Next up at #enigma2021, Sanghyun Hong will be speaking about "A SOUND MIND IN A VULNERABLE BODY: PRACTICAL HARDWARE ATTACKS ON DEEP LEARNING"
(Hint: speaker is on the
* looks at the robustness in an isolated manner
* doesn't look at the whole ecosystem and how the model is used -- ML models are running in real hardware with real software which has real vulns!
e.g. fault injection attacks, side-channel attacks
* co-location of VMs from different users
* weak attackers with less subtle control
The cloud providers try to secure things, e.g. protections against Rowhammer
... BUT this focuses on the average or best case, not the worst cast!
* negligible effect on the average case accuracy
* but flipping one bit can make significant amount of damage for particular queries
How much damage can a single bit flip cause?
Some strong attackers might be able to hit an "achilles" bit (one that's really going to mess with the model), but weaker attackers are going to hit bits more randomly.
The attacker might want to get their hands on fancy DNNs which are considered trade secrets and proprietary to their creators. They're expensive to make! They need good training data! People want to protect them!
Does this work? Apparently so: they tried it out using a cache side-channel attack and got back the architectures of the fancy DNN back.
More from Lea Kissner
More from Science
I want to share my thoughts, as someone who has been so alarmed by the so-called "dissident" scientists like Gupta, Heneghan, Kuldorff, Bhattacharya, & Ioannidis who consider themselves brave Galileos unfairly treated by "establishment scientists." I will try not to swear. 1/n
I want to talk about 3 things:
‼️Their fringe views are inhumane, unethical junk science that promotes harm
‼️They complain that they've been marginalized but this is simply untrue
‼️I am sick of people telling me we have to "listen to both sides." There aren't 2 sides here 2/n
These 'dissident' scientists have consistently downplayed COVID-19, urging policymakers not to take aggressive control measures. They claim it is not a serious threat. Gupta even went on TV saying people under 65 shouldn't worry about it!
RECEIPTS
They have consistently argued that policymakers should just let the virus rip, in an attempt to reach herd immunity by natural infection. Kuldorff *continues* to argue for this even now that we have many highly effective, safe vaccines.
We've never controlled a deadly, contagious pandemic before by just letting the virus spread, as this approach kills & disables too many people. In Manaus, Brazil, 66% of the city was infected & an astonishing *1 in 500* people died of COVID-19
If this is true raises the question of why certain (fringe & unethical) views got access to No.10 while others were ignored... https://t.co/A75HrSEqo4
— Prof. Devi Sridhar (@devisridhar) December 13, 2020
I want to talk about 3 things:
‼️Their fringe views are inhumane, unethical junk science that promotes harm
‼️They complain that they've been marginalized but this is simply untrue
‼️I am sick of people telling me we have to "listen to both sides." There aren't 2 sides here 2/n
These 'dissident' scientists have consistently downplayed COVID-19, urging policymakers not to take aggressive control measures. They claim it is not a serious threat. Gupta even went on TV saying people under 65 shouldn't worry about it!
RECEIPTS
They have consistently argued that policymakers should just let the virus rip, in an attempt to reach herd immunity by natural infection. Kuldorff *continues* to argue for this even now that we have many highly effective, safe vaccines.
Focused Protection: The Middle Ground between Lockdowns and "Let-it-rip". An essay by Jay Bhattacharya (@Stanford), @SunetraGupta (@UniofOxford) and @MartinKulldorff (@Harvard). https://t.co/T8uLxSFwgh
— Martin Kulldorff (@MartinKulldorff) December 11, 2020
We've never controlled a deadly, contagious pandemic before by just letting the virus spread, as this approach kills & disables too many people. In Manaus, Brazil, 66% of the city was infected & an astonishing *1 in 500* people died of COVID-19
You May Also Like
Stan Lee’s fictional superheroes lived in the real New York. Here’s where they lived, and why. https://t.co/oV1IGGN8R6
Stan Lee, who died Monday at 95, was born in Manhattan and graduated from DeWitt Clinton High School in the Bronx. His pulp-fiction heroes have come to define much of popular culture in the early 21st century.
Tying Marvel’s stable of pulp-fiction heroes to a real place — New York — served a counterbalance to the sometimes gravity-challenged action and the improbability of the stories. That was just what Stan Lee wanted. https://t.co/rDosqzpP8i
The New York universe hooked readers. And the artists drew what they were familiar with, which made the Marvel universe authentic-looking, down to the water towers atop many of the buildings. https://t.co/rDosqzpP8i
The Avengers Mansion was a Beaux-Arts palace. Fans know it as 890 Fifth Avenue. The Frick Collection, which now occupies the place, uses the address of the front door: 1 East 70th Street.
Stan Lee, who died Monday at 95, was born in Manhattan and graduated from DeWitt Clinton High School in the Bronx. His pulp-fiction heroes have come to define much of popular culture in the early 21st century.
Tying Marvel’s stable of pulp-fiction heroes to a real place — New York — served a counterbalance to the sometimes gravity-challenged action and the improbability of the stories. That was just what Stan Lee wanted. https://t.co/rDosqzpP8i
The New York universe hooked readers. And the artists drew what they were familiar with, which made the Marvel universe authentic-looking, down to the water towers atop many of the buildings. https://t.co/rDosqzpP8i
The Avengers Mansion was a Beaux-Arts palace. Fans know it as 890 Fifth Avenue. The Frick Collection, which now occupies the place, uses the address of the front door: 1 East 70th Street.