arrow
Return

Mind control attack: Undermining deep learning with GPU memory exploitation

delete2021-03-01
delete7
delete
OA
AI
S
Sang-Ok Park
O
Ohmin Kwon
Y
Yonggon Kim
S
Sang Kil *
H
Hyunsoo Yoon
DOI:10.1016/j.cose.2020.102115delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Modern deep learning frameworks rely heavily on GPUs to accelerate the computation. However, the security implication of GPU device memory exploitation on deep learning frameworks has been largely neglected. In this paper, we argue that GPU device memory manipulation is a novel attack vector against deep learning systems. We present a novel attack method leveraging the attack vector, which makes deep learning predictions no longer different from random guessing by degrading the accuracy of the predictions. To the best of our knowledge, we are the first to show a practical attack that directly exploits deep learning frameworks through GPU memory manipulation. We confirmed that our attack works on three popular deep learning frameworks, TensorFlow, CNTK, and Caffe, running on CUDA. Finally, we propose potential defense mechanisms against our attack, and discuss concerns of GPU memory safety. (c) 2020 The Author(s). Published by Elsevier Ltd. This is an open access article under the CC BY license (http://creativecommons.org/licenses/by/4.0/)
Keywords:
Graphics process unit security
GPU memory exploit
Deep learning security
Reverse engineering
Compute unified device architecture
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

No organization information available