Hardware-assisted Neural Network IP Protection using Non-malicious Backdoor and Selective Weight Obfuscation

Mahdieh Grailoo, Uljana Reinsalu, Mairo Leier, Tooraj Nikoubin · 2022

Neural networks (NNs) are already deployed in hardware today, becoming valuable intellectual property (IP) as many hours are invested in their training and optimization. Therefore, attackers may be interested in copying, reverse engineering, or even modifying this IP. The current practices in hardware obfuscation, including the widely studied LL technique, are insufficient to protect the actual IP of a well-trained NN: its weights. Simply hiding the weights behind a key-based scheme is inefficient (resource-hungry) and inadequate (attackers can exploit knowledge distillation). This paper proposes a two-step technique that addresses these issues: the obfuscation overhead is kept under control by applying only selective weight obfuscation, while distillation-based attack is prevented by prediction poisoning using non-malicious backdoor such that an attacker with access to an oracle cannot accurately train his/her model. This is the first work to consider such a poisoning approach in HW-implemented NNs. The poisoning occurs in score part before SoftMax. In the score poisoning, the accuracy and prediction distribution are maintained without disturbing the functionality or incurring high overheads. Finally, we elaborate a threat model which highlights the difference between random logic obfuscation and the obfuscation of NN IP. Based on this threat model, our security analysis shows that the proposed technique successfully and significantly reduces the accuracy of the stolen NN model on various representative datasets. Finally, we highlight that our proposed approach is flexible and does not require manipulation of the NN toolchain, and is coded in a flexible high-level language (e.g., C++).

Read the paper · More papers on PaperTik