{"id":"https://openalex.org/W3026196565","doi":"https://doi.org/10.1109/tcad.2020.2995347","title":"Practical Attacks on Deep Neural Networks by Memory Trojaning","display_name":"Practical Attacks on Deep Neural Networks by Memory Trojaning","publication_year":2020,"publication_date":"2020-05-19","ids":{"openalex":"https://openalex.org/W3026196565","doi":"https://doi.org/10.1109/tcad.2020.2995347","mag":"3026196565"},"language":"en","primary_location":{"id":"doi:10.1109/tcad.2020.2995347","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tcad.2020.2995347","pdf_url":null,"source":{"id":"https://openalex.org/S100835903","display_name":"IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems","issn_l":"0278-0070","issn":["0278-0070","1937-4151"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101964036","display_name":"Xing Hu","orcid":"https://orcid.org/0000-0002-9979-0561"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210090176","display_name":"Institute of Computing Technology","ror":"https://ror.org/0090r4d87","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210090176"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Xing Hu","raw_affiliation_strings":["State Key Laboratory of Computer Architecture, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"State Key Laboratory of Computer Architecture, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210090176","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5107593559","display_name":"Yang Zhao","orcid":"https://orcid.org/0000-0001-8023-1551"},"institutions":[{"id":"https://openalex.org/I74775410","display_name":"Rice University","ror":"https://ror.org/008zs3103","country_code":"US","type":"education","lineage":["https://openalex.org/I74775410"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yang Zhao","raw_affiliation_strings":["Rice University, Houston, TX, USA"],"affiliations":[{"raw_affiliation_string":"Rice University, Houston, TX, USA","institution_ids":["https://openalex.org/I74775410"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5047545398","display_name":"Lei Deng","orcid":"https://orcid.org/0000-0002-5172-9411"},"institutions":[{"id":"https://openalex.org/I154570441","display_name":"University of California, Santa Barbara","ror":"https://ror.org/02t274463","country_code":"US","type":"education","lineage":["https://openalex.org/I154570441"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Lei Deng","raw_affiliation_strings":["University of California at Santa Barbara, Santa Barbara, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California at Santa Barbara, Santa Barbara, CA, USA","institution_ids":["https://openalex.org/I154570441"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5064892269","display_name":"Ling Liang","orcid":"https://orcid.org/0000-0002-8534-6494"},"institutions":[{"id":"https://openalex.org/I154570441","display_name":"University of California, Santa Barbara","ror":"https://ror.org/02t274463","country_code":"US","type":"education","lineage":["https://openalex.org/I154570441"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ling Liang","raw_affiliation_strings":["University of California at Santa Barbara, Santa Barbara, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California at Santa Barbara, Santa Barbara, CA, USA","institution_ids":["https://openalex.org/I154570441"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034442315","display_name":"Pengfei Zuo","orcid":"https://orcid.org/0000-0001-9982-5130"},"institutions":[{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Pengfei Zuo","raw_affiliation_strings":["Huazhong University of Science and Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"Huazhong University of Science and Technology, Wuhan, China","institution_ids":["https://openalex.org/I47720641"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100394414","display_name":"Jing Ye","orcid":"https://orcid.org/0000-0002-8023-5090"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210090176","display_name":"Institute of Computing Technology","ror":"https://ror.org/0090r4d87","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210090176"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jing Ye","raw_affiliation_strings":["State Key Laboratory of Computer Architecture, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"State Key Laboratory of Computer Architecture, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210090176","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5019582323","display_name":"Yingyan Lin","orcid":"https://orcid.org/0000-0001-5946-203X"},"institutions":[{"id":"https://openalex.org/I74775410","display_name":"Rice University","ror":"https://ror.org/008zs3103","country_code":"US","type":"education","lineage":["https://openalex.org/I74775410"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yingyan Lin","raw_affiliation_strings":["Rice University, Houston, TX, USA"],"affiliations":[{"raw_affiliation_string":"Rice University, Houston, TX, USA","institution_ids":["https://openalex.org/I74775410"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100385336","display_name":"Yuan Xie","orcid":"https://orcid.org/0000-0003-2093-1788"},"institutions":[{"id":"https://openalex.org/I154570441","display_name":"University of California, Santa Barbara","ror":"https://ror.org/02t274463","country_code":"US","type":"education","lineage":["https://openalex.org/I154570441"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yuan Xie","raw_affiliation_strings":["University of California at Santa Barbara, Santa Barbara, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California at Santa Barbara, Santa Barbara, CA, USA","institution_ids":["https://openalex.org/I154570441"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5101964036"],"corresponding_institution_ids":["https://openalex.org/I19820366","https://openalex.org/I4210090176"],"apc_list":null,"apc_paid":null,"fwci":2.9904,"has_fulltext":false,"cited_by_count":32,"citation_normalized_percentile":{"value":0.92821587,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":99},"biblio":{"volume":"40","issue":"6","first_page":"1230","last_page":"1243"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10502","display_name":"Advanced Memory and Neural Computing","score":0.9980999827384949,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/toolchain","display_name":"Toolchain","score":0.871483564376831},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7712175846099854},{"id":"https://openalex.org/keywords/trojan","display_name":"Trojan","score":0.626251220703125},{"id":"https://openalex.org/keywords/hardware-trojan","display_name":"Hardware Trojan","score":0.5911164879798889},{"id":"https://openalex.org/keywords/payload","display_name":"Payload (computing)","score":0.5650053024291992},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.4577128291130066},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.45104551315307617},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.37502312660217285},{"id":"https://openalex.org/keywords/computer-hardware","display_name":"Computer hardware","score":0.33308449387550354},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.2826293110847473},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.2787935733795166},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.16820907592773438}],"concepts":[{"id":"https://openalex.org/C2777062904","wikidata":"https://www.wikidata.org/wiki/Q545406","display_name":"Toolchain","level":3,"score":0.871483564376831},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7712175846099854},{"id":"https://openalex.org/C174333608","wikidata":"https://www.wikidata.org/wiki/Q19635","display_name":"Trojan","level":2,"score":0.626251220703125},{"id":"https://openalex.org/C2780873074","wikidata":"https://www.wikidata.org/wiki/Q5656397","display_name":"Hardware Trojan","level":3,"score":0.5911164879798889},{"id":"https://openalex.org/C134066672","wikidata":"https://www.wikidata.org/wiki/Q1424639","display_name":"Payload (computing)","level":3,"score":0.5650053024291992},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.4577128291130066},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.45104551315307617},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.37502312660217285},{"id":"https://openalex.org/C9390403","wikidata":"https://www.wikidata.org/wiki/Q3966","display_name":"Computer hardware","level":1,"score":0.33308449387550354},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.2826293110847473},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.2787935733795166},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.16820907592773438},{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tcad.2020.2995347","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tcad.2020.2995347","pdf_url":null,"source":{"id":"https://openalex.org/S100835903","display_name":"IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems","issn_l":"0278-0070","issn":["0278-0070","1937-4151"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems","raw_type":"journal-article"},{"id":"pmh:oai:repository.hkust.edu.hk:1783.1-133035","is_oa":false,"landing_page_url":"http://lbdiscover.ust.hk/uresolver?url_ver=Z39.88-2004&rft_val_fmt=info:ofi/fmt:kev:mtx:journal&rfr_id=info:sid/HKUST:SPI&rft.genre=article&rft.issn=0278-0070&rft.volume=40&rft.issue=6&rft.date=2021&rft.spage=1230&rft.aulast=Hu&rft.aufirst=Xing&rft.atitle=Practical+Attacks+on+Deep+Neural+Networks+by+Memory+Trojaning&rft.title=IEEE+Transactions+on+Computer-Aided+Design+of+Integrated+Circuits+and+Systems","pdf_url":null,"source":{"id":"https://openalex.org/S4306401796","display_name":"Rare & Special e-Zone (The Hong Kong University of Science and Technology)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I200769079","host_organization_name":"Hong Kong University of Science and Technology","host_organization_lineage":["https://openalex.org/I200769079"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.75,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G1003572525","display_name":null,"funder_award_id":"1730309","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G7396753823","display_name":null,"funder_award_id":"1725447","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":94,"referenced_works":["https://openalex.org/W9657784","https://openalex.org/W639708223","https://openalex.org/W1473189865","https://openalex.org/W1541663547","https://openalex.org/W1673923490","https://openalex.org/W1686810756","https://openalex.org/W1928419358","https://openalex.org/W1945616565","https://openalex.org/W1976955200","https://openalex.org/W2032121576","https://openalex.org/W2038296020","https://openalex.org/W2040509711","https://openalex.org/W2048266589","https://openalex.org/W2117539524","https://openalex.org/W2161998562","https://openalex.org/W2180612164","https://openalex.org/W2183341477","https://openalex.org/W2194775991","https://openalex.org/W2408141691","https://openalex.org/W2432142698","https://openalex.org/W2442974303","https://openalex.org/W2461943168","https://openalex.org/W2462906003","https://openalex.org/W2535690855","https://openalex.org/W2535873859","https://openalex.org/W2557044351","https://openalex.org/W2561498661","https://openalex.org/W2565305208","https://openalex.org/W2603766943","https://openalex.org/W2604319603","https://openalex.org/W2605289356","https://openalex.org/W2606722458","https://openalex.org/W2612445135","https://openalex.org/W2613718673","https://openalex.org/W2618530766","https://openalex.org/W2621405616","https://openalex.org/W2727966874","https://openalex.org/W2738229973","https://openalex.org/W2738841453","https://openalex.org/W2753783305","https://openalex.org/W2757182288","https://openalex.org/W2767260595","https://openalex.org/W2771112233","https://openalex.org/W2774644650","https://openalex.org/W2807765471","https://openalex.org/W2808426733","https://openalex.org/W2809300109","https://openalex.org/W2890054895","https://openalex.org/W2900327659","https://openalex.org/W2902501132","https://openalex.org/W2903582334","https://openalex.org/W2905755717","https://openalex.org/W2906885438","https://openalex.org/W2913144408","https://openalex.org/W2913562707","https://openalex.org/W2962700793","https://openalex.org/W2962748759","https://openalex.org/W2962835266","https://openalex.org/W2962835968","https://openalex.org/W2962939738","https://openalex.org/W2963047332","https://openalex.org/W2963098487","https://openalex.org/W2963207607","https://openalex.org/W2963343288","https://openalex.org/W2963542245","https://openalex.org/W2963844355","https://openalex.org/W2963955657","https://openalex.org/W2964081807","https://openalex.org/W2964153729","https://openalex.org/W2964318098","https://openalex.org/W2964350391","https://openalex.org/W2973295486","https://openalex.org/W3103836116","https://openalex.org/W3103940881","https://openalex.org/W3118608800","https://openalex.org/W4242053016","https://openalex.org/W4249932213","https://openalex.org/W4291984345","https://openalex.org/W4293529028","https://openalex.org/W4297775537","https://openalex.org/W4298140072","https://openalex.org/W4300434632","https://openalex.org/W4300511536","https://openalex.org/W4394644156","https://openalex.org/W6620707391","https://openalex.org/W6628547770","https://openalex.org/W6632480037","https://openalex.org/W6640425456","https://openalex.org/W6660036703","https://openalex.org/W6694260854","https://openalex.org/W6730054736","https://openalex.org/W6738964779","https://openalex.org/W6750462152","https://openalex.org/W6787972765"],"related_works":["https://openalex.org/W4385434494","https://openalex.org/W3159333627","https://openalex.org/W3004467197","https://openalex.org/W1500594134","https://openalex.org/W2091750459","https://openalex.org/W2999465529","https://openalex.org/W3084939900","https://openalex.org/W2382172865","https://openalex.org/W1526642037","https://openalex.org/W4321062229"],"abstract_inverted_index":{"Deep":[0],"neural":[1],"network":[2],"(DNN)":[3],"accelerators":[4],"are":[5,41],"widely":[6],"deployed":[7],"in":[8,17,49,112,201,215],"computer":[9],"vision,":[10],"speech":[11],"recognition,":[12],"and":[13,110,163,189,221,227,231,243],"machine":[14],"translation":[15],"applications,":[16],"which":[18],"attacks":[19,37,70,245],"on":[20,30,38,185,196,246],"DNNs":[21,93],"have":[22,99],"become":[23],"a":[24,120,134,191],"growing":[25],"concern.":[26],"This":[27],"article":[28],"focuses":[29],"exploring":[31],"the":[32,44,58,95,105,115,140,145,152,160,173,178,198,208,216,229,234],"implications":[33],"of":[34,43,104,148,154,181,218],"hardware":[35,50,89,116],"Trojan":[36,136,192,236],"DNNs.":[39,247],"Trojans":[40,90],"one":[42],"most":[45],"challenging":[46],"threat":[47,121],"models":[48],"security":[51],"where":[52],"adversaries":[53,75,98],"insert":[54],"malicious":[55,141],"modifications":[56],"to":[57,64,91,114,159],"original":[59],"integrated":[60],"circuits":[61],"(ICs),":[62],"leading":[63],"malfunction":[65],"once":[66],"being":[67],"triggered.":[68],"Such":[69],"can":[71,238],"be":[72],"conducted":[73],"by":[74],"because":[76],"modern":[77],"ICs":[78],"commonly":[79],"include":[80],"third-party":[81],"intellectual":[82],"property":[83],"(IP)":[84],"blocks.":[85],"Previous":[86],"studies":[87],"design":[88,226],"attack":[92],"with":[94],"assumption":[96],"that":[97,138,207,233],"full":[100],"knowledge":[101],"or":[102,157],"manipulation":[103,156],"DNN":[106,149],"systems'":[107],"victim":[108,161],"model":[109,122,162],"toolchain":[111,155],"addition":[113],"platforms,":[117],"yet":[118],"such":[119],"is":[123,165,212],"strict,":[124],"limiting":[125],"their":[126],"practical":[127,168],"adoption.":[128],"In":[129],"this":[130],"article,":[131],"we":[132,171,225],"propose":[133,190],"memory":[135,146,182,186],"methodology":[137],"implants":[139],"logics":[142],"merely":[143],"into":[144],"controllers":[147],"systems":[150],"without":[151],"necessity":[153],"accessing":[158],"thus":[164],"feasible":[166],"for":[167],"uses.":[169],"Specifically,":[170],"locate":[172],"input":[174,202],"image":[175],"data":[176],"among":[177],"massive":[179],"volume":[180],"traffics":[183],"based":[184,195],"access":[187],"patterns":[188],"trigger":[193,210],"mechanism":[194,211],"detecting":[197],"geometric":[199],"feature":[200],"images.":[203],"Extensive":[204],"experiments":[205],"show":[206],"proposed":[209,235],"effective":[213],"even":[214],"presence":[217],"environmental":[219],"noises":[220],"preprocessing":[222],"operations.":[223],"Furthermore,":[224],"implement":[228],"payload":[230],"verify":[232],"technique":[237],"effectively":[239],"conduct":[240],"both":[241],"untargeted":[242],"targeted":[244]},"counts_by_year":[{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":8},{"year":2023,"cited_by_count":8},{"year":2022,"cited_by_count":7},{"year":2021,"cited_by_count":5},{"year":2020,"cited_by_count":2}],"updated_date":"2026-04-06T07:47:59.780226","created_date":"2025-10-10T00:00:00"}
