{"id":"https://openalex.org/W3113404214","doi":"https://doi.org/10.1109/tifs.2020.3046858","title":"Stealthy and Robust Glitch Injection Attack on Deep Learning Accelerator for Target With Variational Viewpoint","display_name":"Stealthy and Robust Glitch Injection Attack on Deep Learning Accelerator for Target With Variational Viewpoint","publication_year":2020,"publication_date":"2020-12-23","ids":{"openalex":"https://openalex.org/W3113404214","doi":"https://doi.org/10.1109/tifs.2020.3046858","mag":"3113404214"},"language":"en","primary_location":{"id":"doi:10.1109/tifs.2020.3046858","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2020.3046858","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://dr.ntu.edu.sg/bitstream/10356/146196/2/TIFS-LWY-2020.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5000387478","display_name":"Wenye Liu","orcid":"https://orcid.org/0000-0003-4590-5367"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Wenye Liu","raw_affiliation_strings":["School of Electrical and Electronic Engineering, Nanyang Technological University, Singapore"],"raw_orcid":"https://orcid.org/0000-0003-4590-5367","affiliations":[{"raw_affiliation_string":"School of Electrical and Electronic Engineering, Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5029335324","display_name":"Chip-Hong Chang","orcid":"https://orcid.org/0000-0002-8897-6176"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Chip-Hong Chang","raw_affiliation_strings":["School of Electrical and Electronic Engineering, Nanyang Technological University, Singapore"],"raw_orcid":"https://orcid.org/0000-0002-8897-6176","affiliations":[{"raw_affiliation_string":"School of Electrical and Electronic Engineering, Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100403380","display_name":"Fan Zhang","orcid":"https://orcid.org/0000-0001-6087-8243"},"institutions":[{"id":"https://openalex.org/I168879160","display_name":"Zhejiang University of Science and Technology","ror":"https://ror.org/05mx0wr29","country_code":"CN","type":"education","lineage":["https://openalex.org/I168879160"]},{"id":"https://openalex.org/I45928872","display_name":"Alibaba Group (China)","ror":"https://ror.org/00k642b80","country_code":"CN","type":"company","lineage":["https://openalex.org/I45928872"]},{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Fan Zhang","raw_affiliation_strings":["Alibaba-Zhejiang University Joint Research Institution of Frontier Technologies, Hangzhou, China","College of Computer Science and Technology, Zhejiang University, Hangzhou, China"],"raw_orcid":"https://orcid.org/0000-0001-6087-8243","affiliations":[{"raw_affiliation_string":"Alibaba-Zhejiang University Joint Research Institution of Frontier Technologies, Hangzhou, China","institution_ids":["https://openalex.org/I45928872","https://openalex.org/I76130692"]},{"raw_affiliation_string":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China","institution_ids":["https://openalex.org/I168879160"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.9479,"has_fulltext":true,"cited_by_count":8,"citation_normalized_percentile":{"value":0.81736438,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":98},"biblio":{"volume":"16","issue":null,"first_page":"1928","last_page":"1942"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9933000206947327,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T14117","display_name":"Integrated Circuits and Semiconductor Failure Analysis","score":0.9883000254631042,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8252478241920471},{"id":"https://openalex.org/keywords/toolchain","display_name":"Toolchain","score":0.6147023439407349},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.5611779093742371},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5445908904075623},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5351610779762268},{"id":"https://openalex.org/keywords/glitch","display_name":"Glitch","score":0.4904892146587372},{"id":"https://openalex.org/keywords/edge-device","display_name":"Edge device","score":0.4835953116416931},{"id":"https://openalex.org/keywords/field-programmable-gate-array","display_name":"Field-programmable gate array","score":0.4800916016101837},{"id":"https://openalex.org/keywords/enhanced-data-rates-for-gsm-evolution","display_name":"Enhanced Data Rates for GSM Evolution","score":0.4733288884162903},{"id":"https://openalex.org/keywords/computation","display_name":"Computation","score":0.4235427975654602},{"id":"https://openalex.org/keywords/computer-engineering","display_name":"Computer engineering","score":0.3855506479740143},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.33776986598968506},{"id":"https://openalex.org/keywords/computer-vision","display_name":"Computer vision","score":0.32191574573516846},{"id":"https://openalex.org/keywords/computer-hardware","display_name":"Computer hardware","score":0.25525373220443726},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.11532273888587952}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8252478241920471},{"id":"https://openalex.org/C2777062904","wikidata":"https://www.wikidata.org/wiki/Q545406","display_name":"Toolchain","level":3,"score":0.6147023439407349},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.5611779093742371},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5445908904075623},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5351610779762268},{"id":"https://openalex.org/C191287063","wikidata":"https://www.wikidata.org/wiki/Q543281","display_name":"Glitch","level":3,"score":0.4904892146587372},{"id":"https://openalex.org/C138236772","wikidata":"https://www.wikidata.org/wiki/Q25098575","display_name":"Edge device","level":3,"score":0.4835953116416931},{"id":"https://openalex.org/C42935608","wikidata":"https://www.wikidata.org/wiki/Q190411","display_name":"Field-programmable gate array","level":2,"score":0.4800916016101837},{"id":"https://openalex.org/C162307627","wikidata":"https://www.wikidata.org/wiki/Q204833","display_name":"Enhanced Data Rates for GSM Evolution","level":2,"score":0.4733288884162903},{"id":"https://openalex.org/C45374587","wikidata":"https://www.wikidata.org/wiki/Q12525525","display_name":"Computation","level":2,"score":0.4235427975654602},{"id":"https://openalex.org/C113775141","wikidata":"https://www.wikidata.org/wiki/Q428691","display_name":"Computer engineering","level":1,"score":0.3855506479740143},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.33776986598968506},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.32191574573516846},{"id":"https://openalex.org/C9390403","wikidata":"https://www.wikidata.org/wiki/Q3966","display_name":"Computer hardware","level":1,"score":0.25525373220443726},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.11532273888587952},{"id":"https://openalex.org/C94915269","wikidata":"https://www.wikidata.org/wiki/Q1834857","display_name":"Detector","level":2,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C76155785","wikidata":"https://www.wikidata.org/wiki/Q418","display_name":"Telecommunications","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tifs.2020.3046858","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2020.3046858","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},{"id":"pmh:oai:dr.ntu.edu.sg:10356/146196","is_oa":true,"landing_page_url":"https://hdl.handle.net/10356/146196","pdf_url":"https://dr.ntu.edu.sg/bitstream/10356/146196/2/TIFS-LWY-2020.pdf","source":{"id":"https://openalex.org/S4306402609","display_name":"DR-NTU (Nanyang Technological University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I172675005","host_organization_name":"Nanyang Technological University","host_organization_lineage":["https://openalex.org/I172675005"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Journal Article"}],"best_oa_location":{"id":"pmh:oai:dr.ntu.edu.sg:10356/146196","is_oa":true,"landing_page_url":"https://hdl.handle.net/10356/146196","pdf_url":"https://dr.ntu.edu.sg/bitstream/10356/146196/2/TIFS-LWY-2020.pdf","source":{"id":"https://openalex.org/S4306402609","display_name":"DR-NTU (Nanyang Technological University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I172675005","host_organization_name":"Nanyang Technological University","host_organization_lineage":["https://openalex.org/I172675005"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Journal Article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.75,"display_name":"Peace, Justice and strong institutions"}],"awards":[{"id":"https://openalex.org/G4013555790","display_name":"\u57fa\u4e8e\u6301\u4e45\u6027\u6545\u969c\u7684\u5bc6\u7801\u82af\u7247\u548c\u5b89\u5168\u7cfb\u7edf\u7684\u5206\u6790\u673a\u7406\u548c\u65b9\u6cd5\u7814\u7a76","funder_award_id":"62072398","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G982644696","display_name":null,"funder_award_id":"CHFA-GC1-AW01","funder_id":"https://openalex.org/F4320320709","funder_display_name":"National Research Foundation Singapore"}],"funders":[{"id":"https://openalex.org/F4320320709","display_name":"National Research Foundation Singapore","ror":"https://ror.org/03cpyc314"},{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3113404214.pdf","grobid_xml":"https://content.openalex.org/works/W3113404214.grobid-xml"},"referenced_works_count":79,"referenced_works":["https://openalex.org/W1600075072","https://openalex.org/W1673923490","https://openalex.org/W1686810756","https://openalex.org/W1849277567","https://openalex.org/W1945616565","https://openalex.org/W2062272401","https://openalex.org/W2125640276","https://openalex.org/W2145862222","https://openalex.org/W2194775991","https://openalex.org/W2289252105","https://openalex.org/W2302635400","https://openalex.org/W2535873859","https://openalex.org/W2543927648","https://openalex.org/W2565960208","https://openalex.org/W2604319603","https://openalex.org/W2606722458","https://openalex.org/W2618492571","https://openalex.org/W2734506812","https://openalex.org/W2736899637","https://openalex.org/W2750990141","https://openalex.org/W2771112233","https://openalex.org/W2793950911","https://openalex.org/W2795915628","https://openalex.org/W2798302089","https://openalex.org/W2807835252","https://openalex.org/W2809523935","https://openalex.org/W2887603965","https://openalex.org/W2912806500","https://openalex.org/W2919115771","https://openalex.org/W2931892667","https://openalex.org/W2943220429","https://openalex.org/W2946801000","https://openalex.org/W2948811271","https://openalex.org/W2950865323","https://openalex.org/W2962922359","https://openalex.org/W2963163009","https://openalex.org/W2963207607","https://openalex.org/W2963389226","https://openalex.org/W2963557656","https://openalex.org/W2963612069","https://openalex.org/W2963857521","https://openalex.org/W2964014389","https://openalex.org/W2964097310","https://openalex.org/W2964153729","https://openalex.org/W2964175514","https://openalex.org/W2964350391","https://openalex.org/W2964923388","https://openalex.org/W2973780393","https://openalex.org/W2983058739","https://openalex.org/W2984260944","https://openalex.org/W2985535619","https://openalex.org/W2993396030","https://openalex.org/W2995091922","https://openalex.org/W3008727730","https://openalex.org/W3015806656","https://openalex.org/W3023959029","https://openalex.org/W3092454700","https://openalex.org/W3092516112","https://openalex.org/W3102908045","https://openalex.org/W3105009650","https://openalex.org/W4242053016","https://openalex.org/W4246001895","https://openalex.org/W4288337628","https://openalex.org/W6637162671","https://openalex.org/W6637373629","https://openalex.org/W6640425456","https://openalex.org/W6694260854","https://openalex.org/W6729756640","https://openalex.org/W6740552771","https://openalex.org/W6741036071","https://openalex.org/W6743496458","https://openalex.org/W6744511767","https://openalex.org/W6752265895","https://openalex.org/W6753468839","https://openalex.org/W6758508162","https://openalex.org/W6758593136","https://openalex.org/W6760684019","https://openalex.org/W6763559720","https://openalex.org/W6771898115"],"related_works":["https://openalex.org/W2357202691","https://openalex.org/W2973622361","https://openalex.org/W3176282186","https://openalex.org/W4387489555","https://openalex.org/W3185576471","https://openalex.org/W4288024917","https://openalex.org/W4293053895","https://openalex.org/W2983364019","https://openalex.org/W2998183476","https://openalex.org/W3215372595"],"abstract_inverted_index":{"Deep":[0],"neural":[1],"network":[2],"(DNN)":[3],"accelerators":[4],"overcome":[5],"the":[6,46,54,110,116,154,164,168,194,215,257,260,292,295],"power":[7],"and":[8,98,124,203,223,252,314],"memory":[9],"walls":[10],"for":[11,88,175,287],"executing":[12],"neural-net":[13],"models":[14,212],"locally":[15],"on":[16,79,137,208,214,234,299],"edge-computing":[17],"devices":[18],"to":[19,38,58,66,108,247,283],"support":[20],"sophisticated":[21],"AI":[22,60],"applications.":[23],"The":[24,119,150,172,228],"advocacy":[25],"of":[26,93,103,143,167,178,181,193,198,220,263,312,319],"\u201cmodel":[27],"once,":[28],"run":[29],"optimized":[30],"anywhere\u201d":[31],"paradigm":[32],"introduces":[33],"potential":[34],"new":[35,133],"security":[36],"threat":[37],"edge":[39,222],"intelligence":[40],"that":[41,113,140],"is":[42,141],"methodologically":[43],"different":[44],"from":[45,189],"well-known":[47],"adversarial":[48,51,86,269],"examples.":[49],"Existing":[50],"examples":[52,270],"modify":[53],"input":[55],"samples":[56,105],"presented":[57],"an":[59,308],"application":[61],"either":[62],"digitally":[63],"or":[64,77],"physically":[65],"cause":[67],"a":[68,84,90,100,132,145,284,315],"misclassification.":[69],"Nevertheless,":[70],"these":[71],"input-based":[72],"perturbations":[73,121],"are":[74,106,122,201,206,232,303],"not":[75],"robust":[76,293],"surreptitious":[78],"multi-view":[80],"target.":[81,195],"To":[82],"generate":[83],"good":[85],"example":[87],"misclassifying":[89,144],"real-world":[91],"target":[92,146,177],"variational":[94,148],"viewing":[95,244],"angle,":[96],"lighting":[97],"distance,":[99],"decent":[101],"number":[102],"target\u2019s":[104],"required":[107],"extract":[109],"rare":[111],"anomalies":[112],"can":[114,186],"cross":[115],"decision":[117],"boundary.":[118],"feasible":[120],"substantial":[123],"visually":[125],"perceptible.":[126],"In":[127,256,291],"this":[128],"paper,":[129],"we":[130],"propose":[131],"glitch":[134,310,317],"injection":[135],"attack":[136,173,199,229,265,296],"DNN":[138,225],"accelerator":[139],"capable":[142],"under":[147],"viewpoints.":[149],"glitches":[151,278],"injected":[152,279],"into":[153,280],"computation":[155],"clock":[156],"signal":[157],"induce":[158],"transitory":[159],"but":[160],"disruptive":[161],"errors":[162],"in":[163,237],"intermediate":[165],"results":[166],"multiply-and-accumulate":[169],"(MAC)":[170],"operations.":[171],"pattern":[174],"each":[176],"interest":[179],"consists":[180],"sparse":[182],"instantaneous":[183],"glitches,":[184],"which":[185],"be":[187],"derived":[188],"just":[190],"one":[191,288],"sample":[192],"Two":[196],"modes":[197],"patterns":[200],"derived,":[202],"their":[204],"effectiveness":[205],"demonstrated":[207],"four":[209,301],"representative":[210],"ImageNet":[211],"implemented":[213],"Deep-learning":[216],"Processing":[217],"Unit":[218],"(DPU)":[219],"FPGA":[221],"its":[224],"development":[226],"toolchain.":[227],"success":[230,261,297],"rates":[231,262,298],"evaluated":[233],"118":[235],"objects":[236],"61":[238],"diverse":[239],"sensing":[240],"conditions,":[241],"including":[242],"25":[243],"angles":[245],"(\u221260\u00b0":[246],"60\u00b0),":[248],"24":[249],"illumination":[250],"directions":[251],"12":[253],"color":[254],"temperatures.":[255],"covert":[258],"mode,":[259,294],"our":[264],"exceed":[266],"existing":[267],"stealthy":[268],"by":[271],"more":[272,304],"than":[273,305],"16.3%,":[274],"with":[275,307],"only":[276],"two":[277],"ten":[281],"thousands":[282],"million":[285],"cycles":[286],"complete":[289],"inference.":[290],"all":[300],"DNNs":[302],"96.2%":[306],"average":[309],"intensity":[311,318],"1.4%":[313],"maximum":[316],"10.2%.":[320]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":5}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
