{"id":"https://openalex.org/W4224919922","doi":"https://doi.org/10.1109/icassp43922.2022.9747337","title":"SparseBFA: Attacking Sparse Deep Neural Networks with the Worst-Case Bit Flips on Coordinates","display_name":"SparseBFA: Attacking Sparse Deep Neural Networks with the Worst-Case Bit Flips on Coordinates","publication_year":2022,"publication_date":"2022-04-27","ids":{"openalex":"https://openalex.org/W4224919922","doi":"https://doi.org/10.1109/icassp43922.2022.9747337"},"language":"en","primary_location":{"id":"doi:10.1109/icassp43922.2022.9747337","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icassp43922.2022.9747337","pdf_url":null,"source":{"id":"https://openalex.org/S4363607702","display_name":"ICASSP 2022 - 2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ICASSP 2022 - 2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101710525","display_name":"Kyungmi Lee","orcid":"https://orcid.org/0000-0003-3304-4627"},"institutions":[{"id":"https://openalex.org/I63966007","display_name":"Massachusetts Institute of Technology","ror":"https://ror.org/042nb2s44","country_code":"US","type":"education","lineage":["https://openalex.org/I63966007"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Kyungmi Lee","raw_affiliation_strings":["Massachusetts Institute of Technology,Department of Electrical Engineering and Computer Science,Cambridge,USA","Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, USA"],"affiliations":[{"raw_affiliation_string":"Massachusetts Institute of Technology,Department of Electrical Engineering and Computer Science,Cambridge,USA","institution_ids":["https://openalex.org/I63966007"]},{"raw_affiliation_string":"Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, USA","institution_ids":["https://openalex.org/I63966007"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5084128470","display_name":"Anantha P. Chandrakasan","orcid":"https://orcid.org/0000-0002-5977-2748"},"institutions":[{"id":"https://openalex.org/I63966007","display_name":"Massachusetts Institute of Technology","ror":"https://ror.org/042nb2s44","country_code":"US","type":"education","lineage":["https://openalex.org/I63966007"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Anantha P. Chandrakasan","raw_affiliation_strings":["Massachusetts Institute of Technology,Department of Electrical Engineering and Computer Science,Cambridge,USA","Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, USA"],"affiliations":[{"raw_affiliation_string":"Massachusetts Institute of Technology,Department of Electrical Engineering and Computer Science,Cambridge,USA","institution_ids":["https://openalex.org/I63966007"]},{"raw_affiliation_string":"Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, USA","institution_ids":["https://openalex.org/I63966007"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5101710525"],"corresponding_institution_ids":["https://openalex.org/I63966007"],"apc_list":null,"apc_paid":null,"fwci":1.26,"has_fulltext":false,"cited_by_count":13,"citation_normalized_percentile":{"value":0.81216875,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"4208","last_page":"4212"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9976999759674072,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9904999732971191,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/pruning","display_name":"Pruning","score":0.7082762122154236},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.695365309715271},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.6924595832824707},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5941373705863953},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.553985595703125},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.5370622277259827},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.5343700051307678},{"id":"https://openalex.org/keywords/bit","display_name":"Bit (key)","score":0.45795950293540955},{"id":"https://openalex.org/keywords/matrix","display_name":"Matrix (chemical analysis)","score":0.45244520902633667},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.3478814959526062},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.27098143100738525},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.09246182441711426}],"concepts":[{"id":"https://openalex.org/C108010975","wikidata":"https://www.wikidata.org/wiki/Q500094","display_name":"Pruning","level":2,"score":0.7082762122154236},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.695365309715271},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.6924595832824707},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5941373705863953},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.553985595703125},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5370622277259827},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.5343700051307678},{"id":"https://openalex.org/C117011727","wikidata":"https://www.wikidata.org/wiki/Q1278488","display_name":"Bit (key)","level":2,"score":0.45795950293540955},{"id":"https://openalex.org/C106487976","wikidata":"https://www.wikidata.org/wiki/Q685816","display_name":"Matrix (chemical analysis)","level":2,"score":0.45244520902633667},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.3478814959526062},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.27098143100738525},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.09246182441711426},{"id":"https://openalex.org/C192562407","wikidata":"https://www.wikidata.org/wiki/Q228736","display_name":"Materials science","level":0,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.0},{"id":"https://openalex.org/C159985019","wikidata":"https://www.wikidata.org/wiki/Q181790","display_name":"Composite material","level":1,"score":0.0},{"id":"https://openalex.org/C6557445","wikidata":"https://www.wikidata.org/wiki/Q173113","display_name":"Agronomy","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icassp43922.2022.9747337","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icassp43922.2022.9747337","pdf_url":null,"source":{"id":"https://openalex.org/S4363607702","display_name":"ICASSP 2022 - 2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ICASSP 2022 - 2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320324571","display_name":"Korea Foundation for Advanced Studies","ror":"https://ror.org/0556dev32"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":24,"referenced_works":["https://openalex.org/W2037227137","https://openalex.org/W2117539524","https://openalex.org/W2119144962","https://openalex.org/W2193145675","https://openalex.org/W2194775991","https://openalex.org/W2576037784","https://openalex.org/W2625457103","https://openalex.org/W2707890836","https://openalex.org/W2939057911","https://openalex.org/W2948811271","https://openalex.org/W2963163009","https://openalex.org/W2963674932","https://openalex.org/W2964137095","https://openalex.org/W2981860227","https://openalex.org/W3082761341","https://openalex.org/W3106250896","https://openalex.org/W3118608800","https://openalex.org/W3154181338","https://openalex.org/W4245276998","https://openalex.org/W6732215895","https://openalex.org/W6739917289","https://openalex.org/W6763559720","https://openalex.org/W6775611046","https://openalex.org/W6787972765"],"related_works":["https://openalex.org/W17155033","https://openalex.org/W3207760230","https://openalex.org/W1496222301","https://openalex.org/W4312814274","https://openalex.org/W1590307681","https://openalex.org/W2536018345","https://openalex.org/W2906845177","https://openalex.org/W4200107511","https://openalex.org/W2891427086","https://openalex.org/W1968625315"],"abstract_inverted_index":{"Deep":[0],"neural":[1],"networks":[2],"(DNNs)":[3],"are":[4,64,90],"shown":[5],"to":[6,9,27,55,106],"be":[7],"vulnerable":[8],"a":[10,50,74],"few":[11],"carefully":[12],"chosen":[13],"bit":[14,20,56],"flips":[15,57],"in":[16,116],"their":[17,59],"parameters,":[18],"and":[19],"flip":[21],"attacks":[22],"(BFAs)":[23],"exploit":[24],"such":[25],"vulnerability":[26,54],"degrade":[28],"the":[29,80,86,101,107,120],"performance":[30,102],"of":[31,53,61,77,82,88,103,119],"DNNs.":[32],"In":[33],"this":[34],"work,":[35],"we":[36,98],"show":[37],"that":[38,43,71,100],"DNNs":[39,89,104],"with":[40],"high":[41],"sparsity":[42],"typically":[44],"result":[45],"from":[46],"weight":[47],"pruning":[48],"have":[49],"unique":[51],"source":[52],"when":[58,85],"coordinates":[60,81],"nonzero":[62,83],"weights":[63,84],"attacked.":[65],"We":[66],"propose":[67],"SparseBFA,":[68,97],"an":[69],"algorithm":[70],"searches":[72],"for":[73],"small":[75],"number":[76],"bits":[78],"among":[79],"parameters":[87],"stored":[91],"using":[92],"sparse":[93],"matrix":[94],"formats.":[95],"Using":[96],"find":[99],"drops":[105],"random-guess":[108],"level":[109],"by":[110],"flipping":[111],"less":[112],"than":[113],"0.00005%":[114],"(1":[115],"2":[117],"million)":[118],"total":[121],"bits.":[122]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":4},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":5},{"year":2022,"cited_by_count":1}],"updated_date":"2026-03-09T08:58:05.943551","created_date":"2025-10-10T00:00:00"}
