether a sample was used to train a target model. Existing MIAs rely on model outputs, ranging from prediction probabilities to predicted labels, an assumption that can be restrictive for on-device ML systems with limited or inaccessible outputs. However, suppressing model outputs does not eliminate the data-dependent computations that produce them, which may remain observable through physical side channels. We present PSCMIA, a power side-channel membership inference attack against embedded ML models that can infer membership directly from power traces without requiring prediction probabilities or even the predicted labels. We evaluate PSCMIA across multiple datasets (MNIST, FMNIST, CIFAR10, CINIC10), fully connected (FC) and convolutional neural network (CNN) architectures, and two embedded platforms (STM32F3, XMEGA). PSCMIA achieves ROC-AUC values of up to 0.907 on FC models. For CNN models, the ROC-AUC gap between PSCMIA and probability vector-based shadow MIA ranges from 0.006 to 0.116. Across the FC and CNN evaluations, PSCMIA outperforms label-only MIA in 11 of 16 model-dataset-hardware configurations, demonstrating that physical execution can expose membership information even when conventional model outputs are unavailable through unintended power side-channel leakage.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑