Skip to main navigation Skip to search Skip to main content

Time to Leak: Cross-Device Timing Attack On Edge Deep Learning Accelerator

  • Yoo-Seung Won
  • , Soham Chatterjee
  • , Dirmanto Jap
  • , Shivam Bhasin
  • , Arindam Basu

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

Abstract

Edge deep learning accelerators are optimised hardware to enable efficient inference on the edge. The models deployed on these accelerators are often proprietary and thus sensitive for commercial and privacy reasons. In this paper, we demonstrate practical vulnerability of deployed deep learning models to timing side-channel attacks. By measuring the execution time of the inference, the adversary can determine and reconstruct the model from a known family of well known deep learning model and then use available techniques to recover remaining hyperparameters. The vulnerability is validated on Intel Compute Stick 2 for VGG and ResNet family of models. Moreover, the presented attack is quite devastating as it can be performed in a cross-device setting, where adversary profiles constructed on a legally own device can be used to exploit the victim device with a single query and still can achieve near perfect success rate.
Original languageEnglish
Title of host publication2021 International Conference on Electronics, Information, and Communication (ICEIC)
PublisherIEEE
ISBN (Electronic)978-1-7281-9161-4
ISBN (Print)978-1-7281-9162-1
DOIs
Publication statusPublished - Jan 2021
Externally publishedYes
Event20th International Conference on Electronics, Information, and Communication(ICEIC 2021) - Jeju Shinhwa World and virtual, Jeju, Korea, Republic of
Duration: 31 Jan 20213 Feb 2021
http://iceic.org/2021/

Publication series

NameInternational Conference on Electronics, Information, and Communication, ICEIC

Conference

Conference20th International Conference on Electronics, Information, and Communication(ICEIC 2021)
PlaceKorea, Republic of
CityJeju
Period31/01/213/02/21
Internet address

Research Keywords

  • High performance edge machine learning processing unit
  • Intel Compute Stick 2
  • Timing analysis

Fingerprint

Dive into the research topics of 'Time to Leak: Cross-Device Timing Attack On Edge Deep Learning Accelerator'. Together they form a unique fingerprint.

Cite this