Adversarial Perturbation Attacks on ML-based CAD

Author:

Liu Kang1,Yang Haoyu2,Ma Yuzhe2,Tan Benjamin1,Yu Bei2,Young Evangeline F. Y.2,Karri Ramesh1,Garg Siddharth1

Affiliation:

1. New York University, Brooklyn, NY, USA

2. Chinese University of Hong Kong, Shatin, Hong Kong

Abstract

There is substantial interest in the use of machine learning (ML)-based techniques throughout the electronic computer-aided design (CAD) flow, particularly those based on deep learning. However, while deep learning methods have surpassed state-of-the-art performance in several applications, they have exhibited intrinsic susceptibility to adversarial perturbations—small but deliberate alterations to the input of a neural network, precipitating incorrect predictions. In this article, we seek to investigate whether adversarial perturbations pose risks to ML-based CAD tools, and if so, how these risks can be mitigated. To this end, we use a motivating case study of lithographic hotspot detection, for which convolutional neural networks (CNN) have shown great promise. In this context, we show the first adversarial perturbation attacks on state-of-the-art CNN-based hotspot detectors; specifically, we show that small (on average 0.5% modified area), functionality preserving, and design-constraint-satisfying changes to a layout can nonetheless trick a CNN-based hotspot detector into predicting the modified layout as hotspot free (with up to 99.7% success in finding perturbations that flip a detector’s output prediction, based on a given set of attack constraints). We propose an adversarial retraining strategy to improve the robustness of CNN-based hotspot detection and show that this strategy significantly improves robustness (by a factor of ~3) against adversarial attacks without compromising classification accuracy.

Funder

Office of Naval Research

National Science Foundation

Publisher

Association for Computing Machinery (ACM)

Subject

Electrical and Electronic Engineering,Computer Graphics and Computer-Aided Design,Computer Science Applications

Cited by 18 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. APPLE: An Explainer of ML Predictions on Circuit Layout at the Circuit-Element Level;2024 29th Asia and South Pacific Design Automation Conference (ASP-DAC);2024-01-22

2. RL-OPC: Mask Optimization With Deep Reinforcement Learning;IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems;2024-01

3. An Adversarial Active Sampling-Based Data Augmentation Framework for AI-Assisted Lithography Modeling;2023 IEEE/ACM International Conference on Computer Aided Design (ICCAD);2023-10-28

4. Security and Reliability Challenges in Machine Learning for EDA: Latest Advances;2023 24th International Symposium on Quality Electronic Design (ISQED);2023-04-05

5. Detecting DDoS attacks using adversarial neural network;Computers & Security;2023-04

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3