상세 보기
ARMOR: First-Order Masking of Activation and ArgMax Gadgets for Side-Channel Resistant Neural Networks
- Shin, Won Geun;
- Lee, Jeonghwan;
- Jung, Sangyun;
- Kim, Heeseok
SCOPUS
0초록
The widespread deployment of AI applications on wearable and IoT devices has raised security concerns, including model stealing and personal information leakage. Model stealing attacks rely on issuing queries to the target model and analyzing the corresponding outputs. Side-channel analysis, traditionally used to attack cryptographic algorithms, can now facilitate the performance of model stealing attacks on neural networks (NN), by recovering their architectures and parameters. This exposure to model stealing presents risks such as intellectual property theft and adversarial attacks. Masking, a widely used countermeasure for side-channel attacks, has recently been adapted to NN to protect secret model information. However, existing masked NNs incur significant computational overhead or lead to accuracy degradation. In this work, we focus on reducing the main degradation in masking computational costs of non-linear operations specifically activation and argmax. As both operations hinge on sign bit extraction, we achieved an efficient realization using LuTs. Furthermore, we systematically identify and remove flawed masking gadgets that cause accuracy degradation and subsequently apply our gadgets to binarized neural network (BNN). As a result, our proposed BNN implementation securely maintains model accuracy while achieving a 42% performance improvement compared to state-of-the-art software-based masking methods [AWDF21]. © 2026, Ruhr-University of Bochum. All rights reserved.
키워드
- 제목
- ARMOR: First-Order Masking of Activation and ArgMax Gadgets for Side-Channel Resistant Neural Networks
- 저자
- Shin, Won Geun; Lee, Jeonghwan; Jung, Sangyun; Kim, Heeseok
- 발행일
- 2026-04-23
- 유형
- Article
- 권
- 2026
- 호
- 2
- 페이지
- 106 ~ 131