SecureVolt: Enhancing Deep Neural Networks Security via Undervolting

Md Shohidul Islam, Ihsen Alouani, Khaled N. Khasawneh · IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems · 2023

Deep neural networks (DNNs) are shown to be vulnerable to adversarial attacks; carefully crafted additive noise that undermines DNNs integrity. Previously proposed defenses against these attacks require substantial overheads, making it challenging to deploy these solutions in power and computational resource-constrained devices, such as embedded systems and the Edge. In this article, we explore the use of voltage over-scaling (VOS) as a lightweight and efficient defense against adversarial attacks. Specifically, we exploit the stochastic timing violations of VOS within computing elements to implement a moving-target defense for DNNs. Our experimental results demonstrate that VOS guarantees effective defense against different attack methods, does not require any software/hardware modifications, and offers a by-product reduction in power consumption. We propose a space exploration to identify a possible tradeoff between robustness, accuracy, and power gains. Furthermore, we observe the behavior of models’ epistemic uncertainty under variable undervolting aggressiveness. Our experiments show that model uncertainty analysis is coherent with the observation in our robustness/accuracy exploration.

Read the paper · More papers on PaperTik