1 of 33

ResGNN: A Generic Framework for Measuring Graph Neural Network Resilience Against�Faults and Attacks in Hardware Systems

Sharc-lab @ Georgia Tech https://sharclab.ece.gatech.edu/

Hanqiu Chen, Zishen Wan and Cong (Callie) Hao

Georgia Institute of Technology

School of Electrical and Computer Engineering

2 of 33

Background: Bit Flipping in AI Systems

2

AI workloads

memory

computation

core

Hardware systems

User

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

3 of 33

Background: Bit Flipping in AI Systems

3

AI workloads

memory

computation

core

Hardware systems

Attacks or faults

User

10000

0

10000

0

10000

1

10000

1

10000

0

10000

0

10000

0

10000

1

Bit flipping

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

4 of 33

Background: Bit Flipping in AI Systems

4

AI workloads

memory

computation

core

Hardware systems

Attacks or faults

User

10000

0

10000

0

10000

1

10000

1

10000

0

10000

0

10000

0

10000

1

Bit flipping

Lowering voltage

Increasing temperature

Cosmic radiation

Row-Hammer attack

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

5 of 33

Background: Bit Flipping in AI Systems

5

AI workloads

memory

computation

core

Hardware systems

Attacks or faults

User

10000

0

10000

0

10000

1

10000

1

10000

0

10000

0

10000

0

10000

1

Bit flipping

Lowering voltage

Increasing temperature

Cosmic radiation

Row-Hammer attack

How can we evaluate the resilience of system under bit flipping?

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

6 of 33

Background: Bit Flipping in AI Systems

6

AI workloads

memory

computation

core

Hardware systems

Attacks or faults

User

10000

0

10000

0

10000

1

10000

1

10000

0

10000

0

10000

0

10000

1

Bit flipping

Lowering voltage

Increasing temperature

Cosmic radiation

Row-Hammer attack

How can we evaluate the resilience of system under bit flipping?

GNN is more complicated than DNN

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

7 of 33

Related Work: Designed for DNN

7

Ares: A framework for quantifying the resilience of deep neural networks (DAC’18)

Ares

PyTorchFI: A Runtime Perturbation Tool for DNNs (DSN-W’20)

PyTorchFI

GoldenEye

GoldenEye: A Platform for Evaluating Emerging Numerical Data Formats in DNN Accelerators (DSN’22)

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

8 of 33

Related Work: Designed for DNN

8

Ares: A framework for quantifying the resilience of deep neural networks (DAC’18)

Ares

PyTorchFI: A Runtime Perturbation Tool for DNNs (DSN-W’20)

PyTorchFI

GoldenEye

GoldenEye: A Platform for Evaluating Emerging Numerical Data Formats in DNN Accelerators (DSN’22)

GNN

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

9 of 33

Challenges 1: GNN Complex Topology

9

4

5

6

2

9

8

1

7

3

4

5

6

2

9

8

1

7

3

Message passing

Message passing

1

Aggregate

2

3

4

7

8

2

Aggregate

1

6

9

Different nodes aggregate information from different neighborhood nodes

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

10 of 33

Challenges 1: GNN Complex Topology

10

4

5

6

2

9

8

1

7

3

4

5

6

2

9

8

1

7

3

Message passing

Message passing

1

Aggregate

2

3

4

7

8

2

Aggregate

1

6

9

Compared with DNNs, graph topology also needs to be taken into consideration in GNN computation!

Different nodes aggregate information from different neighborhood nodes

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

11 of 33

Challenges 2: Lack of Hardware Attention

11

Existing resilience analysis tools

Software/Algorithm

Hardware

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

12 of 33

Challenges 2: Lack of Hardware Attention

12

Existing resilience analysis tools

Software/Algorithm

Hardware

We need an automated and systematic resilience analysis tool for GNN!

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

13 of 33

ResGNN: A General Framework

13

ResGNN

Contributions

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

14 of 33

ResGNN: A General Framework

14

ResGNN

Contributions

Fault injection framework

~ support different GNNs and multiple tasks

~ show node importance

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

15 of 33

ResGNN: A General Framework

15

ResGNN

Contributions

Fault injection framework

~ support different GNNs and multiple tasks

~ show node importance

Support multi-type faults

~ caused by low voltage or Row-Hammer attacks

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

16 of 33

ResGNN: A General Framework

16

ResGNN

Contributions

Fault injection framework

~ support different GNNs and multiple tasks

~ show node importance

Support multi-type faults

~ caused by low voltage or Row-Hammer attacks

Simulator for evaluation

~ Different positions fault injection

~ different precision GNNs

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

17 of 33

ResGNN: A General Framework

17

Impact with fault mitigation

ResGNN

Contributions

Fault injection framework

~ support different GNNs and multiple tasks

~ show node importance

Support multi-type faults

~ caused by low voltage or Row-Hammer attacks

Simulator for evaluation

~ Different positions fault injection

~ different precision GNNs

~ reliable and energy-efficient GNN systems

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

18 of 33

ResGNN: Front-end Graph Topology Analysis

18

GNN explainer

Important node

Important features

Node features

ResGNN front-end tool is a GNN explainer

GNN explainer is used to analyze the graph topology, annotate important nodes and node embeddings

Explore how graph topology will affect GNN resilience

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

19 of 33

ResGNN: Back-end GNN Resilience Simulator

19

User

Fault model

Fault map

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

20 of 33

ResGNN: Back-end GNN Resilience Simulator

20

User

Fault model

Fault map

0

Undervolting faults

(soft error)

1

Set node embedding values to 0

0

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

21 of 33

ResGNN: Back-end GNN Resilience Simulator

21

User

Fault model

Fault map

0

0

Undervolting faults

(soft error)

1

2

Row-Hammer attack

Set node embedding values to 0

Flip some bits of node embeddings

(bit-flipping)

0

0

1

1

0

1

0

1

1

0

0

0

0

1

1

1

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

22 of 33

ResGNN: Back-end GNN Resilience Simulator

22

User

Fault model

Fault map

0

0

Undervolting faults

(soft error)

1

2

Row-Hammer attack

Set node embedding values to 0

Flip some bits of node embeddings

(bit-flipping)

0

0

1

1

0

1

0

1

1

0

0

0

0

1

1

1

Develop a simulator to evaluate GNN performance under hardware errors and faults

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

23 of 33

Fault Model

23

Memory

1

Where?

User

Fault model

Fault map

Faults in memory

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

24 of 33

Fault Model

24

Memory

1

Where?

User

Fault model

Fault map

Faults in memory

2

Pattern?

Multiple bits flip together to zero in a memory row

Random single bit flip

Undervolting faults

Row-Hammer attack

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

25 of 33

Results: Node Importance Visualization

25

Important node

Unimportant node

Dataset: Open Graph Benchmark Task: graph classification

Dataset link: https://ogb.stanford.edu/docs/graphprop/

Root nodes are more important than leaf nodes!

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

26 of 33

Results: Important/Unimportant Nodes

26

Important nodes are much more sensitive to hardware errors and faults than unimportant nodes

Setting: Insert undervolting faults with fault ratio = 0.3 on the first layer of GNN

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

27 of 33

Results: Different GNN Layers

27

Faults on the first GNN layer has a much larger influence on the GNN prediction accuracy

Setting: Insert undervolting faults with different fault ratios

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

28 of 33

Results: Different Bit Positions

28

0

5

10

15

20

25

30

Bit Order Index

0

5

10

15

20

25

30

Bit Order Index

0

5

10

15

20

25

30

Bit Order Index

0

5

10

15

20

25

30

Bit Order Index

0.4

0.5

0.6

0.7

0.625

0.650

0.675

0.700

0.725

0.750

0.775

0.50

0.55

0.60

0.65

0.70

0.75

0.45

0.50

0.55

0.60

0.65

0.70

0.75

Prediction Accuracy

Prediction Accuracy

Prediction Accuracy

Prediction Accuracy

GCN

GIN

molhiv

moltox21

We observe a rapid turning point

Faults on higher-order bits have a larger impact on GNN prediction accuracy

Setting: Set the bit-flipping fault ratio = 0.05 on the first layer

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

29 of 33

Results: Different Data Precision

29

Quantize to lower precision and fixed point can reduce the resilience of GNN

Fault ratio 0.05

Fault ratio 0.10

Fault ratio 0.15

Fault ratio 0.20

Fault ratio 0.25

Fault ratio 0.30

Fault ratio 0.05

Fault ratio 0.10

Fault ratio 0.15

Fault ratio 0.20

Fault ratio 0.25

Fault ratio 0.30

Setting: Insert undervolting faults on the first layer with different fault ratios

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

30 of 33

Future Works

30

  • Defense Propose hardware efficient fault detection and mitigation strategies

  • Training – Measure the resilience of GNN training under bit-flipping faults

  • Functional support – Add support for faults on edge embeddings and graph structures

  • Simulation quality – Collect more fault maps from real hardware memory for more accurate simulation results

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

31 of 33

Future Prospects: Graph in Data Center

31

Large graph training and inference in data center

GNN + LLM is becoming a new trend for graph applications

More attention of GNN resilience in data center

A Survey of Graph Meets Large Language Model: Progress and Future Directions (IJCAI’24)

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

32 of 33

Future Prospects: Graph in Data Center

32

Large graph training and inference in data center

GNN + LLM is becoming a new trend for graph applications

More attention of GNN resilience in data center

A Survey of Graph Meets Large Language Model: Progress and Future Directions (IJCAI’24)

ResGNN can help in the future!

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology

33 of 33

Summary & Thanks

33

  • ResGNN is an automatic and systematic for measuring graph neural network resilience against faults and attacks in hardware systems

    • Motivation – GNN complex topology and lack of hardware attention

    • Contribution – A fault injection framework; support multi-type faults; simulator for evaluation; help fault mitigation

    • Analysis – Node importance visualization; resilience of GNN with faults on different types of nodes, different GNN layers and different bit positions; resilience of GNN with different data precisions

    • Future prospects – Defense, training, functional support and simulation quality; GNN + LLM training and inference resilience in data center

Hanqiu Chen | Sharc-lab @ Georgia Institute of Technology