BARE-AI: Bit-Flip Attack Resilience in AI Hardware through Built-in Performance Monitors

📅 2026-10-06
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the vulnerability of deep neural networks to bit-flip attacks and the prohibitive overhead of existing defenses by proposing a runtime security framework. The framework leverages lightweight AI performance counters to capture activation statistics, combined with PULSE units for layer-wise security assessment. It introduces a novel activation shift index for precise fault localization and designs a Z-score-based weight repair mechanism to mitigate attacks. Experimental results demonstrate detection accuracies of 98% for vision models and 74%–95% for language models, effectively restoring the accuracy of CNNs and ViTs. Furthermore, under a 28nm process node, the energy, area, and latency overheads remain below 3%, 4%, and 10%, respectively.
📝 Abstract
Deep Neural Networks (DNNs) are integral to many safety critical systems, yet they remain highly vulnerable to bit-flip attacks (BFAs), where a few memory level perturbations can drastically degrade accuracy. Existing defenses incur significant hardware overhead, depend on retraining, or fail against targeted flips. We propose BARE-AI, a runtime framework that detects, localizes, and mitigates BFAs during inference. BARE-AI introduces AI Performance Counters (APCs), lightweight hardware monitors in the accelerator datapath that capture per-layer activation statistics such as sparsity, entropy, kurtosis, and spectral shift. These are analyzed by the Predictive Unit for Layer Security Evaluation (PULSE), a compact detector trained offline as an ensemble of classifiers and realized on-chip as a small neural engine. For explainability and recovery, BARE-AI introduces an Activation Shift Index (ASI) for layer level fault localization and a z-score based repair that resets anomalous weights toward clean layer statistics. Across CNNs, Vision Transformers, and Large Language Models under random, targeted, adaptive, and magnitude based BFAs, BARE-AI achieves up to 98% detection accuracy on vision models and 74% to 95% on language models, restores near clean accuracy for CNNs and ViTs, and provides partial recovery for LLMs. Synthesized at 28nm, the monitoring infrastructure incurs under 3% energy, under 4% area, and about 10% latency overhead, with a configurable operating point that reduces latency overhead to about 6%. Unlike error correcting codes, whose redundancy grows with the number of tolerated flips, BARE-AI's overhead remains constant regardless of attack strength, making it attractive for resource constrained, safety critical edge applications such as autonomous systems, energy, and healthcare.
Problem

Research questions and friction points this paper is trying to address.

Bit-Flip Attack
Deep Neural Networks
AI Hardware Security
Safety-Critical Systems
Inference Resilience
Innovation

Methods, ideas, or system contributions that make the work stand out.

Bit-Flip Attack Resilience
AI Performance Counters
Runtime Detection and Mitigation
Hardware Monitors
Activation Shift Index
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
H
Habibur Rahaman
Department of Electrical and Computer Engineering, University of Florida, Gainesville, FL, 32611, USA
Swastik Bhattacharya
Swastik Bhattacharya
Department of Electrical and Computer Engineering, University of Texas at Dallas, Richardson, TX, 75080, USA
Sanjay Das
Sanjay Das
University of Texas at Dallas
Deep learningHardware AcceleratorsHardware testing & securityFunctional safety
K
Kanad Basu
Department of Electrical, Computer and Systems Engineering, Rensselaer Polytechnic Institute, Troy, NY, 12180, USA
Swarup Bhunia
Swarup Bhunia
University of Florida
IoT SecurityHardware SecurityEnergy-Efficient ElectronicsFood/Medicine Safety