FINN-Tro: Exploiting Verification Gaps in Dataflow Inference Accelerators
Updated
Updated · arxiv.org · Sep 23
FINN-Tro: Exploiting Verification Gaps in Dataflow Inference Accelerators
1 articles · Updated · arxiv.org · Sep 23
Summary
Researchers have revealed FINN-Tro, a new hardware Trojan attack exploiting verification gaps in FPGA-based neural network accelerators generated by the FINN framework.
The attack manipulates the final Matrix-Vector Activation Unit, supporting various trigger modes and payloads, causing significant accuracy degradation while incurring minimal hardware overhead.
This discovery highlights the insufficiency of current verification methods in detecting such attacks, underscoring the need for stronger security in accelerator toolchains.