{"id":"https://openalex.org/W2946801000","doi":"https://doi.org/10.23919/date.2019.8715027","title":"Memory Trojan Attack on Neural Network Accelerators","display_name":"Memory Trojan Attack on Neural Network Accelerators","publication_year":2019,"publication_date":"2019-03-01","ids":{"openalex":"https://openalex.org/W2946801000","doi":"https://doi.org/10.23919/date.2019.8715027","mag":"2946801000"},"language":"en","primary_location":{"id":"doi:10.23919/date.2019.8715027","is_oa":false,"landing_page_url":"https://doi.org/10.23919/date.2019.8715027","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2019 Design, Automation &amp; Test in Europe Conference &amp; Exhibition (DATE)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5107593559","display_name":"Yang Zhao","orcid":"https://orcid.org/0000-0001-8023-1551"},"institutions":[{"id":"https://openalex.org/I154570441","display_name":"University of California, Santa Barbara","ror":"https://ror.org/02t274463","country_code":"US","type":"education","lineage":["https://openalex.org/I154570441"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yang Zhao","raw_affiliation_strings":["Department of Electrical and Computer Engineering, University of California, Santa Barbara"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, University of California, Santa Barbara","institution_ids":["https://openalex.org/I154570441"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101964036","display_name":"Xing Hu","orcid":"https://orcid.org/0000-0002-9979-0561"},"institutions":[{"id":"https://openalex.org/I154570441","display_name":"University of California, Santa Barbara","ror":"https://ror.org/02t274463","country_code":"US","type":"education","lineage":["https://openalex.org/I154570441"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xing Hu","raw_affiliation_strings":["Department of Electrical and Computer Engineering, University of California, Santa Barbara"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, University of California, Santa Barbara","institution_ids":["https://openalex.org/I154570441"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5021027241","display_name":"Shuangchen Li","orcid":"https://orcid.org/0000-0002-0021-6907"},"institutions":[{"id":"https://openalex.org/I154570441","display_name":"University of California, Santa Barbara","ror":"https://ror.org/02t274463","country_code":"US","type":"education","lineage":["https://openalex.org/I154570441"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Shuangchen Li","raw_affiliation_strings":["Department of Electrical and Computer Engineering, University of California, Santa Barbara"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, University of California, Santa Barbara","institution_ids":["https://openalex.org/I154570441"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100394414","display_name":"Jing Ye","orcid":"https://orcid.org/0000-0002-8023-5090"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210090176","display_name":"Institute of Computing Technology","ror":"https://ror.org/0090r4d87","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210090176"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jing Ye","raw_affiliation_strings":["State Key Laboratory of Computer Architecture, Institute of Computing Technology, Chinese Academy of Sciences"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"State Key Laboratory of Computer Architecture, Institute of Computing Technology, Chinese Academy of Sciences","institution_ids":["https://openalex.org/I4210090176","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5047545398","display_name":"Lei Deng","orcid":"https://orcid.org/0000-0002-5172-9411"},"institutions":[{"id":"https://openalex.org/I154570441","display_name":"University of California, Santa Barbara","ror":"https://ror.org/02t274463","country_code":"US","type":"education","lineage":["https://openalex.org/I154570441"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Lei Deng","raw_affiliation_strings":["Department of Electrical and Computer Engineering, University of California, Santa Barbara"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, University of California, Santa Barbara","institution_ids":["https://openalex.org/I154570441"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101794146","display_name":"Yu Ji","orcid":"https://orcid.org/0000-0002-3741-5627"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yu Ji","raw_affiliation_strings":["Tsinghua University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Tsinghua University","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101688363","display_name":"Jianyu Xu","orcid":"https://orcid.org/0000-0003-0976-5096"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jianyu Xu","raw_affiliation_strings":["Tsinghua University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Tsinghua University","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103200805","display_name":"Dong Wu","orcid":"https://orcid.org/0000-0002-2306-5769"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Dong Wu","raw_affiliation_strings":["Tsinghua University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Tsinghua University","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100385336","display_name":"Yuan Xie","orcid":"https://orcid.org/0000-0003-2093-1788"},"institutions":[{"id":"https://openalex.org/I154570441","display_name":"University of California, Santa Barbara","ror":"https://ror.org/02t274463","country_code":"US","type":"education","lineage":["https://openalex.org/I154570441"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yuan Xie","raw_affiliation_strings":["Department of Electrical and Computer Engineering, University of California, Santa Barbara"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, University of California, Santa Barbara","institution_ids":["https://openalex.org/I154570441"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":9,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":4.1936,"has_fulltext":false,"cited_by_count":51,"citation_normalized_percentile":{"value":0.95257858,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"1415","last_page":"1420"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10502","display_name":"Advanced Memory and Neural Computing","score":0.9972000122070312,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/toolchain","display_name":"Toolchain","score":0.8527308702468872},{"id":"https://openalex.org/keywords/trojan","display_name":"Trojan","score":0.7977584600448608},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7713830471038818},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.544744610786438},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.535351574420929},{"id":"https://openalex.org/keywords/leverage","display_name":"Leverage (statistics)","score":0.509440004825592},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.4497305750846863},{"id":"https://openalex.org/keywords/hardware-trojan","display_name":"Hardware Trojan","score":0.4470670223236084},{"id":"https://openalex.org/keywords/software-deployment","display_name":"Software deployment","score":0.44313865900039673},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.37989699840545654},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.2821044325828552},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.2559659481048584},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.24365824460983276}],"concepts":[{"id":"https://openalex.org/C2777062904","wikidata":"https://www.wikidata.org/wiki/Q545406","display_name":"Toolchain","level":3,"score":0.8527308702468872},{"id":"https://openalex.org/C174333608","wikidata":"https://www.wikidata.org/wiki/Q19635","display_name":"Trojan","level":2,"score":0.7977584600448608},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7713830471038818},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.544744610786438},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.535351574420929},{"id":"https://openalex.org/C153083717","wikidata":"https://www.wikidata.org/wiki/Q6535263","display_name":"Leverage (statistics)","level":2,"score":0.509440004825592},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.4497305750846863},{"id":"https://openalex.org/C2780873074","wikidata":"https://www.wikidata.org/wiki/Q5656397","display_name":"Hardware Trojan","level":3,"score":0.4470670223236084},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.44313865900039673},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.37989699840545654},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.2821044325828552},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.2559659481048584},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.24365824460983276}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.23919/date.2019.8715027","is_oa":false,"landing_page_url":"https://doi.org/10.23919/date.2019.8715027","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2019 Design, Automation &amp; Test in Europe Conference &amp; Exhibition (DATE)","raw_type":"proceedings-article"},{"id":"pmh:oai:repository.hkust.edu.hk:1783.1-133387","is_oa":false,"landing_page_url":"https://repository.hkust.edu.hk/ir/Record/1783.1-133387","pdf_url":null,"source":{"id":"https://openalex.org/S4306401796","display_name":"Rare & Special e-Zone (The Hong Kong University of Science and Technology)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I200769079","host_organization_name":"Hong Kong University of Science and Technology","host_organization_lineage":["https://openalex.org/I200769079"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Conference paper"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":29,"referenced_works":["https://openalex.org/W1686810756","https://openalex.org/W1976955200","https://openalex.org/W2032121576","https://openalex.org/W2117539524","https://openalex.org/W2161998562","https://openalex.org/W2163605009","https://openalex.org/W2170993700","https://openalex.org/W2194775991","https://openalex.org/W2442974303","https://openalex.org/W2604319603","https://openalex.org/W2621405616","https://openalex.org/W2807765471","https://openalex.org/W2808426733","https://openalex.org/W2809300109","https://openalex.org/W2962939738","https://openalex.org/W3143328915","https://openalex.org/W4242053016","https://openalex.org/W4246001895","https://openalex.org/W4249932213","https://openalex.org/W4300511536","https://openalex.org/W6637373629","https://openalex.org/W6658216208","https://openalex.org/W6683630750","https://openalex.org/W6684191040","https://openalex.org/W6719080892","https://openalex.org/W6738964779","https://openalex.org/W6752265895","https://openalex.org/W6752765571","https://openalex.org/W6898611122"],"related_works":["https://openalex.org/W4385434494","https://openalex.org/W3159333627","https://openalex.org/W3004467197","https://openalex.org/W2091750459","https://openalex.org/W4328053173","https://openalex.org/W1500594134","https://openalex.org/W3084939900","https://openalex.org/W2382172865","https://openalex.org/W1526642037","https://openalex.org/W4321062229"],"abstract_inverted_index":{"Neural":[0,89],"network":[1],"accelerators":[2],"are":[3,52],"widely":[4],"deployed":[5],"in":[6,46],"application":[7],"systems":[8],"for":[9,28,78],"computer":[10],"vision,":[11],"speech":[12],"recognition,":[13],"and":[14,99,128,176,187],"machine":[15],"translation.":[16],"Due":[17],"to":[18,30,55,65,81,95,139],"ubiquitous":[19],"deployment":[20],"of":[21,40,72,125,191],"these":[22],"systems,":[23],"a":[24,76,118,148],"strong":[25],"incentive":[26],"rises":[27],"adversaries":[29],"attack":[31,44],"such":[32],"artificial":[33],"intelligence":[34],"(AI)":[35],"systems.":[36],"Trojan":[37,85,120,149],"is":[38,106],"one":[39],"the":[41,63,73,79,83,96,103,123,135,141,154,160,179,183,189],"most":[42],"important":[43],"models":[45],"hardware":[47,84,100],"security":[48],"domain.":[49],"Hardware":[50],"Trojans":[51,92],"malicious":[53],"modifications":[54],"original":[56,180],"ICs":[57],"inserted":[58],"by":[59],"adversaries,":[60],"which":[61,108,163],"lead":[62],"system":[64],"malfunction":[66],"after":[67],"being":[68],"triggered.":[69],"The":[70,167],"globalization":[71],"semiconductor":[74],"gives":[75],"chance":[77],"adversary":[80],"conduct":[82],"attacks.Previous":[86],"works":[87,170],"design":[88],"Network":[90],"(NN)":[91],"with":[93,173],"access":[94,137],"model,":[97],"toolchain,":[98],"platform.":[101],"However,":[102],"threat":[104],"model":[105,129],"impractical":[107],"hinders":[109],"their":[110],"real":[111],"adoption.":[112],"In":[113,182],"this":[114],"work,":[115],"we":[116,146,185],"propose":[117,147],"memory":[119,136],"methodology":[121],"without":[122],"help":[124],"toolchain":[126],"manipulation":[127],"parameter":[130],"information.":[131],"We":[132],"first":[133],"leverage":[134],"patterns":[138],"identify":[140],"input":[142,156],"image":[143,157],"data.":[144],"Then":[145],"triggering":[150,168],"method":[151],"based":[152],"on":[153],"dedicated":[155],"other":[158],"than":[159],"circuit":[161],"events,":[162],"has":[164],"better":[165],"controllability.":[166],"mechanism":[169],"well":[171],"even":[172],"environment":[174],"noise":[175],"preprocessing":[177],"towards":[178],"images.":[181],"end,":[184],"implement":[186],"verify":[188],"effectiveness":[190],"accuracy":[192],"degradation":[193],"attack.":[194]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":7},{"year":2024,"cited_by_count":7},{"year":2023,"cited_by_count":6},{"year":2022,"cited_by_count":4},{"year":2021,"cited_by_count":7},{"year":2020,"cited_by_count":16},{"year":2019,"cited_by_count":2}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
