Next up at #enigma2021, Sanghyun Hong will be speaking about "A SOUND MIND IN A VULNERABLE BODY: PRACTICAL HARDWARE ATTACKS ON DEEP LEARNING"
(Hint: speaker is on the

* looks at the robustness in an isolated manner
* doesn't look at the whole ecosystem and how the model is used -- ML models are running in real hardware with real software which has real vulns!

e.g. fault injection attacks, side-channel attacks
* co-location of VMs from different users
* weak attackers with less subtle control
The cloud providers try to secure things, e.g. protections against Rowhammer
... BUT this focuses on the average or best case, not the worst cast!

* negligible effect on the average case accuracy
* but flipping one bit can make significant amount of damage for particular queries
How much damage can a single bit flip cause?

Some strong attackers might be able to hit an "achilles" bit (one that's really going to mess with the model), but weaker attackers are going to hit bits more randomly.

The attacker might want to get their hands on fancy DNNs which are considered trade secrets and proprietary to their creators. They're expensive to make! They need good training data! People want to protect them!

Does this work? Apparently so: they tried it out using a cache side-channel attack and got back the architectures of the fancy DNN back.

More from Lea Kissner
More from Science
@mugecevik is an excellent scientist and a responsible professional. She likely read the paper more carefully than most. She grasped some of its strengths and weaknesses that are not apparent from a cursory glance. Below, I will mention a few points some may have missed.
1/
The paper does NOT evaluate the effect of school closures. Instead it conflates all ‘educational settings' into a single category, which includes universities.
2/
The paper primarily evaluates data from March and April 2020. The article is not particularly clear about this limitation, but the information can be found in the hefty supplementary material.
3/
The authors applied four different regression methods (some fancier than others) to the same data. The outcomes of the different regression models are correlated (enough to reach statistical significance), but they vary a lot. (heat map on the right below).
4/
The effect of individual interventions is extremely difficult to disentangle as the authors stress themselves. There is a very large number of interventions considered and the model was run on 49 countries and 26 US States (and not >200 countries).
5/
1/
I've recently come across a disinformation around evidence relating to school closures and community transmission that's been platformed prominently. This arises from flawed understanding of the data that underlies this evidence, and the methodologies used in these studies. pic.twitter.com/VM7cVKghgj
— Deepti Gurdasani (@dgurdasani1) February 1, 2021
The paper does NOT evaluate the effect of school closures. Instead it conflates all ‘educational settings' into a single category, which includes universities.
2/
The paper primarily evaluates data from March and April 2020. The article is not particularly clear about this limitation, but the information can be found in the hefty supplementary material.
3/

The authors applied four different regression methods (some fancier than others) to the same data. The outcomes of the different regression models are correlated (enough to reach statistical significance), but they vary a lot. (heat map on the right below).
4/

The effect of individual interventions is extremely difficult to disentangle as the authors stress themselves. There is a very large number of interventions considered and the model was run on 49 countries and 26 US States (and not >200 countries).
5/

You May Also Like
Neo-nazi group #PatriotFront held a photo op in #Chicago last weekend & is currently marching around #DC so it's as good time as any to compile a list of their identified members for folks to watch for
Who are these chuds?
Patriot Front broke away from white nationalist org Vanguard America following #unitetheright in #charlottesville after James Alex Fields was seen with a VA shield before driving his car into a crowd, murdering Heather Heyer & injuring dozens of others
Syed Robbie Javid a.k.a. Sayed Robbie Javid or Robbie Javid of Alexandria,
Antoine Bernard Renard (a.k.a. “Charlemagne MD” on Discord) from Rockville, MD.
https://t.co/ykEjdZFDi6
Brandon Troy Higgs, 25, from Reisterstown,
Who are these chuds?
Patriot Front broke away from white nationalist org Vanguard America following #unitetheright in #charlottesville after James Alex Fields was seen with a VA shield before driving his car into a crowd, murdering Heather Heyer & injuring dozens of others
Syed Robbie Javid a.k.a. Sayed Robbie Javid or Robbie Javid of Alexandria,
Happy Monday everyone :-) Let's ring in September by reacquainting ourselves with Virginia neo-Nazi and NSC Dixie affiliate Sayed "Robbie" Javid, now known by "Reform the States". Robbie is an explicitly genocidal neo-Nazi, so lets get to know him a bit better!
— Garfield but Anti-Fascist (@AntifaGarfield) August 31, 2020
CW on this thread pic.twitter.com/3gzxrIo9HD
Antoine Bernard Renard (a.k.a. “Charlemagne MD” on Discord) from Rockville, MD.
https://t.co/ykEjdZFDi6

Brandon Troy Higgs, 25, from Reisterstown,