ai digital background

Security Highlight: TPUXtract – A New Side-Channel Attack on Neural Networks

In the ever-evolving landscape of artificial intelligence, security remains a concern. Today, we highlight an interesting attack called TPUXtract, which can successfully extract the hyperparameters of a neural network by measuring electromagnetic (EM) side channels. The hardware under test is the Google Tensor Processing Unit (TPU), a specialized chip designed to accelerate machine learning tasks.

The hyperparameters targeted by this attack define the structure and configuration of the neural network, including the number of layers, the types of layers, the number of neurons in each layer, and their connections. This attack does not obtain the weights of the model—which are the result of expensive training—but extracting what is essentially the architecture of the network is nonetheless a significant step toward that goal.

The researchers from North Carolina State University observe that the data going through the neural network will proceed through the layers in a sequential order. They also note that the power consumption of a single layer depends on its configuration. The attack works by correlating the electromagnetic emanations of the device with the power profiles of different configurations. One layer at a time, they find the best match and then proceed to the next layer until all parameters are extracted. This layer-by-layer approach significantly reduces the complexity of the attack. An accuracy of 99.91% is claimed.

We observe that the tools and techniques used in this research are not new but rather a continuation of existing attacks in the context of new technology. TPUXtract can extract the hyperparameters of traditional neural networks without requiring any modifications to the model. When the configurations are more complex, as in Transformer-based LLM models, an approach of nullifying the weights of certain layers still allows for full extraction.

To conclude, TPUXtract highlighted an important vulnerability in AI, emphasizing the need for security measures against attacks on specialized hardware.

You can read the full paper here: https://tches.iacr.org/index.php/TCHES/article/view/11923/11782

For more information on how Keysight can help secure your AI-driven systems, contact us at [email protected].

Related Posts

limit
3