acceptodds
Under review as a conference paper at ICLR 2027

SANAI: BIT-FLIP ATTACK-RESISTANT SECURE NEURAL NETWORK WITH EMBEDDED AND KEYED PARITY

Abstract

Quantized neural networks store weights in dense memory, where bit flips caused by voltage scaling, aging, radiation, or deliberate attacks such as RowHammer can severely degrade model behavior. A single corrupted high-order bit can lead to erroneous classifications or nonsensical language-model outputs. Embedded error-correcting codes (ECC) avoid dedicated parity storage by hiding parity within model weights. However, existing schemes use largely uniform embedding across layers and bit planes, leave parity unsecured, and tolerate only low bit-error rates (BERs), typically up to 6%. Moreover, an adversary aware of sensitive weight locations and the ECC scheme can bypass protection by deliberately exceeding the correction capability of targeted codewords. We propose SANAI, a sensitivity- guided, bit-plane-selective scheme that robustly protects critical model weights against bit flips with zero additional parity-storage overhead. SANAI secures ECC parity through keyed embedding across a two-dimensional weight space. Spread transform dither modulation binds parity to a secret key, while keyed interleaving disperses concentrated attacks across codewords. We derive a survival law showing that robustness is governed by the correctable fraction t/n, rather than correction strength t alone, and establish a closed-form bound on the protectable fraction of a model. Implemented as a streaming checker on an 8 × 8 systolic array, SANAI verifies weights on the load path with only 0.41% area overhead and no additional memory. Across ten vision backbones, three quantization schemes, and ten language models ranging from 82M to 13B parameters, SANAI maintains accuracy within approximately one percentage point of the clean baseline at BERs up to 12%, twice the maximum BER supported by prior embedded-ECC approaches. It also survives fine-tuning bit-exactly, neutralizes progressive and targeted bit-flip attacks, and exactly corrects AttentionBreaker and SilentStriker attacks.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.