DeepFreeze: Cold Boot Attacks and High Fidelity Model Recovery on Commercial EdgeML Device

Yoo-Seung Won, Soham Chatterjee, Dirmanto Jap, Arindam Basu, Shivam Bhasin

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

11 Citations (Scopus)

Abstract

EdgeML accelerators like Intel Neural Compute Stick 2 (NCS) can enable efficient edge-based inference with complex pre-trained models. The models are loaded in the host (like Raspberry Pi) and then transferred to NCS for inference. In this paper, we demonstrate practical and low-cost cold boot based model recovery attacks on NCS to recover the model architecture and weights, loaded from the Raspberry Pi. The architecture is recovered with 100% success and weights with an error rate of 0.04%. The recovered model reports maximum accuracy loss of 0.5% as compared to original model and allows high fidelity transfer of adversarial examples. We further extend our study to other cold boot attack setups reported in the literature with higher error rates leading to accuracy loss as high as 70%. We then propose a methodology based on knowledge distillation to correct the erroneous weights in recovered model, even without access to original training data. The proposed attack remains unaffected by the model encryption features of the OpenVINO and NCS framework.
Original languageEnglish
Title of host publication2021 IEEE/ACM International Conference on Computer-Aided Design (ICCAD)
PublisherIEEE
Number of pages9
Edition40th
ISBN (Electronic)9781665445078
ISBN (Print)9781665445085
DOIs
Publication statusPublished - 2021
Event40th IEEE/ACM International Conference on Computer-Aided Design (ICCAD 2021) - Munich, Germany
Duration: 1 Nov 20214 Nov 2021

Publication series

NameIEEE/ACM International Conference on Computer-Aided Design, Digest of Technical Papers, ICCAD
ISSN (Print)1933-7760
ISSN (Electronic)1558-2434

Conference

Conference40th IEEE/ACM International Conference on Computer-Aided Design (ICCAD 2021)
PlaceGermany
CityMunich
Period1/11/214/11/21

Research Keywords

  • Cold Boot Attack
  • EdgeML
  • Intel Neural Compute Stick 2
  • Model Recovery

Fingerprint

Dive into the research topics of 'DeepFreeze: Cold Boot Attacks and High Fidelity Model Recovery on Commercial EdgeML Device'. Together they form a unique fingerprint.

Cite this