Nelms Institute in the News: A hardware neural network backdoor that hides in plain sight

Deep learning systems on phones, cars, and other edge devices increasingly run on custom silicon. Specialized chips such as FPGAs and ASICs give these systems the speed and low power consumption that edge applications need. Many of these chips come from third-party design houses and foundries, which adds steps to the supply chain where an outside party can alter a device.

Researchers at the University of Tennessee and the University of Florida built an attack that takes advantage of this arrangement. The attack, called HAMLOCK, short for Hardware-Model Logically Combined Attack, divides a backdoor into two parts and places them on opposite sides of the hardware and software boundary.

The paper is authored by Sanskar Amgain, Daniel Lobo, Atri Chatterjee, Swarup Bhunia, and Fnu Suya.

Read the full article on Help Net Security >>

Graphic figure showing the threat of the HAMLOCK attack.
Threat Model of HAMLOCK (Source: Research paper)