• Home
  • Search
  • NNReArch: A Tensor Program Scheduling Framework Against Neural Network Architecture Reverse Engineering
  • Open Access IconOpen Access
  • Cite Icon7
  • https://doi.org/10.1109/fccm53951.2022.9786112Copy DOI Icon

NNReArch: A Tensor Program Scheduling Framework Against Neural Network Architecture Reverse Engineering

  • May 15, 2022
  • Yukui Luo +4 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Architecture reverse engineering has become an emerging attack against deep neural network (DNN) implementations. Several prior works have utilized side-channel leakage to recover the model architecture while the an DNN is executing on a hardware acceleration platform. In this work, we target an open-source deep-learning accelerator, Versatile Tensor Accelerator (VTA), and utilize electromagnetic (EM) side-channel leakage to comprehensively learn the association between DNN architecture configurations and EM emanations. We also consider the holistic system–including the low-level tensor program code of the VTA accelerator on a Xilinx FPGA, and explore the effect of such low-level configurations on the EM leakage. Our study demonstrates that both the optimization and configuration of tensor programs will affect the EM side-channel leakage.Gaining knowledge of the association between low-level tensor program and the EM emanations, we propose NNReArch, a lightweight tensor program scheduling framework against side-channel-based DNN model architecture reverse engineering. Specifically, NNReArch targets reshaping the EM traces of different DNN operators, through scheduling the tensor program execution of the DNN model so as to confuse the adversary. NNReArch is a comprehensive protection framework supporting two modes, a balanced mode that strikes a balance between the DNN model confidentiality and execution performance, and a secure mode where the most secure setting is chosen. We implement and evaluate the proposed framework on the open-source VTA with state-of-the-art DNN architectures. The experimental results demonstrate that NNReArch can efficiently enhance the model architecture security with a small performance overhead. In addition, the proposed obfuscation technique makes reverse engineering of the DNN architecture significantly harder.

Similar Papers
  • Book Chapter
  • Citations1

Handwritten Digit Recognition Using Very Deep Convolutional Neural Network

  • Jan 01, 2022
  • M Dhilsath Fathima +2
  • Research Article
  • Citations10

Transparent and Interpretable State of Health Forecasting of Lithium-Ion Batteries with Deep Learning and Saliency Maps

  • Sep 06, 2023
  • International Journal of Energy Research
  • Friedrich Von Bülow +3
  • Research Article
  • Citations16

NN-Lock : A Lightweight Authorization to Prevent IP Threats of Deep Learning Models

  • Apr 28, 2022
  • ACM Journal on Emerging Technologies in Computing Systems
  • Manaar Alam +3
  • Research Article
  • Citations248

Survey on Deep Neural Networks in Speech and Vision Systems

  • Jul 26, 2020
  • Neurocomputing
  • M Alam +4
  • Conference Article
  • Citations5

Investigating the electromagnetic side channel leakage from a Raspberry Pi

  • Aug 01, 2017
  • Ibraheem Frieslaar +1
  • Conference Article
  • Citations36

On decomposing a deep neural network into modules

  • Nov 07, 2020
  • Rangeet Pan +1
  • Research Article
  • Citations185

An Empirical Study of the Impact of Hyperparameter Tuning and Model Optimization on the Performance Properties of Deep Neural Networks

  • Apr 09, 2022
  • ACM Transactions on Software Engineering and Methodology
  • Lizhi Liao +3
  • Research Article
  • Citations154

Feature extraction and genetic algorithm enhanced adaptive deep neural network for energy consumption prediction in buildings

  • Jun 29, 2020
  • Renewable and Sustainable Energy Reviews
  • X.J Luo +5
  • PDF
  • Research Article

Optimal deep neural network architecture design with improved generalization for data-driven cooling load estimation problem

  • May 02, 2025
  • Neural Computing and Applications
  • Baris Baykant Alagoz +4
  • Conference Article
  • Citations1

Novel Adaptive DNN Partitioning Method Based on Image-Stream Pipeline Inference between the Edge and Cloud

  • May 01, 2022
  • Chenchen Ji +4
  • Research Article
  • Citations5

SSAT: Active Authorization Control and User’s Fingerprint Tracking Framework for DNN IP Protection

  • Oct 29, 2024
  • ACM Transactions on Multimedia Computing, Communications, and Applications
  • Mingfu Xue +5
  • PDF
  • Research Article
  • Citations10

An Adaptive Task Migration Scheduling Approach for Edge‐Cloud Collaborative Inference

  • Jan 01, 2022
  • Wireless Communications and Mobile Computing
  • Boyin Zhang +4
  • PDF
  • Research Article
  • Citations7

Assessment of Therapeutic Responses Using a Deep Neural Network Based on 18F-FDG PET and Blood Inflammatory Markers in Pyogenic Vertebral Osteomyelitis

  • Nov 21, 2022
  • Medicina
  • Hyunkwang Shin +4
  • Research Article
  • Citations52

Deep neural network modeling of unknown partial differential equations in nodal space

  • Oct 15, 2021
  • Journal of Computational Physics
  • Zhen Chen +3
  • Research Article
  • Citations1

Prediction of normalized shear modulus and damping ratio for granular soils over a wide strain range using deep neural network modelling

  • Dec 20, 2024
  • Georisk: Assessment and Management of Risk for Engineered Systems and Geohazards
  • Wei-Qiang Feng +5
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.