DeepNcode: Encoding-Based Protection against Bit-Flip Attacks on Neural Networks
cs.CR, cs.AI
Submitted: 2024-05-22
Updated: 2024-06-02
Journal ref: IEEE Trans. Emerg. Topics Comput., vol. 14, no. 3, pp. 1181-1196, 2026
DOI: 10.1109/TETC.2026.3704626
License: http://creativecommons.org/licenses/by/4.0/
The gist: Fault injection attacks are a potent threat against embedded implementations of neural network models.
Terminology
Abstract
Fault injection attacks are a potent threat against embedded implementations of neural network models. Several attack vectors have been proposed, such as misclassification, model extraction, and trojan/backdoor planting. Most of these attacks work by flipping bits in the memory where quantized model parameters are stored. In this paper, we introduce an encoding-based protection method against bit-flip attacks on neural networks, titled DeepNcode. We experimentally evaluate our proposal with several publicly available models and datasets, by using state-of-the-art bit-flip attacks: BFA, T-BFA, and TA-LBF. Our results show an increase in protection margin of up to 7.6 times for 4- bit and 12.4 times for 8- bit quantized networks. Memory overheads start at 50% of the original network size, while the time overheads are negligible. Moreover, DeepNcode does not require retraining and does not change the original accuracy of the model.
Sources
- Intriguing properties of neural networks
- RA-BNN: Constructing Robust & Accurate Binary Neural Network to Simultaneously Defend Adversarial Bit-Flip Attack and Improve Accuracy
- Targeted Attack against Deep Neural Networks via Flipping Limited Weight Bits
- A White Paper on Neural Network Quantization
- DNN-Defender: A Victim-Focused In-DRAM Defense Mechanism for Taming Adversarial Weight Attack on DNNs
- Very Deep Convolutional Networks for Large-Scale Image Recognition
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs