NDSS 2025 – BitShield: Defending Against Bit-Flip Attacks On DNN Executables
好的,我现在需要帮用户总结一篇关于DNN攻击面的文章,控制在100字以内。首先,我得通读整篇文章,抓住主要信息。 文章主要讲的是BitShield,一种防御DNN执行文件免受比特翻转攻击的方法。比特翻转攻击比如Rowhammer技术,可以改变DNN的预测结果,甚至完全破坏其智能。现有的防御措施针对的是DL框架中的模型,但对编译成独立可执行文件的DNN无效。 BitShield通过检测数据和代码部分的比特翻转攻击,利用语义完整性检查来防御。它还融合了代码校验和到DNN的语义中,增强了自身的抗攻击能力。集成到Amazon TVM中,兼容现有编译优化,并且能主动检测攻击,保护全精度DNN,效果显著。 现在我需要把这些要点浓缩到100字以内。确保涵盖BitShield的作用、防御机制、集成情况以及效果。 </think> 文章介绍了一种名为BitShield的防御方法,用于保护深度神经网络(DNN)执行文件免受比特翻转攻击(如Rowhammer技术)。该方法通过检测数据和代码部分的比特翻转攻击,并结合语义完整性检查和代码校验和机制,提供高效且通用的防护。实验表明其具有高缓解率和低性能开销。 2026-1-19 16:0:0 Author: securityboulevard.com(查看原文) 阅读量:0 收藏

Session 9B: DNN Attack Surfaces

Authors, Creators & Presenters: Yanzuo Chen (The Hong Kong University of Science and Technology), Yuanyuan Yuan (The Hong Kong University of Science and Technology), Zhibo Liu (The Hong Kong University of Science and Technology), Sihang Hu (Huawei Technologies), Tianxiang Li (Huawei Technologies), Shuai Wang (The Hong Kong University of Science and Technology)
PAPER
BitShield: Defending Against Bit-Flip Attacks on DNN Executables
Recent research has demonstrated the severity and prevalence of bit-flip attacks (BFAs; e.g., with Rowhammer techniques) on deep neural networks (DNNs). BFAs can manipulate DNN prediction and completely deplete DNN intelligence, and can be launched against both DNNs running on deep learning (DL) frameworks like PyTorch, as well as those compiled into standalone executables by DL compilers. While BFA defenses have been proposed for models on DL frameworks, we find them incapable of protecting DNN executables due to the new attack vectors on these executables. This paper proposes the first defense against BFA for DNN executables. We first present a motivating study to demonstrate the fragility and unique attack surfaces of DNN executables. Specifically, attackers can flip bits in the section to alter the computation logic of DNN executables and consequently manipulate DNN predictions; previous defenses guarding model weights can also be easily evaded when implemented in DNN executables. Subsequently, we propose BitShield, a full-fledged defense that detects BFAs targeting both data and sections in DNN executables. We novelly model BFA on DNN executables as a process to corrupt their semantics, and base BitShield on semantic integrity checks. Moreover, by deliberately fusing code checksum routines into a DNN’s semantics, we make BitShield highly resilient against BFAs targeting itself. BitShield is integrated in a popular DL compiler (Amazon TVM) and is compatible with all existing compilation and optimization passes. Unlike prior defenses, BitShield is designed to protect more vulnerable full-precision DNNs and does not assume specific attack methods, exhibiting high generality. BitShield also proactively detects ongoing BFA attempts instead of passively hardening DNNs. Evaluations show that BitShield provides strong protection against BFAs (average mitigation rate 97.51%) with low performance overhead (2.47% on average) even when faced with fully white-box, powerful attackers.
ABOUT NDSS
The Network and Distributed System Security Symposium (NDSS) fosters information exchange among researchers and practitioners of network and distributed system security. The target audience includes those interested in practical aspects of network and distributed system security, with a focus on actual system design and implementation. A major goal is to encourage and enable the Internet community to apply, deploy, and advance the state of available security technologies.

Our thanks to the Network and Distributed System Security (NDSS) Symposium for publishing their Creators, Authors and Presenter’s superb NDSS Symposium 2025 Conference content on the Organizations’ YouTube Channel.

Permalink

*** This is a Security Bloggers Network syndicated blog from Infosecurity.US authored by Marc Handelman. Read the original post at: https://www.youtube-nocookie.com/embed/Xgy0z5Ek6tI?si=lJcArFqxHIgT3n5z


文章来源: https://securityboulevard.com/2026/01/ndss-2025-bitshield-defending-against-bit-flip-attacks-on-dnn-executables/
如有侵权请联系:admin#unsafe.sh