{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T05:43:25Z","timestamp":1782971005689,"version":"3.54.5"},"publisher-location":"Cham","reference-count":30,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031541285","type":"print"},{"value":"9783031541292","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-54129-2_38","type":"book-chapter","created":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:03:15Z","timestamp":1710194595000},"page":"644-664","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Fault Injection and\u00a0Safe-Error Attack for\u00a0Extraction of\u00a0Embedded Neural Network Models"],"prefix":"10.1007","author":[{"given":"Kevin","family":"Hector","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pierre-Alain","family":"Mo\u00ebllic","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jean-Max","family":"Dutertre","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mathieu","family":"Dumont","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,3,12]]},"reference":[{"key":"38_CR1","doi-asserted-by":"crossref","unstructured":"Agoyan, M., et al.: How to flip a bit? In: 2010 IEEE 16th International On-Line Testing Symposium, pp. 235\u2013239. IEEE (2010)","DOI":"10.1109\/IOLTS.2010.5560194"},{"key":"38_CR2","first-page":"20120","volume":"33","author":"A Barbalau","year":"2020","unstructured":"Barbalau, A., Cosma, A., Ionescu, R.T., Popescu, M.: Black-box ripper: copying black-box models using generative evolutionary algorithms. Adv. Neural. Inf. Process. Syst. 33, 20120\u201320129 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"issue":"11","key":"38_CR3","doi-asserted-by":"publisher","first-page":"3056","DOI":"10.1109\/JPROC.2012.2188769","volume":"100","author":"A Barenghi","year":"2012","unstructured":"Barenghi, A., Breveglieri, L., Koren, I., Naccache, D.: Fault injection attacks on cryptographic devices: theory, practice, and countermeasures. Proc. IEEE 100(11), 3056\u20133076 (2012)","journal-title":"Proc. IEEE"},{"key":"38_CR4","unstructured":"Batina, L., Bhasin, S., Jap, D., Picek, S.: Csi nn: reverse engineering of neural network architectures through electromagnetic side channel (2019)"},{"key":"38_CR5","doi-asserted-by":"publisher","first-page":"113122","DOI":"10.1109\/ACCESS.2022.3217212","volume":"10","author":"J Breier","year":"2022","unstructured":"Breier, J., Hou, X.: How practical are fault injection attacks, really? IEEE Access 10, 113122\u2013113130 (2022)","journal-title":"IEEE Access"},{"issue":"4","key":"38_CR6","doi-asserted-by":"publisher","first-page":"1527","DOI":"10.1109\/TR.2021.3105697","volume":"71","author":"J Breier","year":"2021","unstructured":"Breier, J., Jap, D., Hou, X., Bhasin, S., Liu, Y.: Sniff: reverse engineering of neural networks with fault attacks. IEEE Trans. Reliab. 71(4), 1527\u20131539 (2021)","journal-title":"IEEE Trans. Reliab."},{"key":"38_CR7","unstructured":"Brendel, W., Rauber, J., Bethge, M.: Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. In: International Conference on Learning Representations (2018)"},{"key":"38_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"189","DOI":"10.1007\/978-3-030-56877-1_7","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"N Carlini","year":"2020","unstructured":"Carlini, N., Jagielski, M., Mironov, I.: Cryptanalytic extraction of neural\u00a0network models. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020. LNCS, vol. 12172, pp. 189\u2013218. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56877-1_7"},{"key":"38_CR9","unstructured":"Chandrasekaran, V., Chaudhuri, K., Giacomelli, I., Jha, S., Yan, S.: Exploring connections between active learning and model extraction. In: 29th USENIX Security Symposium (USENIX Security 20), pp. 1309\u20131326 (2020)"},{"key":"38_CR10","doi-asserted-by":"crossref","unstructured":"Colombier, B., Menu, A., Dutertre, J.M., Mo\u00ebllic, P.A., Rigaud, J.B., Danger, J.L.: Laser-induced single-bit faults in flash memory: Instructions corruption on a 32-bit microcontroller. In: 2019 IEEE International Symposium on Hardware Oriented Security and Trust (HOST), pp. 1\u201310. IEEE (2019)","DOI":"10.1109\/HST.2019.8741030"},{"key":"38_CR11","doi-asserted-by":"crossref","unstructured":"Dumont, M., Hector, K., Moellic, P.A., Dutertre, J.M., Ponti\u00e9, S.: Evaluation of parameter-based attacks against embedded neural networks with laser injection. arXiv preprint arXiv:2304.12876 (2023)","DOI":"10.1007\/978-3-031-40923-3_19"},{"key":"38_CR12","doi-asserted-by":"crossref","unstructured":"Dutertre, J.M., et al.: Laser fault injection at the cmos 28 nm technology node: an analysis of the fault model. In: 2018 Workshop on Fault Diagnosis and Tolerance in Cryptography (FDTC), pp. 1\u20136. 14th Workshop on Fault Diagnosis and Tolerance in Cryptography, September 2018","DOI":"10.1109\/FDTC.2018.00009"},{"key":"38_CR13","unstructured":"Jagielski, M., Carlini, N., Berthelot, D., Kurakin, A., Papernot, N.: High accuracy and high fidelity extraction of neural networks, pp. 1345\u20131362 (2020)"},{"key":"38_CR14","doi-asserted-by":"crossref","unstructured":"Joud, R., Mo\u00ebllic, P.A., Ponti\u00e9, S., Rigaud, J.B.: A practical introduction to side-channel extraction of deep neural network parameters. In: Smart Card Research and Advanced Applications: 21st International Conference, CARDIS 2022, Birmingham, UK, November 7\u20139, 2022, Revised Selected Papers, pp. 45\u201365. Springer (2023)","DOI":"10.1007\/978-3-031-25319-5_3"},{"issue":"3","key":"38_CR15","doi-asserted-by":"publisher","first-page":"361","DOI":"10.1145\/2678373.2665726","volume":"42","author":"Y Kim","year":"2014","unstructured":"Kim, Y., et al.: Flipping bits in memory without accessing them: an experimental study of dram disturbance errors. ACM SIGARCH Comput. Architecture News 42(3), 361\u2013372 (2014)","journal-title":"ACM SIGARCH Comput. Architecture News"},{"key":"38_CR16","doi-asserted-by":"crossref","unstructured":"Kwong, A., Genkin, D., Gruss, D., Yarom, Y.: Rambleed: reading bits in memory without accessing them. In: 2020 IEEE Symposium on Security and Privacy (SP), pp. 695\u2013711. IEEE (2020)","DOI":"10.1109\/SP40000.2020.00020"},{"key":"38_CR17","unstructured":"Lai, L., Suda, N., Chandra, V.: Cmsis-nn: Efficient neural network kernels for arm cortex-m cpus. arXiv preprint arXiv:1801.06601 (2018)"},{"key":"38_CR18","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. In: International Conference on Learning Representations (2018)"},{"issue":"15","key":"38_CR19","doi-asserted-by":"publisher","first-page":"12079","DOI":"10.1109\/JIOT.2021.3061314","volume":"8","author":"S Maji","year":"2021","unstructured":"Maji, S., Banerjee, U., Chandrakasan, A.P.: Leaky nets: Recovering embedded neural network models and inputs through simple power and timing side-channels-attacks and defenses. IEEE Internet Things J. 8(15), 12079\u201312092 (2021)","journal-title":"IEEE Internet Things J."},{"key":"38_CR20","doi-asserted-by":"crossref","unstructured":"Menu, A., Dutertre, J.M., Rigaud, J.B., Colombier, B., Moellic, P.A., Danger, J.L.: Single-bit laser fault model in nor flash memories: analysis and exploitation. In: 2020 Workshop on Fault Detection and Tolerance in Cryptography (FDTC), pp. 41\u201348. IEEE (2020)","DOI":"10.1109\/FDTC51366.2020.00013"},{"key":"38_CR21","doi-asserted-by":"crossref","unstructured":"Orekondy, T., Schiele, B., Fritz, M.: Knockoff nets: stealing functionality of black-box models. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 4954\u20134963 (2019)","DOI":"10.1109\/CVPR.2019.00509"},{"key":"38_CR22","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z.B., Swami, A.: Practical Black-Box Attacks against Machine Learning. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, ASIA CCS 2017, pp. 506\u2013519. Association for Computing Machinery, New York, NY, USA, April 2017","DOI":"10.1145\/3052973.3053009"},{"key":"38_CR23","doi-asserted-by":"crossref","unstructured":"Qiu, P., Wang, D., Lyu, Y., Qu, G.: Voltjockey: breaching trustzone by software-controlled voltage manipulation over multi-core frequencies. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pp. 195\u2013209 (2019)","DOI":"10.1145\/3319535.3354201"},{"key":"38_CR24","doi-asserted-by":"crossref","unstructured":"Rakin, A.S., Chowdhuryy, M.H.I., Yao, F., Fan, D.: Deepsteal: advanced model extractions leveraging efficient weight stealing in memories. In: 2022 IEEE Symposium on Security and Privacy (SP), pp. 1157\u20131174 (2022)","DOI":"10.1109\/SP46214.2022.9833743"},{"key":"38_CR25","doi-asserted-by":"crossref","unstructured":"Rakin, A.S., He, Z., Fan, D.: Bit-flip attack: crushing neural network with progressive bit search. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 1211\u20131220 (2019)","DOI":"10.1109\/ICCV.2019.00130"},{"key":"38_CR26","unstructured":"Rolnick, D., Kording, K.: Reverse-engineering deep relu networks. In: International Conference on Machine Learning, pp. 8178\u20138187. PMLR (2020)"},{"key":"38_CR27","doi-asserted-by":"crossref","unstructured":"Roscian, C., Sarafianos, A., Dutertre, J.M., Tria, A.: Fault model analysis of laser-induced faults in sram memory cells. In: 2013 Workshop on Fault Diagnosis and Tolerance in Cryptography, pp. 89\u201398 (2013)","DOI":"10.1109\/FDTC.2013.17"},{"key":"38_CR28","unstructured":"Tram\u00e8r, F., Zhang, F., Juels, A., Reiter, M.K., Ristenpart, T.: Stealing machine learning models via prediction apis. In: USENIX Security Symposium, vol. 16, pp. 601\u2013618 (2016)"},{"key":"38_CR29","doi-asserted-by":"crossref","unstructured":"Trouchkine, T., Bouffard, G., Cl\u00e9di\u00e8re, J.: Em fault model characterization on socs: from different architectures to the same fault model. In: 2021 Workshop on Fault Detection and Tolerance in Cryptography (FDTC), pp. 31\u201338. IEEE (2021)","DOI":"10.1109\/FDTC53659.2021.00014"},{"issue":"9","key":"38_CR30","doi-asserted-by":"publisher","first-page":"967","DOI":"10.1109\/12.869328","volume":"49","author":"SM Yen","year":"2000","unstructured":"Yen, S.M., Joye, M.: Checking before output may not be enough against fault-based cryptanalysis. IEEE Trans. Comput. 49(9), 967\u2013970 (2000)","journal-title":"IEEE Trans. Comput."}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2023 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-54129-2_38","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:08:17Z","timestamp":1710194897000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-54129-2_38"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031541285","9783031541292"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-54129-2_38","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"12 March 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Hague","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Netherlands","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 September 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2023.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"478","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"93","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3-4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"10","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}