Security Risks in AI Accelerators: Detecting RTL Vulnerabilities to Model Theft with Formal Verification


연구 분야: Verification



학회: 2025 IEEE European Test Symposium (ETS)


초록

The rapid growth of computational demands for Artificial Intelligence (AI) has spawned intensive research on dedicated AI accelerators being integrated into the hardware (HW) of modern computing systems. Unfortunately, the increased use of AI accelerators comes with new and relevant security risks. A serious threat is model theft, where attackers target the valuable AI model processed in such accelerators.In this work, we address model theft at the microarchitectural level. While various attacks have already been reported that use timing side channels in AI accelerators for model theft, there is a distinct lack of detection methods for such vulnerabilities. This paper contributes to filling this gap. We propose a formal threat model and develop a method to exhaustively prove security with respect to this threat. Our method is based on analyzing the timing dependence of the HW’s computation on all relevant parameters of the AI model. We demonstrate our approach both for data flow and systolic array architectures. In particular, we report a vulnerability in a optimization feature of Neural Networks (NNs) that was detected by our method.


Author Profile
Mohamed Shelkamy Ali

RPTU Kaiserslautern-Landau Germany

Germany
Author Profile
Lucas Deutschmann

RPTU Kaiserslautern-Landau Germany

Germany
Author Profile
Johannes Müller

RPTU Kaiserslautern-Landau Germany

Germany

📄 논문 정보

발행 연도 2025년
인용수 45
출판 국가 Germany, United States
사이트 IEEE
좋아요 수 0

연관 논문 목록 (65건)