{"id":"https://openalex.org/W7123350402","doi":"https://doi.org/10.1109/tvlsi.2025.3650411","title":"Securing DNN Acceleration From Off-Chip Memory Vulnerabilities With Low-Overhead Authenticated Encryption","display_name":"Securing DNN Acceleration From Off-Chip Memory Vulnerabilities With Low-Overhead Authenticated Encryption","publication_year":2026,"publication_date":"2026-01-12","ids":{"openalex":"https://openalex.org/W7123350402","doi":"https://doi.org/10.1109/tvlsi.2025.3650411"},"language":null,"primary_location":{"id":"doi:10.1109/tvlsi.2025.3650411","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tvlsi.2025.3650411","pdf_url":null,"source":{"id":"https://openalex.org/S37538908","display_name":"IEEE Transactions on Very Large Scale Integration (VLSI) Systems","issn_l":"1063-8210","issn":["1063-8210","1557-9999"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Very Large Scale Integration (VLSI) Systems","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5062648698","display_name":"Kyungmi Lee","orcid":"https://orcid.org/0000-0001-6406-9515"},"institutions":[{"id":"https://openalex.org/I63966007","display_name":"Massachusetts Institute of Technology","ror":"https://ror.org/042nb2s44","country_code":"US","type":"education","lineage":["https://openalex.org/I63966007"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Kyungmi Lee","raw_affiliation_strings":["Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, MA, USA"],"raw_orcid":"https://orcid.org/0000-0001-6406-9515","affiliations":[{"raw_affiliation_string":"Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, MA, USA","institution_ids":["https://openalex.org/I63966007"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5122886364","display_name":"Gaurab Das","orcid":null},"institutions":[{"id":"https://openalex.org/I63966007","display_name":"Massachusetts Institute of Technology","ror":"https://ror.org/042nb2s44","country_code":"US","type":"education","lineage":["https://openalex.org/I63966007"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Gaurab Das","raw_affiliation_strings":["Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, MA, USA"],"raw_orcid":"https://orcid.org/0009-0000-8777-2748","affiliations":[{"raw_affiliation_string":"Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, MA, USA","institution_ids":["https://openalex.org/I63966007"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5039062148","display_name":"Donghyeon Han","orcid":"https://orcid.org/0000-0002-5212-2072"},"institutions":[{"id":"https://openalex.org/I63966007","display_name":"Massachusetts Institute of Technology","ror":"https://ror.org/042nb2s44","country_code":"US","type":"education","lineage":["https://openalex.org/I63966007"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Donghyeon Han","raw_affiliation_strings":["Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, MA, USA"],"raw_orcid":"https://orcid.org/0000-0002-5212-2072","affiliations":[{"raw_affiliation_string":"Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, MA, USA","institution_ids":["https://openalex.org/I63966007"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5084128470","display_name":"Anantha P. Chandrakasan","orcid":"https://orcid.org/0000-0002-5977-2748"},"institutions":[{"id":"https://openalex.org/I63966007","display_name":"Massachusetts Institute of Technology","ror":"https://ror.org/042nb2s44","country_code":"US","type":"education","lineage":["https://openalex.org/I63966007"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Anantha P. Chandrakasan","raw_affiliation_strings":["Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, MA, USA"],"raw_orcid":"https://orcid.org/0000-0002-5977-2748","affiliations":[{"raw_affiliation_string":"Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, MA, USA","institution_ids":["https://openalex.org/I63966007"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.05590966,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"34","issue":"3","first_page":"953","last_page":"966"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.8292999863624573,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.8292999863624573,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.10670000314712524,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10951","display_name":"Cryptographic Implementations and Security","score":0.021199999377131462,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.6026999950408936},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.5180000066757202},{"id":"https://openalex.org/keywords/cryptographic-primitive","display_name":"Cryptographic primitive","score":0.4934000074863434},{"id":"https://openalex.org/keywords/authenticated-encryption","display_name":"Authenticated encryption","score":0.47099998593330383},{"id":"https://openalex.org/keywords/authentication","display_name":"Authentication (law)","score":0.4239000082015991},{"id":"https://openalex.org/keywords/overhead","display_name":"Overhead (engineering)","score":0.4185999929904938},{"id":"https://openalex.org/keywords/data-integrity","display_name":"Data integrity","score":0.3889000117778778},{"id":"https://openalex.org/keywords/message-authentication-code","display_name":"Message authentication code","score":0.3296000063419342}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8285999894142151},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.6026999950408936},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.5180000066757202},{"id":"https://openalex.org/C15927051","wikidata":"https://www.wikidata.org/wiki/Q246593","display_name":"Cryptographic primitive","level":4,"score":0.4934000074863434},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.4837999939918518},{"id":"https://openalex.org/C128619300","wikidata":"https://www.wikidata.org/wiki/Q15263584","display_name":"Authenticated encryption","level":3,"score":0.47099998593330383},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.46059998869895935},{"id":"https://openalex.org/C148417208","wikidata":"https://www.wikidata.org/wiki/Q4825882","display_name":"Authentication (law)","level":2,"score":0.4239000082015991},{"id":"https://openalex.org/C2779960059","wikidata":"https://www.wikidata.org/wiki/Q7113681","display_name":"Overhead (engineering)","level":2,"score":0.4185999929904938},{"id":"https://openalex.org/C33762810","wikidata":"https://www.wikidata.org/wiki/Q461671","display_name":"Data integrity","level":2,"score":0.3889000117778778},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3596000075340271},{"id":"https://openalex.org/C141492731","wikidata":"https://www.wikidata.org/wiki/Q1052621","display_name":"Message authentication code","level":3,"score":0.3296000063419342},{"id":"https://openalex.org/C41036726","wikidata":"https://www.wikidata.org/wiki/Q844824","display_name":"Physical address","level":3,"score":0.3264999985694885},{"id":"https://openalex.org/C9368797","wikidata":"https://www.wikidata.org/wiki/Q117010","display_name":"Disk encryption","level":4,"score":0.32429999113082886},{"id":"https://openalex.org/C71745522","wikidata":"https://www.wikidata.org/wiki/Q2476929","display_name":"Confidentiality","level":2,"score":0.31679999828338623},{"id":"https://openalex.org/C33884865","wikidata":"https://www.wikidata.org/wiki/Q1254335","display_name":"Cryptographic protocol","level":3,"score":0.30649998784065247},{"id":"https://openalex.org/C18131444","wikidata":"https://www.wikidata.org/wiki/Q163585","display_name":"Memory protection","level":5,"score":0.28600001335144043},{"id":"https://openalex.org/C93974786","wikidata":"https://www.wikidata.org/wiki/Q1589480","display_name":"Ciphertext","level":3,"score":0.28200000524520874},{"id":"https://openalex.org/C10511746","wikidata":"https://www.wikidata.org/wiki/Q899388","display_name":"Data security","level":3,"score":0.2750999927520752},{"id":"https://openalex.org/C106544461","wikidata":"https://www.wikidata.org/wiki/Q543151","display_name":"Block cipher","level":3,"score":0.2743000090122223},{"id":"https://openalex.org/C2780221543","wikidata":"https://www.wikidata.org/wiki/Q4681865","display_name":"Cipher","level":3,"score":0.2718000113964081},{"id":"https://openalex.org/C6295992","wikidata":"https://www.wikidata.org/wiki/Q976521","display_name":"Cryptosystem","level":3,"score":0.26980000734329224},{"id":"https://openalex.org/C9390403","wikidata":"https://www.wikidata.org/wiki/Q3966","display_name":"Computer hardware","level":1,"score":0.25850000977516174}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tvlsi.2025.3650411","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tvlsi.2025.3650411","pdf_url":null,"source":{"id":"https://openalex.org/S37538908","display_name":"IEEE Transactions on Very Large Scale Integration (VLSI) Systems","issn_l":"1063-8210","issn":["1063-8210","1557-9999"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Very Large Scale Integration (VLSI) Systems","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.7771205306053162,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Security":[0],"vulnerabilities":[1],"in":[2,81],"deep":[3],"neural":[4],"network":[5],"(DNN)":[6],"accelerators":[7,40],"pose":[8],"risks":[9],"for":[10,35,97,126],"high-stakes":[11],"applications,":[12],"with":[13,60,92,107,134,190,209,214],"off-chip":[14,72,99,216],"memory":[15,36,78,100,110,136,217],"attacks":[16,70],"representing":[17],"a":[18,56,108,157],"critical":[19],"threat":[20],"to":[21,63,122],"both":[22,66],"data":[23,125,133],"confidentiality":[24,67],"and":[25,68,129,149,166,181,195,202],"integrity.":[26],"While":[27],"general-purpose":[28],"processors":[29],"employ":[30],"comprehensive":[31],"cryptographic":[32,127,153],"authenticated":[33,61],"encryption":[34,62],"security,":[37],"domain-specific":[38],"DNN":[39,57,82,211],"lack":[41],"adequate":[42],"protection,":[43],"particularly":[44],"against":[45,65,164],"integrity":[46,69],"violations.":[47],"To":[48],"address":[49],"this":[50,105],"research":[51],"gap,":[52],"we":[53],"present":[54],"Sorbet,":[55],"accelerator":[58,212],"equipped":[59],"defend":[64],"on":[71],"memory.":[73],"Integrity":[74],"verification":[75],"introduces":[76],"complex":[77],"access":[79],"patterns":[80],"accelerators,":[83],"as":[84],"the":[85,93,118,123,135,139,147],"granularity":[86],"of":[87,138,152],"authentication":[88,128],"operations":[89,154],"often":[90],"clashes":[91],"tiling":[94],"strategies":[95],"used":[96],"efficient":[98],"access.":[101],"Our":[102,169],"approach":[103],"tackles":[104],"challenge":[106],"secure":[109],"interface":[111],"(SMI)":[112],"module":[113],"that":[114],"efficiently:":[115],"1)":[116],"translates":[117],"accelerator\u2019s":[119,140],"tile":[120],"request":[121],"required":[124],"2)":[130],"aligns":[131],"fetched":[132],"map":[137],"on-chip":[141,192],"buffers.":[142],"Moreover,":[143],"our":[144],"design":[145],"mitigates":[146],"area":[148,201],"performance":[150],"overhead":[151,175],"by":[155],"adopting":[156],"lightweight":[158],"cipher":[159],"while":[160],"maintaining":[161],"security":[162],"requirements":[163],"splicing":[165],"replay":[167],"attacks.":[168],"fabricated":[170],"chip":[171],"achieves":[172],"22%":[173],"latency":[174],"across":[176],"diverse":[177],"workloads,":[178],"including":[179],"convolutions":[180],"multihead":[182],"attentions":[183],"(MHAs),":[184],"which":[185,206],"can":[186],"be":[187],"further":[188],"reduced":[189],"larger":[191],"buffer":[193],"size":[194],"double-buffering.":[196],"It":[197],"incurs":[198],"only":[199],"7.9%":[200],"18.3%":[203],"energy":[204],"overhead,":[205],"is":[207],"competitive":[208],"recent":[210],"defenses":[213],"weaker":[215],"protection.":[218]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-01-14T00:00:00"}
