FaRAccel: FPGA-Accelerated Defense Architecture for Efficient Bit-Flip Attack Resilience in Transformer Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Nazari, Najmeh, Latibari, Banafsheh Saber, Hosseini, Elahe, Movafagh, Fatemeh, Fang, Chongzhou, Makrani, Hosein Mohammadi, Gubbi, Kevin Immanuel, Mahalanobis, Abhijit, Rafatirad, Setareh, Sayadi, Hossein, Homayoun, Houman
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915585159331840
author Nazari, Najmeh
Latibari, Banafsheh Saber
Hosseini, Elahe
Movafagh, Fatemeh
Fang, Chongzhou
Makrani, Hosein Mohammadi
Gubbi, Kevin Immanuel
Mahalanobis, Abhijit
Rafatirad, Setareh
Sayadi, Hossein
Homayoun, Houman
author_facet Nazari, Najmeh
Latibari, Banafsheh Saber
Hosseini, Elahe
Movafagh, Fatemeh
Fang, Chongzhou
Makrani, Hosein Mohammadi
Gubbi, Kevin Immanuel
Mahalanobis, Abhijit
Rafatirad, Setareh
Sayadi, Hossein
Homayoun, Houman
contents Forget and Rewire (FaR) methodology has demonstrated strong resilience against Bit-Flip Attacks (BFAs) on Transformer-based models by obfuscating critical parameters through dynamic rewiring of linear layers. However, the application of FaR introduces non-negligible performance and memory overheads, primarily due to the runtime modification of activation pathways and the lack of hardware-level optimization. To overcome these limitations, we propose FaRAccel, a novel hardware accelerator architecture implemented on FPGA, specifically designed to offload and optimize FaR operations. FaRAccel integrates reconfigurable logic for dynamic activation rerouting, and lightweight storage of rewiring configurations, enabling low-latency inference with minimal energy overhead. We evaluate FaRAccel across a suite of Transformer models and demonstrate substantial reductions in FaR inference latency and improvement in energy efficiency, while maintaining the robustness gains of the original FaR methodology. To the best of our knowledge, this is the first hardware-accelerated defense against BFAs in Transformers, effectively bridging the gap between algorithmic resilience and efficient deployment on real-world AI platforms.
format Preprint
id arxiv_https___arxiv_org_abs_2510_24985
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle FaRAccel: FPGA-Accelerated Defense Architecture for Efficient Bit-Flip Attack Resilience in Transformer Models
Nazari, Najmeh
Latibari, Banafsheh Saber
Hosseini, Elahe
Movafagh, Fatemeh
Fang, Chongzhou
Makrani, Hosein Mohammadi
Gubbi, Kevin Immanuel
Mahalanobis, Abhijit
Rafatirad, Setareh
Sayadi, Hossein
Homayoun, Houman
Cryptography and Security
Artificial Intelligence
Forget and Rewire (FaR) methodology has demonstrated strong resilience against Bit-Flip Attacks (BFAs) on Transformer-based models by obfuscating critical parameters through dynamic rewiring of linear layers. However, the application of FaR introduces non-negligible performance and memory overheads, primarily due to the runtime modification of activation pathways and the lack of hardware-level optimization. To overcome these limitations, we propose FaRAccel, a novel hardware accelerator architecture implemented on FPGA, specifically designed to offload and optimize FaR operations. FaRAccel integrates reconfigurable logic for dynamic activation rerouting, and lightweight storage of rewiring configurations, enabling low-latency inference with minimal energy overhead. We evaluate FaRAccel across a suite of Transformer models and demonstrate substantial reductions in FaR inference latency and improvement in energy efficiency, while maintaining the robustness gains of the original FaR methodology. To the best of our knowledge, this is the first hardware-accelerated defense against BFAs in Transformers, effectively bridging the gap between algorithmic resilience and efficient deployment on real-world AI platforms.
title FaRAccel: FPGA-Accelerated Defense Architecture for Efficient Bit-Flip Attack Resilience in Transformer Models
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2510.24985