Hardware Trojan in FPGA CNN Accelerator

Jing Ye, Yu Hen Hu, Xiaowei Li · 2018

Maliciously manipulating prediction results of Convolutional Neural Network (CNN) is a severe security threat. Previous works studied this threat from the aspects of dataset and model. However, with the increasing developments of CNN accelerators nowadays, the role of hardware in this threat lacks attentions. This paper inserts a hardware Trojan into the convolutional operations of a FPGA CNN accelerator. The experiments on ImageNet show that, with only 0.0051% hardware overhead to the accelerator and 0.000356% modification to an image, the hardware Trojan can be triggered to 100% precisely control the CNN classification result of the image.

Read the paper · More papers on PaperTik