Papers › Design and Analysis of Novel Bit-flip Attacks and Defense Strategies for DNNs

Design and Analysis of Novel Bit-flip Attacks and Defense Strategies for DNNs

24 Jun 2022IEEE Conference on Dependable and Secure Computing (DSC) 2022 6archive 2025-07-28

Yash Khare, Kumud Lakara, Maruthi S Inukonda, Sparsh Mittal, Mahesh Chandra, Arvind Kaushik

The security of deep neural networks (DNNs) has become a matter of grave concern in the past few years due to their increasing ubiquity in security-critical domains. In this paper, we present novel bit-flip attack (BFA) algorithms for DNNs, along with techniques for defending against the attack. Our attack algorithms leverage information about the layer importance, such that a layer is considered important if it has high-ranked feature maps. We first present a classwise-targeted attack that degrades the accuracy of just one class in the dataset. Comparative evaluation with related works shows the effectiveness of our attack algorithm. We finally propose multiple novel defense strategies against untargeted BFAs. We comprehensively evaluate the robustness of both large-scale CNNs (VGG19, ResNext50, AlexNet and ResNet) and compact CNNs (MobileNet-v2, ShuffleNet, GoogleNet and SqueezeNet) towards BFAs. We also reveal a valuable insight that compact CNNs are highly vulnerable to not only well-crafted BFAs such as ours, but even random BFAs. Also, defense strategies are less effective on compact CNNs. This fact makes them unsuitable for use in security-critical domains.

PaperPDFCode

Code

Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.

Code Syntology ran Syntology

Not run by Syntology. Nothing on this page verifies that the listed code works.

Results from the paper archive 2025-07-28

No leaderboard rows for this paper in the archive.

Methods

1x1 ConvolutionAuxiliary ClassifierAverage PoolingBatch NormalizationChannel ShuffleConvolutionDense ConnectionsDepthwise ConvolutionDropoutGlobal Average PoolingGrouped ConvolutionGroupwise Point ConvolutionInception ModuleLocal Response NormalizationMax PoolingPointwise ConvolutionReLUResidual ConnectionShuffleNetShuffleNet BlockSoftmax

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections