{"id":"https://openalex.org/W7106159637","doi":"https://doi.org/10.1109/iccad66269.2025.11240849","title":"Non-Negative AdderNet: Algorithm-Hardware Co-design for Lightweight Defense of Adversarial Bit-Flip Attacks","display_name":"Non-Negative AdderNet: Algorithm-Hardware Co-design for Lightweight Defense of Adversarial Bit-Flip Attacks","publication_year":2025,"publication_date":"2025-10-26","ids":{"openalex":"https://openalex.org/W7106159637","doi":"https://doi.org/10.1109/iccad66269.2025.11240849"},"language":null,"primary_location":{"id":"doi:10.1109/iccad66269.2025.11240849","is_oa":false,"landing_page_url":"https://doi.org/10.1109/iccad66269.2025.11240849","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE/ACM International Conference On Computer Aided Design (ICCAD)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Yunxiang Zhang","orcid":null},"institutions":[{"id":"https://openalex.org/I123946342","display_name":"Binghamton University","ror":"https://ror.org/008rmbt77","country_code":"US","type":"education","lineage":["https://openalex.org/I123946342"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Yunxiang Zhang","raw_affiliation_strings":["Binghamton University,Binghamton,New York,USA"],"affiliations":[{"raw_affiliation_string":"Binghamton University,Binghamton,New York,USA","institution_ids":["https://openalex.org/I123946342"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Sabbir Ahmed","orcid":null},"institutions":[{"id":"https://openalex.org/I123946342","display_name":"Binghamton University","ror":"https://ror.org/008rmbt77","country_code":"US","type":"education","lineage":["https://openalex.org/I123946342"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Sabbir Ahmed","raw_affiliation_strings":["Binghamton University,Binghamton,New York,USA"],"affiliations":[{"raw_affiliation_string":"Binghamton University,Binghamton,New York,USA","institution_ids":["https://openalex.org/I123946342"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Abeer Matar A Almalky","orcid":null},"institutions":[{"id":"https://openalex.org/I123946342","display_name":"Binghamton University","ror":"https://ror.org/008rmbt77","country_code":"US","type":"education","lineage":["https://openalex.org/I123946342"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Abeer Matar A Almalky","raw_affiliation_strings":["Binghamton University,Binghamton,New York,USA"],"affiliations":[{"raw_affiliation_string":"Binghamton University,Binghamton,New York,USA","institution_ids":["https://openalex.org/I123946342"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Adnan Siraj Rakin","orcid":null},"institutions":[{"id":"https://openalex.org/I123946342","display_name":"Binghamton University","ror":"https://ror.org/008rmbt77","country_code":"US","type":"education","lineage":["https://openalex.org/I123946342"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Adnan Siraj Rakin","raw_affiliation_strings":["Binghamton University,Binghamton,New York,USA"],"affiliations":[{"raw_affiliation_string":"Binghamton University,Binghamton,New York,USA","institution_ids":["https://openalex.org/I123946342"]}]},{"author_position":"last","author":{"id":null,"display_name":"Wenfeng Zhao","orcid":null},"institutions":[{"id":"https://openalex.org/I123946342","display_name":"Binghamton University","ror":"https://ror.org/008rmbt77","country_code":"US","type":"education","lineage":["https://openalex.org/I123946342"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Wenfeng Zhao","raw_affiliation_strings":["Binghamton University,Binghamton,New York,USA"],"affiliations":[{"raw_affiliation_string":"Binghamton University,Binghamton,New York,USA","institution_ids":["https://openalex.org/I123946342"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I123946342"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.77241312,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.6930999755859375,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.6930999755859375,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.19120000302791595,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.03220000118017197,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.6664999723434448},{"id":"https://openalex.org/keywords/resilience","display_name":"Resilience (materials science)","score":0.5569999814033508},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.489300012588501},{"id":"https://openalex.org/keywords/encoding","display_name":"Encoding (memory)","score":0.478300005197525},{"id":"https://openalex.org/keywords/multiplicative-function","display_name":"Multiplicative function","score":0.37439998984336853},{"id":"https://openalex.org/keywords/threat-model","display_name":"Threat model","score":0.3725999891757965}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.784600019454956},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.6664999723434448},{"id":"https://openalex.org/C2779585090","wikidata":"https://www.wikidata.org/wiki/Q3457762","display_name":"Resilience (materials science)","level":2,"score":0.5569999814033508},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.489300012588501},{"id":"https://openalex.org/C125411270","wikidata":"https://www.wikidata.org/wiki/Q18653","display_name":"Encoding (memory)","level":2,"score":0.478300005197525},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3804999887943268},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.3785000145435333},{"id":"https://openalex.org/C42747912","wikidata":"https://www.wikidata.org/wiki/Q1048447","display_name":"Multiplicative function","level":2,"score":0.37439998984336853},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.3725999891757965},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.34790000319480896},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.3089999854564667},{"id":"https://openalex.org/C81363708","wikidata":"https://www.wikidata.org/wiki/Q17084460","display_name":"Convolutional neural network","level":2,"score":0.30640000104904175},{"id":"https://openalex.org/C49289754","wikidata":"https://www.wikidata.org/wiki/Q2267081","display_name":"Side channel attack","level":3,"score":0.3009999990463257},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.27889999747276306},{"id":"https://openalex.org/C57273362","wikidata":"https://www.wikidata.org/wiki/Q576722","display_name":"Decoding methods","level":2,"score":0.2685999870300293},{"id":"https://openalex.org/C168167062","wikidata":"https://www.wikidata.org/wiki/Q1117970","display_name":"Component (thermodynamics)","level":2,"score":0.262800008058548}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/iccad66269.2025.11240849","is_oa":false,"landing_page_url":"https://doi.org/10.1109/iccad66269.2025.11240849","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE/ACM International Conference On Computer Aided Design (ICCAD)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.7367734313011169,"display_name":"Affordable and clean energy","id":"https://metadata.un.org/sdg/7"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320332681","display_name":"Binghamton University","ror":"https://ror.org/008rmbt77"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":16,"referenced_works":["https://openalex.org/W1903029394","https://openalex.org/W2108598243","https://openalex.org/W2157116240","https://openalex.org/W2963122961","https://openalex.org/W2981860227","https://openalex.org/W3034344052","https://openalex.org/W3034579202","https://openalex.org/W3126952258","https://openalex.org/W3199792160","https://openalex.org/W3213793813","https://openalex.org/W4214737857","https://openalex.org/W4380875579","https://openalex.org/W4384664508","https://openalex.org/W4390872667","https://openalex.org/W4404134104","https://openalex.org/W4404852812"],"related_works":[],"abstract_inverted_index":{"AdderNet":[0,79,94,199],"emerges":[1],"with":[2,17,124],"superior":[3],"hardware":[4,76],"efficiencies":[5],"compared":[6],"to":[7,54,67,130,185],"Convolutional":[8],"Neural":[9],"Networks":[10],"(CNNs)":[11],"by":[12],"replacing":[13],"the":[14,36,57,75,82,144,162,168,192],"multiplicative":[15],"operations":[16],"energy-efficient":[18],"additive":[19],"alternatives.":[20],"Nevertheless,":[21],"AdderNet\u2019s":[22,52],"security":[23],"exploration":[24],"remains":[25],"underexplored,":[26],"especially":[27],"against":[28,87,188,200],"emerging":[29],"adversarial":[30],"weight":[31,45,115],"perturbation":[32],"attacks,":[33],"such":[34],"as":[35],"Bit-Flip":[37],"Attack":[38],"(BFA),":[39],"which":[40],"injects":[41],"memory":[42],"faults":[43],"into":[44],"bits.":[46],"In":[47],"this":[48],"paper,":[49],"we":[50,89,150],"investigate":[51],"vulnerabilities":[53],"BFA":[55,68,155,159,177],"for":[56],"first":[58],"time":[59,84],"and":[60,80,118,134,137,156,179,197],"discover":[61],"that":[62],"it":[63,111],"is":[64],"more":[65,182],"susceptible":[66],"than":[69],"its":[70],"CNN":[71],"counterpart.":[72],"To":[73,141],"utilize":[74],"efficiency":[77],"of":[78,106,139,146,194],"at":[81],"same":[83],"improve":[85],"resiliency":[86],"BFA,":[88],"propose":[90],"a":[91,113,120,153],"novel":[92,121],"Non-Negative":[93],"${\\text{":[95,101],"(}}\\overleftarrow":[96,102],"{{\\text{NNAN}}}":[97,103,174],"{\\text{)}}$":[98,104],"model.":[99],"Proposed":[100],"consists":[105],"two":[107],"key":[108],"components:":[109],"i)":[110],"incorporates":[112],"non-positive":[114,127],"encoding":[116],"technique,":[117],"ii)":[119],"accelerator":[122],"design":[123,193],"an":[125,157],"integrated":[126],"decoder":[128],"(NPD)":[129],"achieve":[131],"hardware-level":[132],"lightweight":[133],"runtime":[135],"detection":[136],"correction":[138],"BFA.":[140,201],"further":[142],"test":[143],"resilience":[145],"our":[147],"proposed":[148,169,172],"defense,":[149],"perform":[151],"both":[152,195],"baseline":[154],"advanced":[158],"(BFA+),":[160],"where":[161],"attacker":[163],"has":[164],"sufficient":[165],"knowledge":[166],"about":[167],"defense.":[170],"Our":[171],"$\\overleftarrow":[173],"$":[175],"makes":[176],"obsolete":[178],"requires":[180],"many":[181],"attack":[183],"cycles":[184],"be":[186],"compromised":[187],"BFA+,":[189],"successfully":[190],"enabling":[191],"hardware-efficient":[196],"secure":[198]},"counts_by_year":[],"updated_date":"2026-04-09T08:11:56.329763","created_date":"2025-11-20T00:00:00"}
