{"id":"https://openalex.org/W4212968594","doi":"https://doi.org/10.1109/host49136.2021.9702292","title":"Safeguarding the Intelligence of Neural Networks with Built-in Light-weight Integrity MArks (LIMA)","display_name":"Safeguarding the Intelligence of Neural Networks with Built-in Light-weight Integrity MArks (LIMA)","publication_year":2021,"publication_date":"2021-12-12","ids":{"openalex":"https://openalex.org/W4212968594","doi":"https://doi.org/10.1109/host49136.2021.9702292"},"language":"en","primary_location":{"id":"doi:10.1109/host49136.2021.9702292","is_oa":false,"landing_page_url":"https://doi.org/10.1109/host49136.2021.9702292","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5069422613","display_name":"Fateme S. Hosseini","orcid":"https://orcid.org/0000-0002-9091-3908"},"institutions":[{"id":"https://openalex.org/I86501945","display_name":"University of Delaware","ror":"https://ror.org/01sbq1a82","country_code":"US","type":"education","lineage":["https://openalex.org/I86501945"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Fateme S. Hosseini","raw_affiliation_strings":["University of Delaware"],"affiliations":[{"raw_affiliation_string":"University of Delaware","institution_ids":["https://openalex.org/I86501945"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100453144","display_name":"Qi Liu","orcid":"https://orcid.org/0000-0001-5378-6404"},"institutions":[{"id":"https://openalex.org/I186143895","display_name":"Lehigh University","ror":"https://ror.org/012afjb06","country_code":"US","type":"education","lineage":["https://openalex.org/I186143895"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Qi Liu","raw_affiliation_strings":["Lehigh University"],"affiliations":[{"raw_affiliation_string":"Lehigh University","institution_ids":["https://openalex.org/I186143895"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5052839989","display_name":"Fanruo Meng","orcid":"https://orcid.org/0000-0003-2876-2798"},"institutions":[{"id":"https://openalex.org/I86501945","display_name":"University of Delaware","ror":"https://ror.org/01sbq1a82","country_code":"US","type":"education","lineage":["https://openalex.org/I86501945"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Fanruo Meng","raw_affiliation_strings":["University of Delaware"],"affiliations":[{"raw_affiliation_string":"University of Delaware","institution_ids":["https://openalex.org/I86501945"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5016268650","display_name":"Chengmo Yang","orcid":"https://orcid.org/0000-0003-0978-1504"},"institutions":[{"id":"https://openalex.org/I86501945","display_name":"University of Delaware","ror":"https://ror.org/01sbq1a82","country_code":"US","type":"education","lineage":["https://openalex.org/I86501945"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Chengmo Yang","raw_affiliation_strings":["University of Delaware"],"affiliations":[{"raw_affiliation_string":"University of Delaware","institution_ids":["https://openalex.org/I86501945"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5067226050","display_name":"Wujie Wen","orcid":"https://orcid.org/0000-0003-0011-0675"},"institutions":[{"id":"https://openalex.org/I186143895","display_name":"Lehigh University","ror":"https://ror.org/012afjb06","country_code":"US","type":"education","lineage":["https://openalex.org/I186143895"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Wujie Wen","raw_affiliation_strings":["Lehigh University"],"affiliations":[{"raw_affiliation_string":"Lehigh University","institution_ids":["https://openalex.org/I186143895"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5069422613"],"corresponding_institution_ids":["https://openalex.org/I86501945"],"apc_list":null,"apc_paid":null,"fwci":0.5589,"has_fulltext":false,"cited_by_count":8,"citation_normalized_percentile":{"value":0.74553008,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"12"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10558","display_name":"Advancements in Semiconductor Devices and Circuit Design","score":0.9847000241279602,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.984499990940094,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/safeguarding","display_name":"Safeguarding","score":0.9282820224761963},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5989006161689758},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5687171220779419},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4764041006565094},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3261496424674988},{"id":"https://openalex.org/keywords/medicine","display_name":"Medicine","score":0.12338709831237793}],"concepts":[{"id":"https://openalex.org/C2776743756","wikidata":"https://www.wikidata.org/wiki/Q5097921","display_name":"Safeguarding","level":2,"score":0.9282820224761963},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5989006161689758},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5687171220779419},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4764041006565094},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3261496424674988},{"id":"https://openalex.org/C71924100","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medicine","level":0,"score":0.12338709831237793},{"id":"https://openalex.org/C159110408","wikidata":"https://www.wikidata.org/wiki/Q121176","display_name":"Nursing","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/host49136.2021.9702292","is_oa":false,"landing_page_url":"https://doi.org/10.1109/host49136.2021.9702292","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G7367005836","display_name":null,"funder_award_id":"1909854,2011236","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G7746399254","display_name":null,"funder_award_id":"2964.001","funder_id":"https://openalex.org/F4320306087","funder_display_name":"Semiconductor Research Corporation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320306087","display_name":"Semiconductor Research Corporation","ror":"https://ror.org/047z4n946"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":47,"referenced_works":["https://openalex.org/W1673923490","https://openalex.org/W1686810756","https://openalex.org/W1945616565","https://openalex.org/W2097117768","https://openalex.org/W2108598243","https://openalex.org/W2119112357","https://openalex.org/W2157116240","https://openalex.org/W2180612164","https://openalex.org/W2194775991","https://openalex.org/W2243397390","https://openalex.org/W2294710185","https://openalex.org/W2489529491","https://openalex.org/W2562137921","https://openalex.org/W2625267941","https://openalex.org/W2807401673","https://openalex.org/W2807835252","https://openalex.org/W2945145734","https://openalex.org/W2945476062","https://openalex.org/W2948811271","https://openalex.org/W2948833786","https://openalex.org/W2962726564","https://openalex.org/W2963389226","https://openalex.org/W2963612069","https://openalex.org/W2974891422","https://openalex.org/W2981860227","https://openalex.org/W3009692632","https://openalex.org/W3025011581","https://openalex.org/W3034665124","https://openalex.org/W3044504496","https://openalex.org/W3049152512","https://openalex.org/W3082761341","https://openalex.org/W3091984031","https://openalex.org/W3092411122","https://openalex.org/W3105648728","https://openalex.org/W3112604890","https://openalex.org/W3112790703","https://openalex.org/W3128389908","https://openalex.org/W6637162671","https://openalex.org/W6637373629","https://openalex.org/W6640425456","https://openalex.org/W6729756640","https://openalex.org/W6744511767","https://openalex.org/W6753937820","https://openalex.org/W6763559720","https://openalex.org/W6775611046","https://openalex.org/W6781151384","https://openalex.org/W6787639732"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W4387497383","https://openalex.org/W3183948672","https://openalex.org/W3173606202","https://openalex.org/W3110381201","https://openalex.org/W2948807893","https://openalex.org/W2778153218","https://openalex.org/W2758277628","https://openalex.org/W2748952813","https://openalex.org/W1531601525"],"abstract_inverted_index":{"As":[0],"Deep":[1],"Neural":[2],"Networks":[3],"(DNNs)":[4],"are":[5,19],"widely":[6],"adopted":[7],"in":[8,97,137],"many":[9],"real-world":[10],"applications,":[11],"their":[12],"integrity":[13,64],"becomes":[14],"critical.":[15],"Unfortunately,":[16],"DNN":[17,72,91,117],"models":[18],"not":[20,175],"resilient":[21],"to":[22,128],"fault":[23],"injection":[24],"attacks.":[25],"In":[26],"particular,":[27],"recent":[28],"work":[29],"has":[30,158],"shown":[31],"that":[32,153],"Bit-Flip":[33],"Attack":[34],"(BFA)":[35],"can":[36,120],"completely":[37,176],"destroy":[38],"the":[39,63,66,75,156,162],"intelligence":[40],"of":[41,65,71,78,115,140,161],"DNNs":[42,167],"with":[43,124,168],"a":[44,89],"few":[45],"carefully":[46],"injected":[47],"bit-flips.":[48],"To":[49],"defend":[50],"against":[51],"this":[52],"threat,":[53],"we":[54],"propose":[55],"Light-weight":[56],"Integrity":[57],"MArks":[58],"(LIMA)":[59],"framework":[60],"which":[61],"protects":[62],"most":[67],"significant":[68],"bits":[69],"(MSBs)":[70],"weights":[73,93],"-":[74],"main":[76],"target":[77],"BFA.":[79,130],"Such":[80],"protection":[81],"is":[82,171],"enabled":[83],"by":[84],"embedding":[85,147],"specific":[86],"property":[87],"into":[88],"trained":[90],"model&#x0027;s":[92],"before":[94],"deploying":[95],"it":[96,105],"hardware.":[98],"LIMA":[99,170],"outperforms":[100],"existing":[101],"BFA":[102],"countermeasures":[103],"as":[104],"requires":[106],"no":[107,110],"retraining,":[108],"imposes":[109],"storage":[111],"overhead,":[112],"offers":[113],"full-coverage":[114],"all":[116],"layers,":[118],"and":[119,142],"be":[121],"easily":[122],"verified":[123],"Multiply-Accumulate":[125],"(MAC)":[126],"operations":[127],"detect":[129],"Our":[131],"comprehensive":[132],"study":[133],"demonstrates":[134],"100%":[135],"effectiveness":[136],"detecting":[138],"chains":[139],"bit-flips":[141],"near-zero":[143],"accuracy":[144],"loss":[145],"for":[146],"LIMA.":[148],"The":[149],"eresults":[150],"also":[151],"show":[152],"even":[154],"when":[155],"attacker":[157],"complete":[159],"knowledge":[160],"proposed":[163],"defense":[164],"plan,":[165],"attacking":[166],"built-in":[169],"extremely":[172],"difficult,":[173],"if":[174],"impossible.":[177]},"counts_by_year":[{"year":2025,"cited_by_count":4},{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":3}],"updated_date":"2026-03-09T08:58:05.943551","created_date":"2025-10-10T00:00:00"}
