Next up at #enigma2021, Sanghyun Hong will be speaking about "A SOUND MIND IN A VULNERABLE BODY: PRACTICAL HARDWARE ATTACKS ON DEEP LEARNING"

(Hint: speaker is on the

In recent years ML models have worked from research labs to production, which makes ML security important. Adversarial ML research studies how to mess with ML
For example by messing with the training data (c.f. Tay which became super-racist super-fast) or by foiling ML models by changing inputs in ways humans can't see.
Prior work considers ML models in a standalone, mathematical way
* looks at the robustness in an isolated manner
* doesn't look at the whole ecosystem and how the model is used -- ML models are running in real hardware with real software which has real vulns!
This talk focuses on hardware-level vulnerabilities. This is particularly interesting because these can break cryptographic guarantees (because those are outside of their threat models)
e.g. fault injection attacks, side-channel attacks
Recent work targets The Cloud
* co-location of VMs from different users
* weak attackers with less subtle control

The cloud providers try to secure things, e.g. protections against Rowhammer
But can you use the weak attacks left after mitigations deployed by cloud compute providers?
DNNs are resilient to numerical perturbations: this is used both to make things more efficient (e.g. pruning) but also in security it's really hard to make accuracy drop

... BUT this focuses on the average or best case, not the worst cast!
What happens when you can mess with the memory at one of these steps?
* negligible effect on the average case accuracy
* but flipping one bit can make significant amount of damage for particular queries

How much damage can a single bit flip cause?
Try it out!
tl;dr in general, one bit flip can really mess with your model! (Looked for the worst bit to flip)
Well, can you use this? There's a lot less control in real life

Some strong attackers might be able to hit an "achilles" bit (one that's really going to mess with the model), but weaker attackers are going to hit bits more randomly.
So they tried it out!
tl;dr running a pretty weak Rowhammer attack is enough to mess with a ML model being trained.
How about side-channel attacks?

The attacker might want to get their hands on fancy DNNs which are considered trade secrets and proprietary to their creators. They're expensive to make! They need good training data! People want to protect them!
Prior work required that the ML-model-trainer uses an off-the-shelf architecture. But people often don't for the fancy models. So what this work does [... if I'm following correctly] is to basically guess from a lot of architecture possibilities and then filter it down
Why is this possible? Because there are regularities in deep-learning calculation.

Does this work? Apparently so: they tried it out using a cache side-channel attack and got back the architectures of the fancy DNN back.
This needs more study
* we need to understand the worst-case ML fails under hardware attack
* don't discount the ability of an attacker with access to a weak hardware attack to cause a disproportionate amount of damage
You can find a writeup of this research at https://t.co/qUx8nAHW52

[end of talk]

More from Lea Kissner

More from Science

1. I find it remarkable that some medics and scientists aren’t raising their voices to make children as safe as possible. The comment about children being less infectious than adults is unsupported by evidence.


2. @c_drosten has talked about this extensively and @dgurdasani1 and @DrZoeHyde have repeatedly pointed out flaws in the studies which have purported to show this. Now for the other assertion: children are very rarely ill with COVID19.

3. Children seem to suffer less with acute illness, but we have no idea of the long-term impact of infection. We do know #LongCovid affects some children. @LongCovidKids now speaks for 1,500 children struggling with a wide range of long-term symptoms.

4. 1,500 children whose parents found a small campaign group. How many more are out there? We don’t know. ONS data suggests there might be many, but the issue hasn’t been studied sufficiently well or long enough for a definitive answer.

5. Some people have talked about #COVID19 being this generation’s Polio. According to US CDC, Polio resulted in inapparent infection in more than 99% of people. Severe disease occurred in a tiny fraction of those infected. Source:
An interesting thing about carp is that they can go into anoxic hibernation and switch to an anaerobic metabolism based on converting glycogen to ethanol.

The waste ethanol is diffused out the gills

https://t.co/V3D1umHf04

Carp can switch over to an anaerobic metabolism and quietly exhale booze until the situation gets better.

They basically evolved the same metabolic pathway as yeast, independently.

In theory, if you spent a few thousand years breeding carp for it, you could use them to make booze.

They'd be enormous, almost entirely glycogen deposits with a fish added as an afterthought.

The really interesting thing about anaerobic carp, is that they can go 4-5 months without oxygen by relying on liver glycogen.

You, a human, have only about 100 grams of glycogen in your liver, about 400 more grams in your skeletal muscles. Call it 500 grams total.

In humans, glycogen is also burned for energy. This is where the marathon runner's bonk comes from: you only have about 2,000 calories worth, and running a marathon burns those 2,000 calories.
JUST ONE PERSON—UK 🇬🇧 scientists think one immunocompromised person who cleared virus slowly & only partially wiped out an infection, leaving behind genetically-hardier viruses that rebound & learn how to survive better. That’s likely how #B117 started. 🧵 https://t.co/bMMjM8Hiuz


2) The leading hypothesis is that the new variant evolved within just one person, chronically infected with the virus for so long it was able to evolve into a new, more infectious form.

same thing happened in Boston in another immunocompromised person that was sick for 155 days.

3) What happened in Boston with one 45 year old man who was highly infectious for 155 days straight before he died... is exactly what scientists think happened in Kent, England that gave rise to #B117.


4) Doctors were shocked to find virus has evolved many different forms inside of this one immunocompromised man. 20 new mutations in one virus, akin to the #B117. This is possibly how #B1351 in South Africa 🇿🇦 and #P1 in Brazil 🇧🇷 also evolved.


5) “On its own, the appearance of a new variant in genomic databases doesn’t tell us much. “That’s just one genome amongst thousands every week. It wouldn’t necessarily stick out,” says Oliver Pybus, a professor of evolution and infectious disease at Oxford.

You May Also Like