{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,26]],"date-time":"2026-02-26T21:26:42Z","timestamp":1772141202507,"version":"3.50.1"},"reference-count":47,"publisher":"IEEE","license":[{"start":{"date-parts":[[2020,12,7]],"date-time":"2020-12-07T00:00:00Z","timestamp":1607299200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2020,12,7]],"date-time":"2020-12-07T00:00:00Z","timestamp":1607299200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,12,7]],"date-time":"2020-12-07T00:00:00Z","timestamp":1607299200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,12,7]]},"DOI":"10.1109\/host45689.2020.9300274","type":"proceedings-article","created":{"date-parts":[[2020,12,25]],"date-time":"2020-12-25T22:19:40Z","timestamp":1608934780000},"page":"209-218","source":"Crossref","is-referenced-by-count":90,"title":["DeepEM: Deep Neural Networks Model Recovery through EM Side-Channel Information Leakage"],"prefix":"10.1109","author":[{"given":"Honggang","family":"Yu","sequence":"first","affiliation":[]},{"given":"Haocheng","family":"Ma","sequence":"additional","affiliation":[]},{"given":"Kaichen","family":"Yang","sequence":"additional","affiliation":[]},{"given":"Yiqiang","family":"Zhao","sequence":"additional","affiliation":[]},{"given":"Yier","family":"Jin","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.9"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2015.7301270"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3020078.3021741"},{"key":"ref32","article-title":"Adversarial manipulation of deep representations","author":"sabour","year":"2016","journal-title":"Proceedings of the International Conference on Learning Representations (ICLR)"},{"key":"ref31","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"arXiv preprint arXiv 1312 6199"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ISVLSI.2019.00122"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref36","article-title":"Mobilenets: Efficient convolutional neural networks for mobile vision applications","volume":"abs 1704 4861","author":"howard","year":"2017","journal-title":"CoRR"},{"key":"ref35","article-title":"Squeezenet: Alexnet-level accuracy with 50x fewer parameters and <1mb model size","volume":"abs 1602 7360","author":"iandola","year":"2016","journal-title":"CoRR"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.29007\/k6cr"},{"key":"ref10","first-page":"515","article-title":"CSI NN: Reverse engineering of neural network architectures through electromagnetic side channel","author":"batina","year":"2019","journal-title":"28th USENIX Security Symposium (USENIX Security 19)"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.244"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/1-4020-8147-2_9"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24178"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref15","article-title":"Xnor-net: Imagenet classification using binary convolutional neural networks","author":"rastegari","year":"2016","journal-title":"ECCV"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3020078.3021744"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/IPDPSW.2017.95"},{"key":"ref18","first-page":"4107","article-title":"Binarized neural networks","author":"hubara","year":"2016","journal-title":"Advances in Neural IInformation Processing Systems"},{"key":"ref19","article-title":"Binarynet: Training deep neural networks with weights and activations constrained to +1 or - 1","volume":"abs 1602 2830","author":"courbariaux","year":"2016","journal-title":"CoRR"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TVLSI.2004.831478"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-14706-7_20"},{"key":"ref27","first-page":"1","article-title":"A dynamic partial reconfigurable overlay concept for pynq","author":"jan\u00dfen","year":"2017","journal-title":"2017 27th International Conference on Field Programmable Logic and Applications (FPL)"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01214"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_36"},{"key":"ref29","article-title":"Stealing neural networks via timing side channels","author":"duddu","year":"2018","journal-title":"arXiv preprint arXiv 1812 11720"},{"key":"ref5","article-title":"Very deep convolutional networks for natural language processing","volume":"abs 1606 1781","author":"conneau","year":"2016","journal-title":"CoRR"},{"key":"ref8","article-title":"Security analysis of deep neural networks operating in the presence of cache side-channel attacks","volume":"abs 1810 3487","author":"hong","year":"2018","journal-title":"CoRR"},{"key":"ref7","first-page":"4:1","article-title":"Reverse engineering convolutional neural networks through side-channel information leaks","author":"hua","year":"2018","journal-title":"Proceedings of the 55th Annual Design Automation Conference ser DAC &#x2019;18"},{"key":"ref2","article-title":"Attentive feedback network for boundaryaware salient object detection","author":"feng","year":"2019","journal-title":"The IEEE Conference on Computer Vision and Pattern Recognition (CVPR)"},{"key":"ref9","article-title":"Stealing neural networks via timing side channels","volume":"abs 1812 11720","author":"duddu","year":"2018","journal-title":"CoRR"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00114"},{"key":"ref46","article-title":"High-fidelity extraction of neural network models","author":"jagielski","year":"2019","journal-title":"arXiv preprint arXiv 1909 01771"},{"key":"ref20","first-page":"1289","article-title":"Multiple-instance active learning","author":"settles","year":"2008","journal-title":"Advances in Neural Information Processing Systems 20"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.3115\/1613715.1613855"},{"key":"ref47","first-page":"345","article-title":"Towards accurate binary convolutional neural network","author":"lin","year":"2017","journal-title":"Advances in Neural IInformation Processing Systems"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1613\/jair.295"},{"key":"ref42","article-title":"Model extraction and active learning","volume":"abs 1811 2054","author":"chandrasekaran","year":"2018","journal-title":"ArXiv"},{"key":"ref24","article-title":"A framework for the extraction of deep neural networks by leveraging public data","volume":"abs 1905 9165","author":"pal","year":"2019","journal-title":"CoRR"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref23","first-page":"45","article-title":"Support vector machine active learning with applications to text classification","volume":"2","author":"tong","year":"2002","journal-title":"J Mach Learn Res"},{"key":"ref44","article-title":"PRADA: protecting against DNN model stealing attacks","volume":"abs 1805 2628","author":"juuti","year":"2018","journal-title":"CoRR"},{"key":"ref26","doi-asserted-by":"crossref","first-page":"200","DOI":"10.1007\/3-540-45418-7_17","article-title":"Electromagnetic analysis (ema): Measures and counter-measures for smart cards","author":"quisquater","year":"2001","journal-title":"Proceedings of the International Conference on Research in Smart Cards Smart Card Programming and Security ser E-SMART &#x2019;01"},{"key":"ref43","article-title":"Copycat cnn: Stealing knowledge by persuading confession with random non-labeled data","volume":"abs 1806 5476","author":"da silva","year":"2018","journal-title":"CoRR"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-44709-1_21"}],"event":{"name":"2020 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)","location":"San Jose, CA, USA","start":{"date-parts":[[2020,12,7]]},"end":{"date-parts":[[2020,12,11]]}},"container-title":["2020 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9300124\/9300255\/09300274.pdf?arnumber=9300274","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,27]],"date-time":"2022-06-27T15:36:59Z","timestamp":1656344219000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9300274\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,12,7]]},"references-count":47,"URL":"https:\/\/doi.org\/10.1109\/host45689.2020.9300274","relation":{},"subject":[],"published":{"date-parts":[[2020,12,7]]}}}