发表机构
Slovak University of Technology; Indian Institute of Technology Bhilai; TTControl GmbH(斯洛伐克工业大学; 印度理工学院比莱分校; TTControl有限公司)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对嵌入式设备上浮点神经网络权重,提出基于轮廓的模板攻击,利用功耗泄漏逐位恢复IEEE-754单精度权重,在ChipWhisperer-Lite上达到99%以上的精确恢复成功率。
AI 中文摘要
部署在嵌入式设备上的神经网络参数可能在推理过程中通过物理侧信道泄漏而被暴露。现有的针对浮点神经网络参数的侧信道攻击通常针对降低的数值精度,而恢复完整的IEEE-754表示则因32位候选空间庞大且结构化而更具挑战性。我们提出了一种轮廓模板攻击,用于从功耗测量中逐位精确恢复IEEE-754单精度神经网络权重。该攻击针对已知输入与第一层权重之间的浮点乘法。在轮廓分析阶段,使用乘法结果的汉明重量类别从随机化的网络配置中学习多元高斯模板,而其余网络参数则作为干扰变量。为了高效搜索结构化的32位浮点候选空间,我们采用了一种从粗到细再到精确的分层过程,逐步提高数值和泄漏模型的分辨率。在配备Arm Cortex-M4的ChipWhisperer-Lite上进行的实验表明,能够恢复目标权重的精确float32表示。在评估的设置中,该攻击在171条迹线时达到99%的逐位精确成功率,从263条迹线起达到100%。这些结果表明,轮廓分析能够实现从物理泄漏中实际提取浮点神经网络参数的全精度。
英文摘要
Neural-network parameters deployed on embedded devices may be exposed through physical side-channel leakage during inference. Existing side-channel attacks on floating-point neural-network parameters have often targeted reduced numerical precision, while recovering the complete IEEE-754 representation remains considerably more challenging because of the large and structured 32-bit candidate space. We present a profiled template attack for bit-exact recovery of an IEEE-754 single-precision neural-network weight from power measurements. The attack targets the floating-point multiplication between a known input and a first-layer weight. During profiling, multivariate Gaussian templates are learned from randomized network configurations using Hamming-weight classes of the multiplication result, while the remaining network parameters act as nuisance variables. To efficiently search the structured 32-bit floating-point candidate space, we use a hierarchical coarse-to-fine-to-exact procedure that progressively increases both the numerical and leakage-model resolution. Experiments on a ChipWhisperer-Lite with an Arm Cortex-M4 demonstrate recovery of the exact float32 representation of the target weight. In the evaluated setting, the attack reaches a bit-exact success rate of 99% with 171 traces and 100% from 263 traces onward. These results demonstrate that profiling can enable practical full-precision extraction of floating-point neural-network parameters from physical leakage.