Verification of Bit-Flip Attacks against Quantized Neural Networks

Loading...
Thumbnail Image
File version

Version of Record (VoR)

Author(s)
Zhang, Y
Huang, L
Gao, P
Song, F
Sun, J
Dong, JS
Griffith University Author(s)
Primary Supervisor
Other Supervisors
Editor(s)
Date
2025
Size
File type(s)
Location
Abstract

In the rapidly evolving landscape of neural network security, the resilience of neural networks against bit-flip attacks (i.e., an attacker maliciously flips an extremely small amount of bits within its parameter storage memory system to induce harmful behavior), has emerged as a relevant area of research. Existing studies suggest that quantization may serve as a viable defense against such attacks. Recognizing the documented susceptibility of real-valued neural networks to such attacks and the comparative robustness of quantized neural networks (QNNs), in this work, we introduce BFAVerifier, the first verification framework designed to formally verify the absence of bit-flip attacks against QNNs or to identify all vulnerable parameters in a sound and rigorous manner. BFAVerifier comprises two integral components: an abstraction-based method and an MILP-based method. Specifically, we first conduct a reachability analysis with respect to symbolic parameters that represent the potential bit-flip attacks, based on a novel abstract domain with a sound guarantee. If the reachability analysis fails to prove the resilience of such attacks, then we encode this verification problem into an equivalent MILP problem which can be solved by off-the-shelf solvers. Therefore, BFAVerifier is sound, complete, and reasonably efficient. We conduct extensive experiments, which demonstrate its effectiveness and efficiency across various activation functions, quantization bit-widths, and adversary capabilities.

Journal Title

Proceedings of the ACM on Programming Languages

Conference Title
Book Title
Edition
Volume

9

Issue

OOPSLA1

Thesis Type
Degree Program
School
Publisher link
Patent number
Funder(s)
Grant identifier(s)
Rights Statement
Rights Statement

© 2025 Owner/Author. This work is licensed under Creative Commons Attribution International 4.0.

Item Access Status
Note
Access the data
Related item(s)
Subject

Neural networks

Software engineering

Theory of computation

Numerical and computational mathematics

Persistent link to this record
Citation

Zhang, Y; Huang, L; Gao, P; Song, F; Sun, J; Dong, JS, Verification of Bit-Flip Attacks against Quantized Neural Networks, Proceedings of the ACM on Programming Languages, 2025, 9 (OOPSLA1), pp. 115

Collections