Abstract
Deep learning services are now deployed in various fields on top of cloud infrastructures. In such cloud environment, virtualization technology provides logically independent and isolated computing space for each tenant. However, recent studies demonstrate that by leveraging vulnerabilities of virtualization techniques and shared processor architectures in the cloud system, various side-channels can be established between cloud tenants. In this paper, we propose a novel attack scenario that can steal internal information of deep learning models by exploiting the Meltdown vulnerability in a multitenant system environment. On the basis of our experiment, the proposed attack method could extract internal information of a TensorFlow deep learning service with 92.875% accuracy and 1.325kB/s extraction speed.
Original language | English |
---|---|
Title of host publication | 35th International Conference on Information Networking, ICOIN 2021 |
Publisher | IEEE Computer Society |
Pages | 36-38 |
Number of pages | 3 |
ISBN (Electronic) | 9781728191003 |
DOIs | |
Publication status | Published - 2021 Jan 13 |
Event | 35th International Conference on Information Networking, ICOIN 2021 - Jeju Island, Korea, Republic of Duration: 2021 Jan 13 → 2021 Jan 16 |
Publication series
Name | International Conference on Information Networking |
---|---|
Volume | 2021-January |
ISSN (Print) | 1976-7684 |
Conference
Conference | 35th International Conference on Information Networking, ICOIN 2021 |
---|---|
Country/Territory | Korea, Republic of |
City | Jeju Island |
Period | 21/1/13 → 21/1/16 |
Bibliographical note
Funding Information:This work was supported by Institute of Information communications Technology Planning Evaluation (IITP) grant funded by the Korea government (MSIT) (No.2019-0-00533, Research on CPU vulnerability detection and validation) (No.2019-0-01697, Development of Automated Vulnerability Discovery Technologies for Blockchain Platform Security) (IITP-2020-0-01819, ICT Creative Consilience program).
Publisher Copyright:
© 2021 IEEE.
Keywords
- Meltdown
- cloud computing
- deep learning
- neural network stealing
ASJC Scopus subject areas
- Computer Networks and Communications
- Information Systems