[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-117785-en":3,"doc-seo-117785-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},117785,687197100911,"Himbo","https://ap-avatar.wpscdn.com/avatar/a000239b6f1da00475?x-image-process=image/resize,m_fixed,w_180,h_180&k=1785132997149421697",8,"Research & Report","Evil from Within - Machine Learning Backdoors through Hardware Trojans","Backdoors threaten machine learning systems by undermining the integrity of security-critical applications, especially when inference occurs on untrusted hardware. Instead of relying on tampered models or modified software, the presented attack fully resides inside a common machine-learning accelerator. It uses a minimal backdoor that replaces only a small set of parameters and activates via a trigger, while a configurable hardware trojan performs the replacement only for the targeted model. Implemented on the Xilinx Vitis AI DPU, the method changes 0.069% of parameters, adds 0.24% circuit overhead, and shows no runtime overhead, making detection difficult.","Evil from Within:  \nMachine Learning Backdoors through Hardware Trojans  \nAlexander Warnecke􀀃§, Julian Speithy§ , Jan-Niklas Mllery , Konrad Rieck􀀃 , Christof Paary   \n􀀃 Technische Universita¨t Berlin  \ny Max Planck Institute for Security and Privacy (MPI-SP)  \narXiv :2304 .08411v2 [ cs .CR] 18 Apr 2023  \nAbstract—Backdoors pose a serious threat to machine learning, as they can compromise the integrity of security-critical systems, such as self-driving cars. While different defenses have been proposed to address this threat, they all rely on the assumption that the hardware on which the learning models are executed during inference is trusted. In this paper, we challenge this assumption and introduce a backdoor attack that completely resides within a common hardware accelerator for machine learning. Outside of the accelerator, neither the learning model nor the software is manipulated, so that current defenses fail. To make this attack practical, we overcome two challenges: First, as memory on a hardware accelerator is severely limited, we introduce the concept of a minimal backdoor that deviates as little as possible from the original model and is activated by replacing a few model parameters only. Second, we develop a conﬁgurable hardware trojan that can be provisioned with the backdoor and performs a replacement only when the speciﬁc target model is processed. We demonstrate the practical feasibility of our attack by implanting our hardware trojan into the Xilinx Vitis AI DPU, a commercial machine-learning accelerator. We conﬁgure the trojan with a minimal backdoor for a trafﬁc-sign recognition system. The backdoor replaces only 30 (0.069%) model parameters, yet it reliably manipulates the recognition once the input contains a backdoor trigger. Our attack expands the hardware circuit of the accelerator by 0.24% and induces no run-time overhead, rendering a detection hardly possible. Given the complex and highly distributed manufacturing process of current hardware, our work points to a new threat in machine learning that is inaccessible to current security mechanisms and calls for hardware to be manufactured only in fully trusted environments.  \n1. Introduction  \nMachine learning has become ubiquitous in recent years, with applications ranging from trafﬁc sign recognition [1] over cancer detection [2] and protein folding [3] to numerous use cases in social networks [4, 5] . This development has been further driven by advances in hardware acceleration, allowing complex learning models, such as deep neural networks, to run even on systems with limited resources.  \n§ . Both authors contributed equally.  \nToday, hardware accelerators in the form of applicationspeciﬁc integrated circuits (ASICs) and ﬁeld-programmable gate arrays (FPGAs) are indispensable in embedded and mobile systems that use machine learning.  \nHowever, the adoption of machine learning in practice is overshadowed by attacks that range from adversarial examples to backdoors and tampering with the training process [6] . A large body of work has explored these threatsand developed defenses of varying robustness [7–10] . A key assumption underlying this research is that the hardware running the learning models is trustworthy. That is, it is deemed sufﬁcient to ensure the integrity of the input and the learning model to realize a secure operation of machinelearning applications in practice.  \nIn this paper, we challenge this assumption. Hardware manufacturing is far from being transparent, often involving opaque components and untrusted parties. A multitude of attack vectors arise from the design process of integrated circuits (ICs) alone [11–13] and their use of third-party intellectual property (IP) cores [11, 14] . Given the complexity of modern circuits, built from billions of nanometer-sized transistors, it is very difﬁcult (if not impossible) to verify that an IC provides the exact logic speciﬁed in its design. In fact, this problem has led governments to pas","cbCaim27wkh8iMoc","https://ap.wps.com/l/cbCaim27wkh8iMoc","pdf",639917,1,18,"English","en",105,"# Introduction\n## Threat model and key assumption\n## Minimal backdoor concept\n## Hardware trojan design and execution flow\n## Experimental setup and feasibility example","[{\"question\":\"What core assumption do traditional machine-learning backdoor defenses rely on?\",\"answer\":\"They assume the hardware executing the learning model during inference is trustworthy, focusing security efforts on the input and the model itself.\"},{\"question\":\"How does the proposed attack reside within the hardware accelerator?\",\"answer\":\"During inference, a hardware trojan selectively replaces model parameters inside the accelerator based on the processed target model and a trigger.\"},{\"question\":\"What are the practical results demonstrated on the Xilinx Vitis AI DPU?\",\"answer\":\"A minimal backdoor replaces only 30 parameters (0.069%), reliably manipulates recognition when the trigger appears, expands the circuit by 0.24%, and introduces no runtime overhead, making detection difficult.\"}]","Evil from Within - Machine Learning Backdoors through Hardware Trojans | PDF",1785679536,45,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"evil-from-within-machine-learning-backdoors-through-hardware-trojans","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/evil-from-within-machine-learning-backdoors-through-hardware-trojans/117785/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What core assumption do traditional machine-learning backdoor defenses rely on?","Question",{"text":75,"@type":76},"They assume the hardware executing the learning model during inference is trustworthy, focusing security efforts on the input and the model itself.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the proposed attack reside within the hardware accelerator?",{"text":80,"@type":76},"During inference, a hardware trojan selectively replaces model parameters inside the accelerator based on the processed target model and a trigger.",{"name":82,"@type":73,"acceptedAnswer":83},"What are the practical results demonstrated on the Xilinx Vitis AI DPU?",{"text":84,"@type":76},"A minimal backdoor replaces only 30 parameters (0.069%), reliably manipulates recognition when the trigger appears, expands the circuit by 0.24%, and introduces no runtime overhead, making detection difficult.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]