2018/10/22 by Lejla Batina, Batina, Lejla, Shivam Bhasin +5 · 1 citation
Computer Science · Engineering · #Advancements in Semiconductor Devices and Circuit Design #Adversarial Robustness in Machine Learning #Cryptography and Security (cs.CR) #Electrostatic Discharge in Electronics #FOS: Computer and information sciences
paper · pdf · doi:10.48550/arxiv.1810.09076
openalex publication_date 2018/10/22 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
Machine learning has become mainstream across industries. Numerous examples\nproved the validity of it for security applications. In this work, we\ninvestigate how to reverse engineer a neural network by using only power\nside-channel information. To this end, we consider a multilayer perceptron as\nthe machine learning architecture of choice and assume a non-invasive and\neavesdropping attacker capable of measuring only passive side-channel leakages\nlike power consumption, electromagnetic radiation, and reaction time.\n We conduct all experiments on real data and common neural net architectures\nin order to properly assess the applicability and extendability of those\nattacks. Practical results are shown on an ARM CORTEX-M3 microcontroller. Our\nexperiments show that the side-channel attacker is capable of obtaining the\nfollowing information: the activation functions used in the architecture, the\nnumber of layers and neurons in the layers, the number of output classes, and\nweights in the neural network. Thus, the attacker can effectively reverse\nengineer the network using side-channel information.\n Next, we show that once the attacker has the knowledge about the neural\nnetwork architecture, he/she could also recover the inputs to the network with\nonly a single-shot measurement. Finally, we discuss several mitigations one\ncould use to thwart such attacks.\n