{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,25]],"date-time":"2025-03-25T19:45:15Z","timestamp":1742931915254,"version":"3.40.3"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030950842"},{"type":"electronic","value":"9783030950859"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-030-95085-9_8","type":"book-chapter","created":{"date-parts":[[2022,1,28]],"date-time":"2022-01-28T20:02:35Z","timestamp":1643400155000},"page":"148-167","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Parasite: Mitigating Physical Side-Channel Attacks Against Neural Networks"],"prefix":"10.1007","author":[{"given":"Herv\u00e9","family":"Chabanne","sequence":"first","affiliation":[]},{"given":"Jean-Luc","family":"Danger","sequence":"additional","affiliation":[]},{"given":"Linda","family":"Guiga","sequence":"additional","affiliation":[]},{"given":"Ulrich","family":"K\u00fchne","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2022,1,28]]},"reference":[{"key":"8_CR1","unstructured":"Batina, L., Bhasin, S., Jap, D., Picek, S.: CSI NN: reverse engineering of neural network architectures through electromagnetic side channel. In: USENIX Security Symposium, pp. 515\u2013532. USENIX Association (2019)"},{"key":"8_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1007\/978-3-319-75208-2_2","volume-title":"Smart Card Research and Advanced Applications","author":"A Biryukov","year":"2018","unstructured":"Biryukov, A., Dinu, D., Le Corre, Y., Udovenko, A.: Optimal first-order Boolean masking for embedded IoT devices. In: Eisenbarth, T., Teglia, Y. (eds.) CARDIS 2017. LNCS, vol. 10728, pp. 22\u201341. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-75208-2_2"},{"key":"8_CR3","doi-asserted-by":"crossref","unstructured":"Breier, J., Jap, D., Hou, X., Bhasin, S., Liu, Y.: SNIFF: reverse engineering of neural networks with fault attacks. CoRR abs\/2002.11021 (2020)","DOI":"10.1109\/TR.2021.3105697"},{"key":"8_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1007\/978-3-540-28632-5_2","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2004","author":"E Brier","year":"2004","unstructured":"Brier, E., Clavier, C., Olivier, F.: Correlation power analysis with a leakage model. In: Joye, M., Quisquater, J.-J. (eds.) CHES 2004. LNCS, vol. 3156, pp. 16\u201329. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-28632-5_2"},{"key":"8_CR5","doi-asserted-by":"crossref","unstructured":"Camurati, G., Poeplau, S., Muench, M., Hayes, T., Francillon, A.: Screaming channels: when electromagnetic side channels meet radio transceivers. In: CCS, pp. 163\u2013177. ACM (2018)","DOI":"10.1145\/3243734.3243802"},{"key":"8_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"189","DOI":"10.1007\/978-3-030-56877-1_7","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"N Carlini","year":"2020","unstructured":"Carlini, N., Jagielski, M., Mironov, I.: Cryptanalytic extraction of neural\u00a0network models. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020. LNCS, vol. 12172, pp. 189\u2013218. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56877-1_7"},{"key":"8_CR7","doi-asserted-by":"crossref","unstructured":"Chabanne, H., Despiegel, V., Guiga, L.: A protection against the extraction of neural network models. In: ICISSP, pp. 258\u2013269. SCITEPRESS (2021)","DOI":"10.5220\/0010373302580269"},{"issue":"1","key":"8_CR8","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1049\/cit2.12026","volume":"6","author":"H Chabanne","year":"2021","unstructured":"Chabanne, H., Danger, J., Guiga, L., K\u00fchne, U.: Side channel attacks for architecture extraction of neural networks. CAAI Trans. Intell. Technol. 6(1), 3\u201316 (2021)","journal-title":"CAAI Trans. Intell. Technol."},{"key":"8_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"96","DOI":"10.1007\/978-3-030-81645-2_7","volume-title":"Applied Cryptography and Network Security Workshops","author":"\u0141 Chmielewski","year":"2021","unstructured":"Chmielewski, \u0141, Weissbart, L.: On reverse engineering neural network implementation on GPU. In: Zhou, J., et al. (eds.) ACNS 2021. LNCS, vol. 12809, pp. 96\u2013113. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-81645-2_7"},{"key":"8_CR10","doi-asserted-by":"crossref","unstructured":"Deng, J., Dong, W., Socher, R., Li, L.J., Li, K., Fei-Fei, L.: ImageNet: a large-scale hierarchical image database. In: 2009 IEEE Conference on Computer Vision and Pattern Recognition, pp. 248\u2013255. IEEE (2009)","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"8_CR11","unstructured":"Dubey, A., Cammarota, R., Aysu, A.: MaskedNet: a pathway for secure inference against power side-channel attacks. CoRR abs\/1910.13063 (2019)"},{"key":"8_CR12","doi-asserted-by":"crossref","unstructured":"Dubey, A., Cammarota, R., Aysu, A.: BomaNet: Boolean masking of an entire neural network. CoRR abs\/2006.09532 (2020)","DOI":"10.1145\/3400302.3415649"},{"key":"8_CR13","unstructured":"Duddu, V., Samanta, D., Rao, D.V., Balas, V.E.: Stealing neural networks via timing side channels. CoRR abs\/1812.11720 (2018). http:\/\/arxiv.org\/abs\/1812.11720"},{"key":"8_CR14","unstructured":"Eberl, M.: Fisher-yates shuffle. Arch. Formal Proofs 2016 (2016)"},{"key":"8_CR15","doi-asserted-by":"crossref","unstructured":"Genkin, D., Pachmanov, L., Pipman, I., Tromer, E., Yarom, Y.: ECDSA key extraction from mobile devices via nonintrusive physical side channels. IACR Cryptol. ePrint Arch. 2016, 230 (2016)","DOI":"10.1145\/2976749.2978353"},{"key":"8_CR16","unstructured":"Hong, S., et al.: Security analysis of deep neural networks operating in the presence of cache side-channel attacks (code) (2017)"},{"key":"8_CR17","unstructured":"Hong, S., Davinroy, M., Kaya, Y., Dachman-Soled, D., Dumitras, T.: How to 0wn NAS in your spare time. In: International Conference on Learning Representations (2020)"},{"key":"8_CR18","doi-asserted-by":"crossref","unstructured":"Hua, W., Zhang, Z., Suh, G.E.: Reverse engineering convolutional neural networks through side-channel information leaks. In: DAC, pp. 4:1\u20134:6. ACM (2018)","DOI":"10.1145\/3195970.3196105"},{"key":"8_CR19","unstructured":"Jagielski, M., Carlini, N., Berthelot, D., Kurakin, A., Papernot, N.: High-fidelity extraction of neural network models. CoRR abs\/1909.01838 (2019)"},{"key":"8_CR20","unstructured":"Jagielski, M., Carlini, N., Berthelot, D., Kurakin, A., Papernot, N.: High accuracy and high fidelity extraction of neural networks. In: Capkun, S., Roesner, F. (eds.) 29th USENIX Security Symposium, USENIX Security 2020, 12\u201314 August 2020, pp. 1345\u20131362. USENIX Association (2020)"},{"key":"8_CR21","unstructured":"Krizhevsky, A.: Learning multiple layers of features from tiny images. Technical report (2009)"},{"issue":"33","key":"8_CR22","doi-asserted-by":"publisher","first-page":"747","DOI":"10.21105\/joss.00747","volume":"4","author":"A LeNail","year":"2019","unstructured":"LeNail, A.: NN-SVG: publication-ready neural network architecture schematics. J. Open Source Softw. 4(33), 747 (2019)","journal-title":"J. Open Source Softw."},{"key":"8_CR23","doi-asserted-by":"crossref","unstructured":"Milli, S., Schmidt, L., Dragan, A.D., Hardt, M.: Model reconstruction from model explanations, pp. 1\u20139. Association for Computing Machinery, New York (2019)","DOI":"10.1145\/3287560.3287562"},{"key":"8_CR24","doi-asserted-by":"crossref","unstructured":"Mondal, A., Srivastava, A.: Energy-efficient design of MTJ-based neural networks with stochastic computing. ACM J. Emerg. Technol. Comput. Syst. 16(1), 7:1\u20137:27 (2020)","DOI":"10.1145\/3359622"},{"key":"8_CR25","series-title":"Lecture Notes in Computer Science (Lecture Notes in Artificial Intelligence)","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1007\/978-3-030-28954-6_7","volume-title":"Explainable AI: Interpreting, Explaining and Visualizing Deep Learning","author":"SJ Oh","year":"2019","unstructured":"Oh, S.J., Schiele, B., Fritz, M.: Towards reverse-engineering black-box neural networks. In: Samek, W., Montavon, G., Vedaldi, A., Hansen, L.K., M\u00fcller, K.-R. (eds.) Explainable AI: Interpreting, Explaining and Visualizing Deep Learning. LNCS (LNAI), vol. 11700, pp. 121\u2013144. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-28954-6_7"},{"key":"8_CR26","unstructured":"Rolnick, D., Kording, K.P.: Reverse-engineering deep Relu networks. In: Proceedings of the 37th International Conference on Machine Learning, ICML 2020, 13\u201318 July 2020, Virtual Event. Proceedings of Machine Learning Research, vol. 119, pp. 8178\u20138187. PMLR (2020)"},{"key":"8_CR27","doi-asserted-by":"crossref","unstructured":"Sandler, M., Howard, A.G., Zhu, M., Zhmoginov, A., Chen, L.: MobileNetV2: inverted residuals and linear bottlenecks. In: 2018 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2018, Salt Lake City, UT, USA, 18\u201322 June 2018, pp. 4510\u20134520. IEEE Computer Society (2018)","DOI":"10.1109\/CVPR.2018.00474"},{"key":"8_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1007\/978-3-030-61638-0_11","volume-title":"Applied Cryptography and Network Security Workshops","author":"G Takatoi","year":"2020","unstructured":"Takatoi, G., Sugawara, T., Sakiyama, K., Li, Y.: Simple electromagnetic analysis against activation functions of deep neural networks. In: Zhou, J., et al. (eds.) ACNS 2020. LNCS, vol. 12418, pp. 181\u2013197. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-61638-0_11"},{"key":"8_CR29","doi-asserted-by":"crossref","unstructured":"Wang, R., Wang, H., Dubrova, E.: Far field EM side-channel attack on AES using deep learning. In: ASHES@CCS, pp. 35\u201344. ACM (2020)","DOI":"10.1145\/3411504.3421214"},{"key":"8_CR30","doi-asserted-by":"crossref","unstructured":"Wang, X., Hou, R., Zhu, Y., Zhang, J., Meng, D.: NPUFort: a secure architecture of DNN accelerator against model inversion attack. In: CF, pp. 190\u2013196. ACM (2019)","DOI":"10.1145\/3310273.3323070"},{"key":"8_CR31","doi-asserted-by":"crossref","unstructured":"Y. LeCun, L. Bottou, Y.B., Haffner, P.: Gradient-based learning applied to document recognition. In: Proceedings of IEEE (1998)","DOI":"10.1109\/5.726791"},{"key":"8_CR32","unstructured":"Yan, M., Fletcher, C.W., Torrellas, J.: Cache telepathy: leveraging shared resource attacks to learn DNN architectures. In: USENIX Security Symposium, pp. 2003\u20132020. USENIX Association (2020)"},{"key":"8_CR33","unstructured":"Zhang, C., Bengio, S., Hardt, M., Mozer, M.C., Singer, Y.: Identity crisis: memorization and generalization under extreme overparameterization. In: 8th International Conference on Learning Representations, ICLR 2020, Addis Ababa, Ethiopia, 26\u201330 April 2020. OpenReview.net (2020)"}],"container-title":["Lecture Notes in Computer Science","Security, Privacy, and Applied Cryptography Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-95085-9_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,21]],"date-time":"2022-04-21T15:07:23Z","timestamp":1650553643000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-95085-9_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783030950842","9783030950859"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-95085-9_8","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"28 January 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SPACE","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Security, Privacy, and Applied Cryptography Engineering","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Kolkata","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"India","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 December 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13 December 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"space2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/cse.iitkgp.ac.in\/conf\/SPACE2021\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"42","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"13","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"31% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2.74","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2.19","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"The conference was held virtually due to the COVID-19 pandemic.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}