0% Complete
Home
/
15th International Conference on Computer and Knowledge Engineering
Towards Low-Overhead Mitigation of Trojan Bit-Flip Attacks on DNNs via Causal Inference
Authors :
Bahare Gholami
1
Mohsen Raji
2
1- دانشگاه شیراز
2- دانشگاه شیراز
Keywords :
Trojan Bit-Flip Attack،Lightweight Defense Mechanism،Causal Inference
Abstract :
Trojan bit-flip attacks pose a significant threat to the security of deep neural networks (DNNs), particularly in safety-critical applications. Existing defense mechanisms often incur substantial memory overhead, limiting their applicability in resource-constrained environments. Identifying the most vulnerable parts of a DNN is the key to designing efficient defense mechanisms against Trojan bit-flip attacks. In this paper, a low overhead defense mechanism for Trojan bit-flip attacks on DNNs is proposed. To identify the most influential layers within a DNN that can be the targets of attackers, the proposed approach leverages causal inference, a statistical and analytical framework for modeling the causal effects of interventions or changes in one variable (e.g., a Trojan bit-flip attack on the parameters of a DNN) on another (e.g., model predictions). By performing a layer-wise causal analysis, the method ranks layers according to their contribution to the model predictions and protects only those layers, rather than protecting all layers as in previous work. Evaluations on ResNet-32 using the CIFAR-10 dataset indicate that, relative to the state-of-the-art, the proposed method reduces the additional memory overhead by more than 3.5×. Specifically, it increases the base model size from 1.77 MB to 3.43 MB (an overhead of 1.66 MB), whereas the state-of-the art method increases it to 7.64 MB (an overhead of 5.87 MB). While preserving high model accuracy (89.64%) and achieving a similar reduction in attack success rate, these results highlight the effectiveness of the proposed causality-guided selective protection in improving DNN robustness with minimal overhead.
Papers List
List of archived papers
SASIAF, An Scalable Accelerator For Seismic Imaging on Amazon AWS FPGAs
Mostafa Koraei - S.Omid Fatemi
Enhanced Melanoma Detection: An Improved Deformable DETR Model with Efficient Channel Attention
Amirreza Rouhbakhshmeghrazi - Shayan Nalbandian - Sheida Shadman - Mohammad Reza Hassannezhad - Shuyuan Yang - Bo Li
An intelligent linguistic error detection approach to automated diagnosis of Dyslexia disorder in Persian speaking children
Fatemeh Asghari - Mahsa Khorasani - Mohsen Kahani - Seyed Amir Amin Yazdi - Mahdi Arkhodi Ghalenoei
Optimizing the controller placement problem in SDN with uncertain parameters with robust optimization
Mohammad Kazemi - AhmadReza Montazerolghaem
Artificial Intelligence applications addressing different aspects of the Covid-19 crisis and key technological solutions for future epidemics control
Nadia Khalili - Hojatollah Hamidi
U-Net-based Hippocampus Segmentation Models: Advancements and Challenges
Laya Mahmoudi - Majid Abbasi - Abolfazl Kanani
Two-step thermal-aware routing algorithm in 3D NoC
Majid Nezarat - Masoume Momeni
Time Series Analysis by Bi-GRU for Forecasting Bitcoin Trends based on Sentiment Analysis
Fatemeh Saadatmand - Mohammad Ali Zare Chahoki
Impossible differential and zero-correlatin linear cryptanalysis of Marx, Marx2, Chaskey andSpeck32
Mahshid Saberi - Nasour Bagheri - Sadegh Sadeghi
A Novel Approach for Image-Text Matching Cross-Modal Space Learning
Amirreza Ebrahimi - Mohammad Javad Parseh - Pejman Rasti
more
Samin Hamayesh - Version 44.5.0