论文标题

HDLOCK:利用特权编码以保护超维度计算模型免受IP窃取

HDLock: Exploiting Privileged Encoding to Protect Hyperdimensional Computing Models against IP Stealing

论文作者

Duan, Shijin, Ren, Shaolei, Xu, Xiaolin

论文摘要

高维计算(HDC)由于直接计算而面临侵权问题。这项工作首次增加了HDC的关键脆弱性,攻击者可以反向整个模型进行反向工程,只需要未索引的HyperVector内存即可。为了减轻这种攻击,我们提出了一种防御策略,即HDLock,这大大增加了编码的推理成本。具体而言,HDLOCK在编码模块中添加了额外的特征HyperVector组合和置换。与标准的HDC模型相比,两层键的HDLOCK可以将对抗性推理复杂性提高10个大小阶,而无需推断精度损失,只有21%的潜伏期开销。

Hyperdimensional Computing (HDC) is facing infringement issues due to straightforward computations. This work, for the first time, raises a critical vulnerability of HDC, an attacker can reverse engineer the entire model, only requiring the unindexed hypervector memory. To mitigate this attack, we propose a defense strategy, namely HDLock, which significantly increases the reasoning cost of encoding. Specifically, HDLock adds extra feature hypervector combination and permutation in the encoding module. Compared to the standard HDC model, a two-layer-key HDLock can increase the adversarial reasoning complexity by 10 order of magnitudes without inference accuracy loss, with only 21% latency overhead.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源