{"id":"https://openalex.org/W7162647591","doi":"https://doi.org/10.1109/isqed69900.2026.11534688","title":"Evolving Landscape of Attacks on AI Hardware and Robust Defenses","display_name":"Evolving Landscape of Attacks on AI Hardware and Robust Defenses","publication_year":2026,"publication_date":"2026-04-08","ids":{"openalex":"https://openalex.org/W7162647591","doi":"https://doi.org/10.1109/isqed69900.2026.11534688"},"language":null,"primary_location":{"id":"doi:10.1109/isqed69900.2026.11534688","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isqed69900.2026.11534688","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2026 27th International Symposium on Quality Electronic Design (ISQED)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5137288636","display_name":"Habibur Rahaman","orcid":null},"institutions":[{"id":"https://openalex.org/I33213144","display_name":"University of Florida","ror":"https://ror.org/02y3ad647","country_code":"US","type":"education","lineage":["https://openalex.org/I33213144"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Habibur Rahaman","raw_affiliation_strings":["University of Florida,Department of Electrical and Computer Engineering,Gainesville,FL,USA,32611"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Florida,Department of Electrical and Computer Engineering,Gainesville,FL,USA,32611","institution_ids":["https://openalex.org/I33213144"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5092645197","display_name":"Sudipta Paria","orcid":"https://orcid.org/0009-0002-7726-8032"},"institutions":[{"id":"https://openalex.org/I33213144","display_name":"University of Florida","ror":"https://ror.org/02y3ad647","country_code":"US","type":"education","lineage":["https://openalex.org/I33213144"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Sudipta Paria","raw_affiliation_strings":["University of Florida,Department of Electrical and Computer Engineering,Gainesville,FL,USA,32611"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Florida,Department of Electrical and Computer Engineering,Gainesville,FL,USA,32611","institution_ids":["https://openalex.org/I33213144"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5137267523","display_name":"Atri Chatterjee","orcid":null},"institutions":[{"id":"https://openalex.org/I33213144","display_name":"University of Florida","ror":"https://ror.org/02y3ad647","country_code":"US","type":"education","lineage":["https://openalex.org/I33213144"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Atri Chatterjee","raw_affiliation_strings":["University of Florida,Department of Electrical and Computer Engineering,Gainesville,FL,USA,32611"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Florida,Department of Electrical and Computer Engineering,Gainesville,FL,USA,32611","institution_ids":["https://openalex.org/I33213144"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5137296954","display_name":"Swarup Bhunia","orcid":null},"institutions":[{"id":"https://openalex.org/I33213144","display_name":"University of Florida","ror":"https://ror.org/02y3ad647","country_code":"US","type":"education","lineage":["https://openalex.org/I33213144"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Swarup Bhunia","raw_affiliation_strings":["University of Florida,Department of Electrical and Computer Engineering,Gainesville,FL,USA,32611"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Florida,Department of Electrical and Computer Engineering,Gainesville,FL,USA,32611","institution_ids":["https://openalex.org/I33213144"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.86155343,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.8034999966621399,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.8034999966621399,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.046799998730421066,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.02319999970495701,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.3133000135421753},{"id":"https://openalex.org/keywords/field","display_name":"Field (mathematics)","score":0.2703999876976013},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.2578999996185303},{"id":"https://openalex.org/keywords/work","display_name":"Work (physics)","score":0.25769999623298645}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5940999984741211},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3133000135421753},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3077999949455261},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.2921000123023987},{"id":"https://openalex.org/C9652623","wikidata":"https://www.wikidata.org/wiki/Q190109","display_name":"Field (mathematics)","level":2,"score":0.2703999876976013},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.2671000063419342},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.2578999996185303},{"id":"https://openalex.org/C18762648","wikidata":"https://www.wikidata.org/wiki/Q42213","display_name":"Work (physics)","level":2,"score":0.25769999623298645},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.2542000114917755},{"id":"https://openalex.org/C99498987","wikidata":"https://www.wikidata.org/wiki/Q2210247","display_name":"Noise (video)","level":3,"score":0.25029999017715454}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/isqed69900.2026.11534688","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isqed69900.2026.11534688","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2026 27th International Symposium on Quality Electronic Design (ISQED)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/11","score":0.6005138754844666,"display_name":"Sustainable cities and communities"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":30,"referenced_works":["https://openalex.org/W1897761346","https://openalex.org/W2085992264","https://openalex.org/W2154909745","https://openalex.org/W2157116240","https://openalex.org/W2161998562","https://openalex.org/W2289252105","https://openalex.org/W2753783305","https://openalex.org/W2767079719","https://openalex.org/W2807835252","https://openalex.org/W2934843808","https://openalex.org/W2981860227","https://openalex.org/W3036243698","https://openalex.org/W3210158641","https://openalex.org/W4246001895","https://openalex.org/W4319596548","https://openalex.org/W4382467883","https://openalex.org/W4386385595","https://openalex.org/W4388927244","https://openalex.org/W4390969331","https://openalex.org/W4391381974","https://openalex.org/W4393140720","https://openalex.org/W4404871640","https://openalex.org/W4408442410","https://openalex.org/W4408442455","https://openalex.org/W4408442814","https://openalex.org/W4408749718","https://openalex.org/W4409213760","https://openalex.org/W4409625805","https://openalex.org/W4410582567","https://openalex.org/W4414197381"],"related_works":[],"abstract_inverted_index":{"The":[0],"rapid":[1],"deployment":[2],"of":[3,13,31,96,117,176],"artificial":[4],"intelligence":[5],"(AI)":[6],"systems":[7],"has":[8],"introduced":[9],"a":[10,93],"new":[11],"class":[12],"security":[14],"vulnerabilities":[15],"rooted":[16],"in":[17,101],"hardware":[18,81,97,137,196],"behavior.":[19],"Unlike":[20],"software-only":[21],"threats,":[22],"hardware-oriented":[23],"attacks":[24],"exploit":[25],"physical":[26],"effects":[27],"and":[28,77,80,126,136,144,150,187,193],"micro-architectural":[29],"characteristics":[30],"the":[32,114,127],"computing":[33],"substrate,":[34],"allowing":[35],"adversaries":[36],"to":[37,60],"induce":[38],"faults,":[39],"extract":[40],"sensitive":[41],"information,":[42],"or":[43,70,86,107],"stealthily":[44],"manipulate":[45],"inference":[46],"outcomes.":[47],"Recent":[48],"studies":[49],"show":[50],"that":[51,172],"deep":[52],"neural":[53,177],"network":[54],"(DNN)":[55],"accelerators":[56,123],"are":[57],"particularly":[58],"susceptible":[59],"such":[61],"attacks,":[62],"including":[63],"selective":[64],"bit-flip":[65],"fault":[66],"injection":[67],"via":[68],"Rowhammer":[69],"voltage":[71],"glitching,":[72],"side-channel":[73],"leakage":[74],"through":[75],"power":[76],"electromagnetic":[78],"emanations,":[79],"Trojan":[82,138],"insertion":[83],"during":[84],"fabrication":[85],"third-party":[87],"intellectual":[88],"property":[89],"(IP)":[90],"integration.":[91],"Even":[92],"small":[94],"number":[95],"modifications":[98],"can":[99],"result":[100],"severe":[102],"accuracy":[103],"degradation,":[104],"targeted":[105],"misclassification,":[106],"denial-of-service.":[108],"In":[109],"this":[110],"paper,":[111],"we":[112],"cover":[113],"evolving":[115],"landscape":[116],"hardware-based":[118],"attack":[119],"vectors":[120],"targeting":[121],"AI":[122,164,195],"(e.g.,":[124],"DNNs)":[125],"corresponding":[128],"defense":[129],"methods.":[130],"We":[131,155,183],"systematically":[132],"categorize":[133],"fault-injection,":[134],"side-channel,":[135],"attacks;":[139],"examine":[140],"their":[141],"threat":[142],"models":[143],"practical":[145],"impact":[146],"on":[147],"DNN":[148],"inference;":[149],"review":[151],"existing":[152],"protection":[153],"techniques.":[154],"emphasize":[156],"lightweight":[157],"defenses":[158],"for":[159,179],"resource-constrained":[160],"edge":[161],"platforms,":[162],"highlighting":[163],"Performance":[165],"Counters":[166],"as":[167],"passive,":[168],"low-overhead":[169],"observability":[170],"primitives":[171],"capture":[173],"execution-level":[174],"signatures":[175],"workloads":[178],"runtime":[180],"anomaly":[181],"detection.":[182],"outline":[184],"open":[185],"challenges":[186],"future":[188],"research":[189],"directions":[190],"toward":[191],"resilient":[192],"trustworthy":[194],"systems.":[197]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-05-29T00:00:00"}
