Breaking TinyML: Why Quantized Neural Networks Need Domain-Specific Security Analysis
For TinyML practitioners and security researchers, this work reveals that existing security assumptions for quantized neural networks are insufficient when considering hardware-specific vulnerabilities.
The paper demonstrates a two-step attack pipeline that outperforms current state-of-the-art attacks on quantized neural networks, highlighting the need for hardware-aware security analysis in TinyML.
Most TinyML hardware accelerators focus on supporting Quantized Neural Networks (QNNs) to meet stringent constraints on power consumption and size. Despite this, the security aspects of quantization within TinyML hardware remain largely unexplored. Although previous studies indicate that QNNs demonstrate similar or enhanced robustness when compared to full-precision Deep Neural Networks (DNNs) against typical evasion attacks, no attack strategies tailored specifically for TinyML hardware have been proposed yet. This paper addresses this shortfall by demonstrating how a two-step attack pipeline can surpass the current state-of-the-art in the QNN context and shows the need for more hardware-aware security research.