{"id":"https://openalex.org/W4378191757","doi":"https://doi.org/10.1109/host55118.2023.10133375","title":"Bits to BNNs: Reconstructing FPGA ML-IP with Joint Bitstream and Side-Channel Analysis","display_name":"Bits to BNNs: Reconstructing FPGA ML-IP with Joint Bitstream and Side-Channel Analysis","publication_year":2023,"publication_date":"2023-05-01","ids":{"openalex":"https://openalex.org/W4378191757","doi":"https://doi.org/10.1109/host55118.2023.10133375"},"language":"en","primary_location":{"id":"doi:10.1109/host55118.2023.10133375","is_oa":false,"landing_page_url":"https://doi.org/10.1109/host55118.2023.10133375","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5067475716","display_name":"Brooks Olney","orcid":"https://orcid.org/0000-0001-9178-0783"},"institutions":[{"id":"https://openalex.org/I2613432","display_name":"University of South Florida","ror":"https://ror.org/032db5x82","country_code":"US","type":"education","lineage":["https://openalex.org/I2613432"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Brooks Olney","raw_affiliation_strings":["University of South Florida,Department of Computer Science and Engineering","Department of Computer Science and Engineering, University of South Florida"],"affiliations":[{"raw_affiliation_string":"University of South Florida,Department of Computer Science and Engineering","institution_ids":["https://openalex.org/I2613432"]},{"raw_affiliation_string":"Department of Computer Science and Engineering, University of South Florida","institution_ids":["https://openalex.org/I2613432"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5049193989","display_name":"Robert Karam","orcid":"https://orcid.org/0000-0002-2713-029X"},"institutions":[{"id":"https://openalex.org/I2613432","display_name":"University of South Florida","ror":"https://ror.org/032db5x82","country_code":"US","type":"education","lineage":["https://openalex.org/I2613432"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Robert Karam","raw_affiliation_strings":["University of South Florida,Department of Computer Science and Engineering","Department of Computer Science and Engineering, University of South Florida"],"affiliations":[{"raw_affiliation_string":"University of South Florida,Department of Computer Science and Engineering","institution_ids":["https://openalex.org/I2613432"]},{"raw_affiliation_string":"Department of Computer Science and Engineering, University of South Florida","institution_ids":["https://openalex.org/I2613432"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5067475716"],"corresponding_institution_ids":["https://openalex.org/I2613432"],"apc_list":null,"apc_paid":null,"fwci":0.616,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.60003141,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":94},"biblio":{"volume":null,"issue":null,"first_page":"238","last_page":"248"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10951","display_name":"Cryptographic Implementations and Security","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/bitstream","display_name":"Bitstream","score":0.8463069796562195},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8109634518623352},{"id":"https://openalex.org/keywords/field-programmable-gate-array","display_name":"Field-programmable gate array","score":0.7879864573478699},{"id":"https://openalex.org/keywords/side-channel-attack","display_name":"Side channel attack","score":0.6351472735404968},{"id":"https://openalex.org/keywords/leverage","display_name":"Leverage (statistics)","score":0.5840721726417542},{"id":"https://openalex.org/keywords/edge-device","display_name":"Edge device","score":0.5123237371444702},{"id":"https://openalex.org/keywords/enhanced-data-rates-for-gsm-evolution","display_name":"Enhanced Data Rates for GSM Evolution","score":0.47464022040367126},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.4655051827430725},{"id":"https://openalex.org/keywords/asset","display_name":"Asset (computer security)","score":0.41977572441101074},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.41655001044273376},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.3711646795272827},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.327308714389801},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3198493719100952},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.25686514377593994},{"id":"https://openalex.org/keywords/decoding-methods","display_name":"Decoding methods","score":0.17441880702972412},{"id":"https://openalex.org/keywords/telecommunications","display_name":"Telecommunications","score":0.1259118914604187},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.10345244407653809}],"concepts":[{"id":"https://openalex.org/C136695289","wikidata":"https://www.wikidata.org/wiki/Q415568","display_name":"Bitstream","level":3,"score":0.8463069796562195},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8109634518623352},{"id":"https://openalex.org/C42935608","wikidata":"https://www.wikidata.org/wiki/Q190411","display_name":"Field-programmable gate array","level":2,"score":0.7879864573478699},{"id":"https://openalex.org/C49289754","wikidata":"https://www.wikidata.org/wiki/Q2267081","display_name":"Side channel attack","level":3,"score":0.6351472735404968},{"id":"https://openalex.org/C153083717","wikidata":"https://www.wikidata.org/wiki/Q6535263","display_name":"Leverage (statistics)","level":2,"score":0.5840721726417542},{"id":"https://openalex.org/C138236772","wikidata":"https://www.wikidata.org/wiki/Q25098575","display_name":"Edge device","level":3,"score":0.5123237371444702},{"id":"https://openalex.org/C162307627","wikidata":"https://www.wikidata.org/wiki/Q204833","display_name":"Enhanced Data Rates for GSM Evolution","level":2,"score":0.47464022040367126},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.4655051827430725},{"id":"https://openalex.org/C76178495","wikidata":"https://www.wikidata.org/wiki/Q4808784","display_name":"Asset (computer security)","level":2,"score":0.41977572441101074},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.41655001044273376},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.3711646795272827},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.327308714389801},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3198493719100952},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.25686514377593994},{"id":"https://openalex.org/C57273362","wikidata":"https://www.wikidata.org/wiki/Q576722","display_name":"Decoding methods","level":2,"score":0.17441880702972412},{"id":"https://openalex.org/C76155785","wikidata":"https://www.wikidata.org/wiki/Q418","display_name":"Telecommunications","level":1,"score":0.1259118914604187},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.10345244407653809},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/host55118.2023.10133375","is_oa":false,"landing_page_url":"https://doi.org/10.1109/host55118.2023.10133375","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":41,"referenced_works":["https://openalex.org/W29626722","https://openalex.org/W2005006301","https://openalex.org/W2021705882","https://openalex.org/W2051267297","https://openalex.org/W2093154965","https://openalex.org/W2094756095","https://openalex.org/W2154909745","https://openalex.org/W2561981131","https://openalex.org/W2565125333","https://openalex.org/W2764337919","https://openalex.org/W2765235648","https://openalex.org/W2786070938","https://openalex.org/W2889111331","https://openalex.org/W2907463061","https://openalex.org/W2951308087","https://openalex.org/W2964318098","https://openalex.org/W2965565691","https://openalex.org/W2971542763","https://openalex.org/W3036522585","https://openalex.org/W3046830640","https://openalex.org/W3047375952","https://openalex.org/W3091214985","https://openalex.org/W3110986688","https://openalex.org/W3114482311","https://openalex.org/W3116515605","https://openalex.org/W3118164462","https://openalex.org/W3130641740","https://openalex.org/W3158697642","https://openalex.org/W3170159994","https://openalex.org/W3194922745","https://openalex.org/W4246001895","https://openalex.org/W4281664040","https://openalex.org/W4283069574","https://openalex.org/W4288100545","https://openalex.org/W4295262505","https://openalex.org/W6693397755","https://openalex.org/W6718639682","https://openalex.org/W6752265895","https://openalex.org/W6766787143","https://openalex.org/W6776294083","https://openalex.org/W6781522484"],"related_works":["https://openalex.org/W4319430423","https://openalex.org/W4390224957","https://openalex.org/W4323831234","https://openalex.org/W2544043553","https://openalex.org/W4311839959","https://openalex.org/W1982685694","https://openalex.org/W49599899","https://openalex.org/W2121309702","https://openalex.org/W3217774925","https://openalex.org/W2040087757"],"abstract_inverted_index":{"Energy-efficient":[0],"hardware":[1,37],"acceleration":[2],"platforms":[3],"for":[4,33,213],"edge":[5,214],"deployment":[6],"of":[7,48,89,104,111,129,192,198],"artificial":[8],"intelligence":[9],"(AI)":[10],"and":[11,30,102,154,202],"machine":[12],"learning":[13],"(ML)":[14],"applications":[15],"has":[16,119,188],"been":[17,120],"an":[18,76],"ongoing":[19],"research":[20],"endeavor.":[21],"Many":[22],"efforts":[23],"have":[24],"focused":[25],"on":[26,115],"optimizing":[27],"the":[28,45,50,54,69,90,95,105,109,126,163,167,178,184,190,196],"algorithms":[29],"compute":[31],"structures":[32],"use":[34],"in":[35,135],"resource-constrained":[36],"such":[38],"as":[39,68],"field-programmable":[40],"gate":[41],"arrays":[42],"(FPGAs).":[43],"Indeed,":[44],"difficult":[46],"nature":[47],"crafting":[49],"best":[51],"model":[52,56,96,113],"makes":[53],"ML":[55],"itself":[57],"a":[58,171],"valuable":[59,106],"intellectual":[60],"property":[61],"(IP)":[62],"asset.":[63],"This":[64,182],"can":[65,71,146],"be":[66,73,133,147],"problematic,":[67],"IP":[70],"now":[72],"exposed":[74],"to":[75,149,169,175,209],"attacker":[77],"through":[78],"physical":[79],"interfaces,":[80],"enabling":[81],"threats":[82],"from":[83,157,166,195],"side-channel":[84],"analysis":[85,145,201],"(SCA)":[86],"attacks.":[87],"One":[88],"more":[91],"devastating":[92],"attacks":[93],"is":[94,183,207],"extraction":[97,114],"attack,":[98],"which":[99],"threatens":[100],"piracy":[101],"cloning":[103],"IP.":[107],"While":[108],"problem":[110,191],"SCA-based":[112],"FPGA-deployed":[116],"neural":[117,151],"networks":[118],"well-studied,":[121],"it":[122],"does":[123],"not":[124],"capture":[125],"full":[127],"picture":[128],"what":[130],"vulnerabilities":[131],"may":[132],"present":[134],"those":[136],"platforms.":[137],"In":[138],"this":[139],"paper,":[140],"we":[141],"demonstrate":[142],"how":[143],"bitstream":[144,168,200],"used":[148],"obtain":[150],"network":[152,179],"parameters":[153],"connectivity":[155],"information":[156],"block":[158],"RAMs":[159],"(BRAMs).":[160],"We":[161],"leverage":[162],"knowledge":[164],"gleaned":[165],"mount":[170],"power":[172],"SCA":[173],"attack":[174],"further":[176,205],"refine":[177],"reconstruction":[180],"effort.":[181],"first":[185],"method":[186],"that":[187,204],"approached":[189],"ML-IP":[193],"theft":[194],"angle":[197],"FPGA":[199],"suggests":[203],"work":[206],"needed":[208],"improve":[210],"security":[211],"assurance":[212],"intelligence.":[215]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
