CAREER: Securing Reconfigurable Hardware Accelerator for Machine Learning: Threats and Defenses
职业:保护用于机器学习的可重新配置硬件加速器:威胁与防御
基本信息
- 批准号:2239672
- 负责人:
- 金额:$ 59.9万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2023
- 资助国家:美国
- 起止时间:2023-10-01 至 2028-09-30
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
The proliferation of Machine Learning (ML)-enabled applications has fueled a pressing demand for high-performance computing hardware. As a reconfigurable device offering high power efficiency and low overhead, the field programmable gate array (FPGA)-based ML acceleration systems (FPGA-ML) have become the workhorse of ML computing and inference to support many applications in critical domains, including aerospace, defense, and autonomous driving. Although promising, the growing trend of FPGA-ML accelerators also presents new targets for adversaries to attack. This CAREER project will holistically investigate the FPGA-ML system security and integrate the scientific outcomes with educational activities. The research outcome of this project will generate new security components to the emerging FPGA-ML development toolchains and metrics to evaluate the security of real-world products built on these systems, as well as enable technology transfer of research results to the industry practice. This project contains a significant educational component and will attract K-12 students to pursue a STEM education and nurture and cultivate undergraduate and graduate students from underrepresented groups to engage in this open research field. This CAREER project systematically investigates the threats and defenses of the FPGA-ML systems. The scientific outcomes will significantly enrich the traditional works that mainly consider ML security from an algorithm aspect and neglect implementation peculiarities. There are three complementary research thrusts to investigate: (1) Run-time FPGA-ML integrity by studying the impacts of run-time disruption on FPGA-ML acceleration engine for different malicious objectives; (2) Design-time confidentiality by attacking state-of-the-art FPGA-ML systems to explore the potential attack surface; (3) Efficient and scalable defense solutions by characterizing the root causes of both run-time and design-time vulnerabilities of the FPGA-ML systems and developing cross-layer defense strategies at the circuit- and system-level to suit different application scenarios. The proof-of-principles will be applied in designing and prototyping secure FPGA-ML acceleration systems, and the cross-domain knowledge learned from this project will complement the broader AI-enabled cyberspace.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
支持机器学习 (ML) 的应用程序的激增推动了对高性能计算硬件的迫切需求。作为一种具有高功效和低开销的可重构设备,基于现场可编程门阵列 (FPGA) 的机器学习加速系统 (FPGA-ML) 已成为机器学习计算和推理的主力,支持关键领域的许多应用,包括航空航天、国防、自动驾驶。尽管前景光明,但 FPGA-ML 加速器的增长趋势也为对手提供了新的攻击目标。该职业项目将全面研究 FPGA-ML 系统安全性,并将科学成果与教育活动相结合。该项目的研究成果将为新兴的 FPGA-ML 开发工具链和指标生成新的安全组件,以评估基于这些系统构建的实际产品的安全性,并实现研究成果向行业实践的技术转移。该项目包含重要的教育内容,将吸引 K-12 学生接受 STEM 教育,并培育和培养来自弱势群体的本科生和研究生参与这一开放研究领域。该职业项目系统地研究了 FPGA-ML 系统的威胁和防御。这些科学成果将极大地丰富主要从算法方面考虑机器学习安全性而忽视实现特性的传统工作。需要研究三个互补的研究重点:(1)运行时 FPGA-ML 完整性,通过研究运行时中断对针对不同恶意目标的 FPGA-ML 加速引擎的影响; (2) 通过攻击最先进的 FPGA-ML 系统来探索潜在的攻击面,从而实现设计时机密性; (3) 高效且可扩展的防御解决方案,通过表征 FPGA-ML 系统运行时和设计时漏洞的根本原因,并在电路和系统级别开发跨层防御策略以适应不同的应用场景。原理验证将应用于安全 FPGA-ML 加速系统的设计和原型设计,从该项目中学到的跨领域知识将补充更广泛的人工智能网络空间。该奖项反映了 NSF 的法定使命,并被认为是值得的通过使用基金会的智力优势和更广泛的影响审查标准进行评估来获得支持。
项目成果
期刊论文数量(7)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
MirrorNet: A TEE-Friendly Framework for Secure On-Device DNN Inference
- DOI:10.1109/iccad57390.2023.10323746
- 发表时间:2023-10
- 期刊:
- 影响因子:0
- 作者:Ziyu Liu;Yukui Luo;Shijin Duan;Tong Zhou;Xiaolin Xu
- 通讯作者:Ziyu Liu;Yukui Luo;Shijin Duan;Tong Zhou;Xiaolin Xu
AutoReP: Automatic ReLU Replacement for Fast Private Network Inference
- DOI:10.1109/iccv51070.2023.00478
- 发表时间:2023-08
- 期刊:
- 影响因子:0
- 作者:Hongwu Peng;Shaoyi Huang;Tong Zhou;Yukui Luo;Chenghong Wang;Zigeng Wang;Jiahui Zhao;Xiaowei Xie;Ang Li;Tony Geng;Kaleel Mahmood;Wujie Wen;Xiaolin Xu;Caiwen Ding
- 通讯作者:Hongwu Peng;Shaoyi Huang;Tong Zhou;Yukui Luo;Chenghong Wang;Zigeng Wang;Jiahui Zhao;Xiaowei Xie;Ang Li;Tony Geng;Kaleel Mahmood;Wujie Wen;Xiaolin Xu;Caiwen Ding
HammerDodger: A Lightweight Defense Framework against RowHammer Attack on DNNs
- DOI:10.1109/dac56929.2023.10247671
- 发表时间:2023-07
- 期刊:
- 影响因子:0
- 作者:Gongye Cheng;Yukui Luo;Xiaolin Xu;Yunsi Fei
- 通讯作者:Gongye Cheng;Yukui Luo;Xiaolin Xu;Yunsi Fei
PASNet: Polynomial Architecture Search Framework for Two-party Computation-based Secure Neural Network Deployment
- DOI:10.1109/dac56929.2023.10247663
- 发表时间:2023-06
- 期刊:
- 影响因子:0
- 作者:Hongwu Peng;Shangli Zhou;Yukui Luo;Nuo Xu;Shijin Duan;Ran Ran-Ran;Jiahui Zhao;Chenghong Wang;Tong Geng;Wujie Wen;Xiaolin Xu;Caiwen Ding
- 通讯作者:Hongwu Peng;Shangli Zhou;Yukui Luo;Nuo Xu;Shijin Duan;Ran Ran-Ran;Jiahui Zhao;Chenghong Wang;Tong Geng;Wujie Wen;Xiaolin Xu;Caiwen Ding
NNSplitter: An Active Defense Solution for DNN Model via Automated Weight Obfuscation
NNSplitter:通过自动权重混淆的 DNN 模型主动防御解决方案
- DOI:
- 发表时间:2023
- 期刊:
- 影响因子:0
- 作者:Zhou, Tong;Ren, Shaolei;Xu, Xiaolin
- 通讯作者:Xu, Xiaolin
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Xiaolin Xu其他文献
The Role of Community-Based Rehabilitation and Community-Based Inclusive Development in Facilitating Access to Justice for Persons with Disabilities Globally
社区康复和社区包容性发展在促进全球残疾人诉诸司法方面的作用
- DOI:
10.13169/intljofdissocjus.3.3.0004 - 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
Heather Michelle Aldersey;Xiaolin Xu;Venkatesh Balakrishna;Maholo Carolyne Sserunkuma;Alaa Sebeh;Zambrano Olmedo;Reshma Parvin Nuri;Ansha Nega Ahmed - 通讯作者:
Ansha Nega Ahmed
Research on a Lightweight Method for Maize Seed Quality Detection Based on Improved YOLOv8
基于改进YOLOv8的轻量级玉米种子质量检测方法研究
- DOI:
10.1109/access.2024.3365559 - 发表时间:
2024 - 期刊:
- 影响因子:3.9
- 作者:
Siqi Niu;Xiaolin Xu;Ao Liang;Yuliang Yun;Li Li;Fengqi Hao;Jinqiang Bai;Dexin Ma - 通讯作者:
Dexin Ma
Thermodynamic Modelling of Buried Transformer Substations for Dynamic Loading Capability Assessment Considering Underground Heat Accumulative Effect
考虑地下蓄热效应的地埋变电站动载能力评估热力学模型
- DOI:
10.1016/j.ijepes.2020.106153 - 发表时间:
2020-10 - 期刊:
- 影响因子:5.2
- 作者:
Bin Zhou;Xiaolin Xu;Siu Wing Or;Canbing Li;Qiuwei Wu;Cong Zhang;Wenfang Li - 通讯作者:
Wenfang Li
URMG: Enhanced CBMG-Based Method for Automatically Testing Web Applications in the Cloud
URMG:基于 CBMG 的增强型云中 Web 应用程序自动测试方法
- DOI:
10.1109/tst.2014.6733209 - 发表时间:
2014-02 - 期刊:
- 影响因子:6.6
- 作者:
Xiaolin Xu;Hai Jin;Song Wu;Lixiang Tang;Yihong Wang - 通讯作者:
Yihong Wang
The Effect of Aromatase on the Reproductive Function of Obese
芳香酶对肥胖者生殖功能的影响
- DOI:
- 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Xiaolin Xu;Mingqi Sun;Jifeng Ye;D;an Luo;Xiaohui Su;Dongmei Zheng;Li Feng;Ling Gao;Chunxiao Yu;Qingbo Guan - 通讯作者:
Qingbo Guan
Xiaolin Xu的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Xiaolin Xu', 18)}}的其他基金
Travel: NSF Student Travel Grant for 2023 New England Hardware Security Day (NEHWS2023)
旅行:2023 年新英格兰硬件安全日 NSF 学生旅行补助金 (NEHWS2023)
- 批准号:
2315830 - 财政年份:2023
- 资助金额:
$ 59.9万 - 项目类别:
Standard Grant
CICI:TCR:CAREFREE:Cloud infrAstructure ResiliencE of the Future foR tEstbeds, accelerators and nEtworks
CICI:TCR:CAREFREE:未来测试床、加速器和网络的云基础设施弹性
- 批准号:
2319962 - 财政年份:2023
- 资助金额:
$ 59.9万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Medium: Accelerating Privacy-Preserving Machine Learning as a Service: From Algorithm to Hardware
协作研究:SaTC:核心:中:加速保护隐私的机器学习即服务:从算法到硬件
- 批准号:
2247892 - 财政年份:2023
- 资助金额:
$ 59.9万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Securing Brain-inspired Hyperdimensional Computing against Design-time and Run-time Attacks for Edge Devices
协作研究:SaTC:核心:小型:保护类脑超维计算免受边缘设备的设计时和运行时攻击
- 批准号:
2326597 - 财政年份:2023
- 资助金额:
$ 59.9万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Secure and Robust Machine Learning in Multi-Tenant Cloud FPGA
协作研究:SaTC:CORE:小型:多租户云 FPGA 中安全且稳健的机器学习
- 批准号:
2153690 - 财政年份:2022
- 资助金额:
$ 59.9万 - 项目类别:
Standard Grant
SaTC: EDU: Collaborative: Bolstering UAV Cybersecurity Education through Curriculum Development with Hands-on Laboratory Framework
SaTC:EDU:协作:通过实践实验室框架的课程开发来加强无人机网络安全教育
- 批准号:
1955337 - 财政年份:2020
- 资助金额:
$ 59.9万 - 项目类别:
Standard Grant
SaTC: EDU: Collaborative: Bolstering UAV Cybersecurity Education through Curriculum Development with Hands-on Laboratory Framework
SaTC:EDU:协作:通过实践实验室框架的课程开发来加强无人机网络安全教育
- 批准号:
2043183 - 财政年份:2020
- 资助金额:
$ 59.9万 - 项目类别:
Standard Grant
相似国自然基金
基于固定路线营运车辆动力响应的桥梁快速巡检与状态评估方法研究
- 批准号:52378145
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
基于自助重采样的GNSS整周模糊度固定和检验优化方法
- 批准号:42374030
- 批准年份:2023
- 资助金额:52 万元
- 项目类别:面上项目
水稻根表铁膜硫还原耦合镉固定的微生物过程及调控机制
- 批准号:42307043
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
多层网络固定时间层间同步的优化控制方法研究
- 批准号:62303161
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
活性电极-微生物界面介导的水处理过程CO2再固定的效应及机制
- 批准号:52370033
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
相似海外基金
生物学的窒素固定微生物群の電気化学的活性促進によるアンモニア生成技術の開発
生物固氮微生物电化学活化制氨技术开发
- 批准号:
24K15359 - 财政年份:2024
- 资助金额:
$ 59.9万 - 项目类别:
Grant-in-Aid for Scientific Research (C)
Securing the Future: Inclusive Cybersecurity Education for All
确保未来:全民包容性网络安全教育
- 批准号:
2350448 - 财政年份:2024
- 资助金额:
$ 59.9万 - 项目类别:
Standard Grant
CAREER: Securing Next-Generation Transportation Infrastructure: A Traffic Engineering Perspective
职业:保护下一代交通基础设施:交通工程视角
- 批准号:
2339753 - 财政年份:2024
- 资助金额:
$ 59.9万 - 项目类别:
Standard Grant
遺伝子改変マウスと未固定遺体を用いた動脈硬化の新規の病態解明と治療法の開発
利用转基因小鼠和未固定尸体阐明动脉硬化的新病理学并开发治疗方法
- 批准号:
23K24330 - 财政年份:2024
- 资助金额:
$ 59.9万 - 项目类别:
Grant-in-Aid for Scientific Research (B)
過渡電界制御振動励起プラズマによる高効率プラズマ窒素固定の基盤確立
建立瞬态电场控制振动激发等离子体高效等离子体固氮基础
- 批准号:
23K25861 - 财政年份:2024
- 资助金额:
$ 59.9万 - 项目类别:
Grant-in-Aid for Scientific Research (B)