The Limits of SEMA on Distinguishing Similar Activation Functions of Embedded Deep Neural Networks

被引:3
|
作者
Takatoi, Go [1 ]
Sugawara, Takeshi [1 ]
Sakiyama, Kazuo [1 ]
Hara-Azumi, Yuko [2 ]
Li, Yang [1 ]
机构
[1] Univ Electrocommun, Dept Informat, 1-5-1 Chofugaoka, Chofu, Tokyo 1828585, Japan
[2] Tokyo Inst Technol, Dept Informat & Commun Engn, Meguro Ku, 2-12-1 Ookayama, Tokyo 1528550, Japan
来源
APPLIED SCIENCES-BASEL | 2022年 / 12卷 / 09期
关键词
machine learning; deep learning; side-channel; activation function; SEMA;
D O I
10.3390/app12094135
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Artificial intelligence (AI) is progressing rapidly, and in this trend, edge AI has been researched intensively. However, much less work has been performed around the security of edge AI. Machine learning models are a mass of intellectual property, and an optimized network is very valuable. Trained machine learning models need to be black boxes as well because they may give away information about the training data to the outside world. As selecting the appropriate activation functions to enable fast training of accurate deep neural networks is an active area of research, it is important to conceal the information of the activation functions used in a neural network architecture as well. There has been research on the use of physical attacks such as the side-channel attack (SCA) in areas other than cryptography. The SCA is highly effective against edge artificial intelligence due to its property of the device computing close to the user. We studied a previously proposed method to retrieve the activation functions of a black box neural network implemented on an edge device by using simple electromagnetic analysis (SEMA) and improved the signal processing procedure for further noisy measurements. The SEMA attack identifies activation functions by directly observing distinctive electromagnetic (EM) traces that correspond to the operations in the activation function. This method requires few executions and inputs and also has little implementation dependency on the activation functions. We distinguished eight similar activation functions with EM measurements and examined the versatility and limits of this attack. In this work, the machine learning architecture is a multilayer perceptron, evaluated on an Arduino Uno.
引用
收藏
页数:20
相关论文
共 50 条
  • [41] Learning Activation Functions for Sparse Neural Networks
    Loni, Mohammad
    Mohan, Aditya
    Asadi, Mehdi
    Lindauer, Marius
    INTERNATIONAL CONFERENCE ON AUTOMATED MACHINE LEARNING, VOL 224, 2023, 224
  • [42] Survey on Activation Functions for Optical Neural Networks
    Destras, Oceane
    Le Beux, Sebastien
    de Magalhaes, Felipe Gohring
    Nicolescu, Gabriela
    ACM COMPUTING SURVEYS, 2024, 56 (02)
  • [43] Fractional Adaptation of Activation Functions In Neural Networks
    Zamora Esquivel, Julio
    Cruz Vargas, Jesus Adan
    Lopez-Meyer, Paulo
    Cordourier Maruri, Hector Alfonso
    Camacho Perez, Jose Rodrigo
    Tickoo, Omesh
    2020 25TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION (ICPR), 2021, : 7544 - 7550
  • [44] Bicomplex Neural Networks with Hypergeometric Activation Functions
    Vieira, Nelson
    ADVANCES IN APPLIED CLIFFORD ALGEBRAS, 2023, 33 (02)
  • [45] Multistability of Neural Networks with a Class of Activation Functions
    Wang, Lili
    Lu, Wenlian
    Chen, Tianping
    ADVANCES IN NEURAL NETWORKS - ISNN 2009, PT 1, PROCEEDINGS, 2009, 5551 : 323 - 332
  • [46] Construction of Activation Functions for Wavelet Neural Networks
    Stepanov, Andrey B.
    PROCEEDINGS OF 2017 XX IEEE INTERNATIONAL CONFERENCE ON SOFT COMPUTING AND MEASUREMENTS (SCM), 2017, : 397 - 399
  • [47] Comparative analysis of activation functions in neural networks
    Kamalov, Firuz
    Nazir, Amril
    Safaraliev, Murodbek
    Cherukuri, Aswani Kumar
    Zgheib, Rita
    2021 28TH IEEE INTERNATIONAL CONFERENCE ON ELECTRONICS, CIRCUITS, AND SYSTEMS (IEEE ICECS 2021), 2021,
  • [48] MEDIAN ACTIVATION FUNCTIONS FOR GRAPH NEURAL NETWORKS
    Ruiz, Luana
    Gama, Fernando
    Marques, Antonio G.
    Ribeiro, Alejandro
    2019 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2019, : 7440 - 7444
  • [49] Models of neural networks with fuzzy activation functions
    Nguyen, A. T.
    Korikov, A. M.
    INTERNATIONAL CONFERENCE ON MECHANICAL ENGINEERING, AUTOMATION AND CONTROL SYSTEMS 2016, 2017, 177
  • [50] Bicomplex Neural Networks with Hypergeometric Activation Functions
    Nelson Vieira
    Advances in Applied Clifford Algebras, 2023, 33