{"id":"https://openalex.org/W3033311948","doi":"https://doi.org/10.1109/vts48691.2020.9107564","title":"SafeTPU: A Verifiably Secure Hardware Accelerator for Deep Neural Networks","display_name":"SafeTPU: A Verifiably Secure Hardware Accelerator for Deep Neural Networks","publication_year":2020,"publication_date":"2020-04-01","ids":{"openalex":"https://openalex.org/W3033311948","doi":"https://doi.org/10.1109/vts48691.2020.9107564","mag":"3033311948"},"language":"en","primary_location":{"id":"doi:10.1109/vts48691.2020.9107564","is_oa":false,"landing_page_url":"https://doi.org/10.1109/vts48691.2020.9107564","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 IEEE 38th VLSI Test Symposium (VTS)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5072185968","display_name":"Maria I. Mera Collantes","orcid":"https://orcid.org/0000-0001-7067-8667"},"institutions":[{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Maria I. Mera Collantes","raw_affiliation_strings":["Department of Electrical and Computer Engineering, New York University"],"affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, New York University","institution_ids":["https://openalex.org/I57206974"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034694460","display_name":"Zahra Ghodsi","orcid":"https://orcid.org/0000-0002-4175-8542"},"institutions":[{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Zahra Ghodsi","raw_affiliation_strings":["Department of Electrical and Computer Engineering, New York University"],"affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, New York University","institution_ids":["https://openalex.org/I57206974"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5010950688","display_name":"Siddharth Garg","orcid":"https://orcid.org/0000-0002-6158-9512"},"institutions":[{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Siddharth Garg","raw_affiliation_strings":["Department of Electrical and Computer Engineering, New York University"],"affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, New York University","institution_ids":["https://openalex.org/I57206974"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5072185968"],"corresponding_institution_ids":["https://openalex.org/I57206974"],"apc_list":null,"apc_paid":null,"fwci":0.9279,"has_fulltext":false,"cited_by_count":10,"citation_normalized_percentile":{"value":0.80116875,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10502","display_name":"Advanced Memory and Neural Computing","score":0.9976000189781189,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7763538360595703},{"id":"https://openalex.org/keywords/correctness","display_name":"Correctness","score":0.7033903002738953},{"id":"https://openalex.org/keywords/overhead","display_name":"Overhead (engineering)","score":0.5434293150901794},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.5340612530708313},{"id":"https://openalex.org/keywords/mathematical-proof","display_name":"Mathematical proof","score":0.5284680724143982},{"id":"https://openalex.org/keywords/fault-injection","display_name":"Fault injection","score":0.5080821514129639},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.49586257338523865},{"id":"https://openalex.org/keywords/field-programmable-gate-array","display_name":"Field-programmable gate array","score":0.4759402275085449},{"id":"https://openalex.org/keywords/computation","display_name":"Computation","score":0.4759373664855957},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.4752090871334076},{"id":"https://openalex.org/keywords/reuse","display_name":"Reuse","score":0.4603448212146759},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.2730703353881836},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.19008010625839233},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.15623077750205994},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.1224290132522583}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7763538360595703},{"id":"https://openalex.org/C55439883","wikidata":"https://www.wikidata.org/wiki/Q360812","display_name":"Correctness","level":2,"score":0.7033903002738953},{"id":"https://openalex.org/C2779960059","wikidata":"https://www.wikidata.org/wiki/Q7113681","display_name":"Overhead (engineering)","level":2,"score":0.5434293150901794},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.5340612530708313},{"id":"https://openalex.org/C108710211","wikidata":"https://www.wikidata.org/wiki/Q11538","display_name":"Mathematical proof","level":2,"score":0.5284680724143982},{"id":"https://openalex.org/C2775928411","wikidata":"https://www.wikidata.org/wiki/Q2041312","display_name":"Fault injection","level":3,"score":0.5080821514129639},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.49586257338523865},{"id":"https://openalex.org/C42935608","wikidata":"https://www.wikidata.org/wiki/Q190411","display_name":"Field-programmable gate array","level":2,"score":0.4759402275085449},{"id":"https://openalex.org/C45374587","wikidata":"https://www.wikidata.org/wiki/Q12525525","display_name":"Computation","level":2,"score":0.4759373664855957},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.4752090871334076},{"id":"https://openalex.org/C206588197","wikidata":"https://www.wikidata.org/wiki/Q846574","display_name":"Reuse","level":2,"score":0.4603448212146759},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.2730703353881836},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.19008010625839233},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.15623077750205994},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.1224290132522583},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0},{"id":"https://openalex.org/C18903297","wikidata":"https://www.wikidata.org/wiki/Q7150","display_name":"Ecology","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/vts48691.2020.9107564","is_oa":false,"landing_page_url":"https://doi.org/10.1109/vts48691.2020.9107564","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 IEEE 38th VLSI Test Symposium (VTS)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Industry, innovation and infrastructure","score":0.44999998807907104,"id":"https://metadata.un.org/sdg/9"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":33,"referenced_works":["https://openalex.org/W76123274","https://openalex.org/W1527197079","https://openalex.org/W1598866093","https://openalex.org/W1965115062","https://openalex.org/W2021949528","https://openalex.org/W2050351395","https://openalex.org/W2071520502","https://openalex.org/W2080132708","https://openalex.org/W2108185518","https://openalex.org/W2113244484","https://openalex.org/W2146099890","https://openalex.org/W2207233201","https://openalex.org/W2330979548","https://openalex.org/W2480957914","https://openalex.org/W2511192821","https://openalex.org/W2515122689","https://openalex.org/W2576845151","https://openalex.org/W2726092462","https://openalex.org/W2771112233","https://openalex.org/W2807835252","https://openalex.org/W2903582334","https://openalex.org/W2943220429","https://openalex.org/W2964279767","https://openalex.org/W2964345203","https://openalex.org/W2973780393","https://openalex.org/W3102908045","https://openalex.org/W4242053016","https://openalex.org/W4288337628","https://openalex.org/W4298227433","https://openalex.org/W6603123321","https://openalex.org/W6635810480","https://openalex.org/W6721462961","https://openalex.org/W6740443968"],"related_works":["https://openalex.org/W1667647204","https://openalex.org/W2404647514","https://openalex.org/W4247536566","https://openalex.org/W2018477250","https://openalex.org/W3119814709","https://openalex.org/W4241418540","https://openalex.org/W1508895727","https://openalex.org/W2725786787","https://openalex.org/W4283160672","https://openalex.org/W55831818"],"abstract_inverted_index":{"We":[0,50,63,102],"present":[1,51],"Safe-TPU,":[2],"a":[3,40,52],"framework":[4],"for":[5,33],"secure":[6],"computations":[7],"of":[8,39,85,92],"Deep":[9],"Neural":[10],"Networks":[11],"(DNNs)":[12],"in":[13,97],"untrusted":[14],"hardware":[15,56],"corrupted":[16],"by":[17],"Trojans":[18],"or":[19],"fault":[20],"injection":[21],"attacks.":[22],"This":[23],"work":[24],"leverages":[25],"previous":[26],"advances":[27],"on":[28,59,105],"interactive":[29,60],"proof":[30],"(IP)":[31],"systems":[32],"verifying,":[34],"at":[35,135],"run-time,":[36],"the":[37,71,98,124,136],"correctness":[38],"neural":[41],"network\u2019s":[42],"computations,":[43],"and":[44,73,79,90,108,128],"makes":[45],"three":[46],"new":[47,65],"contributions:":[48],"(1)":[49],"Trojan":[53],"resilient":[54],"DNN":[55,100,126],"accelerator":[57,127],"based":[58],"proofs;":[61,78],"(2)":[62],"introduce":[64],"protocol":[66],"enhancements":[67],"that":[68,116],"significantly":[69],"reduce":[70],"space":[72],"time":[74],"required":[75],"to":[76,141],"generate":[77],"(3)":[80],"we":[81,114],"propose":[82],"an":[83,106],"implementation":[84],"Safe-TPU":[86,104,139],"with":[87,143],"high":[88,144],"parallelism":[89],"reuse":[91],"existing":[93],"resources":[94],"already":[95],"deployed":[96],"baseline":[99,125],"accelerator.":[101],"prototype":[103],"FPGA":[107],"analyze":[109],"its":[110],"security":[111],"guarantees.":[112],"Experimentally,":[113],"show":[115],"Safe-TPU\u2019s":[117],"area":[118],"overhead":[119],"is":[120,129],"small":[121],"(28%)":[122],"over":[123],"3.15\u00d7":[130],"faster":[131],"than":[132],"state-of-the-art,":[133],"while":[134],"same":[137],"time,":[138],"guarantees":[140],"catch,":[142],"probability,":[145],"any":[146],"incorrect":[147],"computations.":[148]},"counts_by_year":[{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":2}],"updated_date":"2026-02-07T06:11:34.122080","created_date":"2025-10-10T00:00:00"}
