{"id":"https://openalex.org/W3120524050","doi":"https://doi.org/10.1587/transfun.2020cip0024","title":"Model Reverse-Engineering Attack against Systolic-Array-Based DNN Accelerator Using Correlation Power Analysis","display_name":"Model Reverse-Engineering Attack against Systolic-Array-Based DNN Accelerator Using Correlation Power Analysis","publication_year":2020,"publication_date":"2020-12-31","ids":{"openalex":"https://openalex.org/W3120524050","doi":"https://doi.org/10.1587/transfun.2020cip0024","mag":"3120524050"},"language":"en","primary_location":{"id":"doi:10.1587/transfun.2020cip0024","is_oa":true,"landing_page_url":"https://doi.org/10.1587/transfun.2020cip0024","pdf_url":"https://www.jstage.jst.go.jp/article/transfun/E104.A/1/E104.A_2020CIP0024/_pdf","source":{"id":"https://openalex.org/S166990724","display_name":"IEICE Transactions on Fundamentals of Electronics Communications and Computer Sciences","issn_l":"0916-8508","issn":["0916-8508","1745-1337"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4320800604","host_organization_name":"Institute of Electronics, Information and Communication Engineers","host_organization_lineage":["https://openalex.org/P4320800604"],"host_organization_lineage_names":["Institute of Electronics, Information and Communication Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"bronze","oa_url":"https://www.jstage.jst.go.jp/article/transfun/E104.A/1/E104.A_2020CIP0024/_pdf","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5063582139","display_name":"Kota Yoshida","orcid":"https://orcid.org/0000-0003-1293-6415"},"institutions":[{"id":"https://openalex.org/I135768898","display_name":"Ritsumeikan University","ror":"https://ror.org/0197nmd03","country_code":"JP","type":"education","lineage":["https://openalex.org/I135768898","https://openalex.org/I4390039241"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Kota YOSHIDA","raw_affiliation_strings":["Graduate School of Science and Technology, Ritsumeikan University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Graduate School of Science and Technology, Ritsumeikan University","institution_ids":["https://openalex.org/I135768898"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5049245325","display_name":"Mitsuru Shiozaki","orcid":"https://orcid.org/0000-0003-3217-5262"},"institutions":[{"id":"https://openalex.org/I135768898","display_name":"Ritsumeikan University","ror":"https://ror.org/0197nmd03","country_code":"JP","type":"education","lineage":["https://openalex.org/I135768898","https://openalex.org/I4390039241"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Mitsuru SHIOZAKI","raw_affiliation_strings":["Research Organization of Science and Engineering, Ritsumeikan University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Research Organization of Science and Engineering, Ritsumeikan University","institution_ids":["https://openalex.org/I135768898"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5049285154","display_name":"Shunsuke Okura","orcid":"https://orcid.org/0000-0001-6422-3703"},"institutions":[{"id":"https://openalex.org/I135768898","display_name":"Ritsumeikan University","ror":"https://ror.org/0197nmd03","country_code":"JP","type":"education","lineage":["https://openalex.org/I135768898","https://openalex.org/I4390039241"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Shunsuke OKURA","raw_affiliation_strings":["Department of Science and Engineering, Ritsumeikan University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Science and Engineering, Ritsumeikan University","institution_ids":["https://openalex.org/I135768898"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102331170","display_name":"Takaya Kubota","orcid":null},"institutions":[{"id":"https://openalex.org/I135768898","display_name":"Ritsumeikan University","ror":"https://ror.org/0197nmd03","country_code":"JP","type":"education","lineage":["https://openalex.org/I135768898","https://openalex.org/I4390039241"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Takaya KUBOTA","raw_affiliation_strings":["Research Organization of Science and Engineering, Ritsumeikan University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Research Organization of Science and Engineering, Ritsumeikan University","institution_ids":["https://openalex.org/I135768898"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5007179822","display_name":"Takeshi Fujino","orcid":"https://orcid.org/0000-0001-9441-3137"},"institutions":[{"id":"https://openalex.org/I135768898","display_name":"Ritsumeikan University","ror":"https://ror.org/0197nmd03","country_code":"JP","type":"education","lineage":["https://openalex.org/I135768898","https://openalex.org/I4390039241"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Takeshi FUJINO","raw_affiliation_strings":["Department of Science and Engineering, Ritsumeikan University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Science and Engineering, Ritsumeikan University","institution_ids":["https://openalex.org/I135768898"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.0833,"has_fulltext":true,"cited_by_count":16,"citation_normalized_percentile":{"value":0.83386503,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":98},"biblio":{"volume":"E104.A","issue":"1","first_page":"152","last_page":"161"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10951","display_name":"Cryptographic Implementations and Security","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10951","display_name":"Cryptographic Implementations and Security","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9975000023841858,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9972000122070312,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/side-channel-attack","display_name":"Side channel attack","score":0.7320242524147034},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.6919555068016052},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6854785680770874},{"id":"https://openalex.org/keywords/information-leakage","display_name":"Information leakage","score":0.5502620935440063},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5130654573440552},{"id":"https://openalex.org/keywords/field-programmable-gate-array","display_name":"Field-programmable gate array","score":0.49871373176574707},{"id":"https://openalex.org/keywords/matrix-multiplication","display_name":"Matrix multiplication","score":0.4925838112831116},{"id":"https://openalex.org/keywords/multiplication","display_name":"Multiplication (music)","score":0.44471031427383423},{"id":"https://openalex.org/keywords/leakage","display_name":"Leakage (economics)","score":0.44209355115890503},{"id":"https://openalex.org/keywords/reverse-engineering","display_name":"Reverse engineering","score":0.4196210205554962},{"id":"https://openalex.org/keywords/enhanced-data-rates-for-gsm-evolution","display_name":"Enhanced Data Rates for GSM Evolution","score":0.41442179679870605},{"id":"https://openalex.org/keywords/computer-engineering","display_name":"Computer engineering","score":0.3811543583869934},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3702634572982788},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.25928112864494324},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.23923826217651367},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.22526398301124573},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.22284692525863647},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.12099304795265198},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.11015719175338745},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.10219255089759827}],"concepts":[{"id":"https://openalex.org/C49289754","wikidata":"https://www.wikidata.org/wiki/Q2267081","display_name":"Side channel attack","level":3,"score":0.7320242524147034},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.6919555068016052},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6854785680770874},{"id":"https://openalex.org/C2779201187","wikidata":"https://www.wikidata.org/wiki/Q2775060","display_name":"Information leakage","level":2,"score":0.5502620935440063},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5130654573440552},{"id":"https://openalex.org/C42935608","wikidata":"https://www.wikidata.org/wiki/Q190411","display_name":"Field-programmable gate array","level":2,"score":0.49871373176574707},{"id":"https://openalex.org/C17349429","wikidata":"https://www.wikidata.org/wiki/Q1049914","display_name":"Matrix multiplication","level":3,"score":0.4925838112831116},{"id":"https://openalex.org/C2780595030","wikidata":"https://www.wikidata.org/wiki/Q3860309","display_name":"Multiplication (music)","level":2,"score":0.44471031427383423},{"id":"https://openalex.org/C2777042071","wikidata":"https://www.wikidata.org/wiki/Q6509304","display_name":"Leakage (economics)","level":2,"score":0.44209355115890503},{"id":"https://openalex.org/C207850805","wikidata":"https://www.wikidata.org/wiki/Q269608","display_name":"Reverse engineering","level":2,"score":0.4196210205554962},{"id":"https://openalex.org/C162307627","wikidata":"https://www.wikidata.org/wiki/Q204833","display_name":"Enhanced Data Rates for GSM Evolution","level":2,"score":0.41442179679870605},{"id":"https://openalex.org/C113775141","wikidata":"https://www.wikidata.org/wiki/Q428691","display_name":"Computer engineering","level":1,"score":0.3811543583869934},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3702634572982788},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.25928112864494324},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.23923826217651367},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.22526398301124573},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.22284692525863647},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.12099304795265198},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.11015719175338745},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.10219255089759827},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C84114770","wikidata":"https://www.wikidata.org/wiki/Q46344","display_name":"Quantum","level":2,"score":0.0},{"id":"https://openalex.org/C139719470","wikidata":"https://www.wikidata.org/wiki/Q39680","display_name":"Macroeconomics","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C114614502","wikidata":"https://www.wikidata.org/wiki/Q76592","display_name":"Combinatorics","level":1,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1587/transfun.2020cip0024","is_oa":true,"landing_page_url":"https://doi.org/10.1587/transfun.2020cip0024","pdf_url":"https://www.jstage.jst.go.jp/article/transfun/E104.A/1/E104.A_2020CIP0024/_pdf","source":{"id":"https://openalex.org/S166990724","display_name":"IEICE Transactions on Fundamentals of Electronics Communications and Computer Sciences","issn_l":"0916-8508","issn":["0916-8508","1745-1337"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4320800604","host_organization_name":"Institute of Electronics, Information and Communication Engineers","host_organization_lineage":["https://openalex.org/P4320800604"],"host_organization_lineage_names":["Institute of Electronics, Information and Communication Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences","raw_type":"journal-article"},{"id":"pmh:oai:irdb.nii.ac.jp:01038:0006909128","is_oa":false,"landing_page_url":"https://ritsumei.repo.nii.ac.jp/records/2003600","pdf_url":null,"source":{"id":"https://openalex.org/S7407056385","display_name":"Institutional Repositories DataBase (IRDB)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I184597095","host_organization_name":"National Institute of Informatics","host_organization_lineage":["https://openalex.org/I184597095"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES","raw_type":"journal article"}],"best_oa_location":{"id":"doi:10.1587/transfun.2020cip0024","is_oa":true,"landing_page_url":"https://doi.org/10.1587/transfun.2020cip0024","pdf_url":"https://www.jstage.jst.go.jp/article/transfun/E104.A/1/E104.A_2020CIP0024/_pdf","source":{"id":"https://openalex.org/S166990724","display_name":"IEICE Transactions on Fundamentals of Electronics Communications and Computer Sciences","issn_l":"0916-8508","issn":["0916-8508","1745-1337"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4320800604","host_organization_name":"Institute of Electronics, Information and Communication Engineers","host_organization_lineage":["https://openalex.org/P4320800604"],"host_organization_lineage_names":["Institute of Electronics, Information and Communication Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences","raw_type":"journal-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/7","score":0.8100000023841858,"display_name":"Affordable and clean energy"}],"awards":[{"id":"https://openalex.org/G2247015924","display_name":null,"funder_award_id":"JPMJMI19B6","funder_id":"https://openalex.org/F4320338243","funder_display_name":"JST-Mirai Program"}],"funders":[{"id":"https://openalex.org/F4320338243","display_name":"JST-Mirai Program","ror":null}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3120524050.pdf","grobid_xml":"https://content.openalex.org/works/W3120524050.grobid-xml"},"referenced_works_count":22,"referenced_works":["https://openalex.org/W1562542037","https://openalex.org/W1945616565","https://openalex.org/W2017190079","https://openalex.org/W2017369466","https://openalex.org/W2051267297","https://openalex.org/W2144630005","https://openalex.org/W2435473771","https://openalex.org/W2461943168","https://openalex.org/W2593560938","https://openalex.org/W2606722458","https://openalex.org/W2759471388","https://openalex.org/W2787698406","https://openalex.org/W2807096445","https://openalex.org/W2809523935","https://openalex.org/W2811276992","https://openalex.org/W2908078360","https://openalex.org/W2927484433","https://openalex.org/W2944442501","https://openalex.org/W2951308087","https://openalex.org/W2990187689","https://openalex.org/W3029372783","https://openalex.org/W3091214985"],"related_works":["https://openalex.org/W3099313426","https://openalex.org/W4287593139","https://openalex.org/W752783541","https://openalex.org/W1506547947","https://openalex.org/W4206811032","https://openalex.org/W2995605830","https://openalex.org/W4239424132","https://openalex.org/W2022533428","https://openalex.org/W2580249689","https://openalex.org/W2596457687"],"abstract_inverted_index":{"A":[0],"model":[1,18,51,58,83,113,116,205,263,273],"extraction":[2,59,114],"attack":[3,197],"is":[4,19,84,175,186],"a":[5,15,66,81,171,203,266,293,297],"security":[6],"issue":[7],"in":[8,28,47,104,134,182,275],"deep":[9],"neural":[10],"networks":[11],"(DNNs).":[12],"Information":[13],"on":[14,57,86,125,218,296],"trained":[16,49,262],"DNN":[17,50,82,107,159,184,204,267,272,294],"an":[20,24,38,87,238,258],"attractive":[21],"target":[22],"for":[23,177,194,245,291],"adversary":[25,39,72,259],"not":[26],"only":[27],"terms":[29],"of":[30,35,158,202,212],"intellectual":[31],"property":[32],"but":[33],"also":[34],"security.":[36],"Thus,":[37],"tries":[40],"to":[41,98,120,137,223],"reveal":[42,99,138,199,261],"the":[43,48,63,71,74,94,100,105,139,178,183,195,207,213,250,271,276],"sensitive":[44,101],"information":[45,102,168],"contained":[46,103],"from":[52,123,142,170,206,230,265],"machine-learning":[53,67],"services.":[54,127],"Previous":[55,148],"studies":[56],"attacks":[60,115,119,124,136,154],"assumed":[61],"that":[62,225,257],"victim":[64],"provides":[65],"cloud":[68,126],"service":[69,75],"and":[70,96,198],"accesses":[73],"through":[76],"formal":[77],"queries.":[78],"However,":[79],"when":[80],"implemented":[85,106,217],"edge":[88],"device,":[89],"adversaries":[90],"can":[91,260],"physically":[92],"access":[93],"device":[95],"try":[97],"model.":[108],"We":[109,188],"call":[110],"these":[111],"physical":[112],"reverse-engineering":[117],"(MRE)":[118],"distinguish":[121],"them":[122],"Power":[128],"side-channel":[129,163,286],"analyses":[130],"are":[131,279],"often":[132],"used":[133,176],"MRE":[135,153,196],"internal":[140],"operation":[141],"power":[143,162,191],"consumption":[144],"or":[145,299],"electromagnetic":[146],"leakage.":[147],"studies,":[149],"including":[150],"ours,":[151],"evaluated":[152],"against":[155,249,285],"several":[156],"types":[157,211],"processors":[160,185],"with":[161,281],"analyses.":[164],"In":[165,234],"this":[166],"paper,":[167],"leakage":[169],"systolic":[172,208,214,232,251],"array":[173,215,221],"which":[174],"matrix":[179],"multiplication":[180],"unit":[181],"evaluated.":[187],"utilized":[189],"correlation":[190],"analysis":[192,240,248],"(CPA)":[193],"weight":[200,228],"parameters":[201,229,264,274],"array.":[209],"Two":[210],"were":[216],"field-programmable":[219],"gate":[220],"(FPGA)":[222],"demonstrate":[224],"CPA":[226,247],"reveals":[227],"those":[231],"arrays.":[233,252],"addition,":[235],"we":[236],"applied":[237],"extended":[239],"approach":[241],"called":[242],"\u201cchain":[243],"CPA\u201d":[244],"robust":[246],"Our":[253],"experimental":[254],"results":[255],"indicate":[256],"accelerator":[268,295],"even":[269],"if":[270],"off-chip":[277],"bus":[278],"protected":[280],"data":[282],"encryption.":[283],"Countermeasures":[284],"leaks":[287],"will":[288],"be":[289],"important":[290],"implementing":[292],"FPGA":[298],"application-specific":[300],"integrated":[301],"circuit":[302],"(ASIC).":[303]},"counts_by_year":[{"year":2025,"cited_by_count":5},{"year":2024,"cited_by_count":3},{"year":2023,"cited_by_count":4},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":3}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
