{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,7]],"date-time":"2026-03-07T18:57:37Z","timestamp":1772909857821,"version":"3.50.1"},"reference-count":40,"publisher":"IEEE","license":[{"start":{"date-parts":[[2021,12,12]],"date-time":"2021-12-12T00:00:00Z","timestamp":1639267200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,12,12]],"date-time":"2021-12-12T00:00:00Z","timestamp":1639267200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000028","name":"Semiconductor Research Corporation","doi-asserted-by":"publisher","award":["2964.001"],"award-info":[{"award-number":["2964.001"]}],"id":[{"id":"10.13039\/100000028","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1909854,2011236"],"award-info":[{"award-number":["1909854,2011236"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,12,12]]},"DOI":"10.1109\/host49136.2021.9702292","type":"proceedings-article","created":{"date-parts":[[2022,2,15]],"date-time":"2022-02-15T06:21:12Z","timestamp":1644906072000},"page":"1-12","source":"Crossref","is-referenced-by-count":8,"title":["Safeguarding the Intelligence of Neural Networks with Built-in Light-weight Integrity MArks (LIMA)"],"prefix":"10.1109","author":[{"given":"Fateme S.","family":"Hosseini","sequence":"first","affiliation":[{"name":"University of Delaware"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qi","family":"Liu","sequence":"additional","affiliation":[{"name":"Lehigh University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fanruo","family":"Meng","sequence":"additional","affiliation":[{"name":"University of Delaware"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chengmo","family":"Yang","sequence":"additional","affiliation":[{"name":"University of Delaware"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wujie","family":"Wen","sequence":"additional","affiliation":[{"name":"Lehigh University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2014","journal-title":"ArXiv Preprint"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3316781.3317934"},{"key":"ref32","first-page":"2003","article-title":"Cache telepathy: Leveraging shared resource attacks to learn dnn architectures","author":"yan","year":"0","journal-title":"29th USENIX Security Symposium (USENIX Security 20)"},{"key":"ref31","article-title":"Concurrent weight encoding-based detection for bit-flip attack on neural network acceler ators","author":"liu","year":"0","journal-title":"IEEE\/ACM International Conference on Computer-Aided Design (ICCAD) 2020"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218665"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref35","author":"krizhevsky","year":"0","journal-title":"Cifar-10 (canadian institute for advanced research)"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2016.7783721"},{"key":"ref10","article-title":"Ead: elastic-net attacks to deep neural networks via adversarial examples","author":"chen","year":"2017","journal-title":"ArXiv Preprint"},{"key":"ref11","first-page":"131","article-title":"Fault injection attack on deep neural network. in 2017 ieee","author":"liu","year":"0","journal-title":"ACM International Conference on Computer-Aided Design (ICCAD)"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3400302.3415680"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3278519"},{"key":"ref13","first-page":"497","article-title":"Terminal brain damage: Exposing the graceless degradation in deep neural networks under hardware fault attacks","author":"hong","year":"0","journal-title":"28th USENIX Security Symposium (USENIX Security 19)"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00130"},{"key":"ref15","first-page":"1463","article-title":"Deephammer: Depleting the intelligence of deep neural networks through targeted chain of bit flips","author":"yao","year":"0","journal-title":"29th USENIX Security Symposium (USENIX Security 20)"},{"key":"ref16","article-title":"T-bfa: Targeted bit-flip adversarial weight attack","author":"rakin","year":"2020","journal-title":"ArXiv Preprint"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2015.152"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218675"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00486"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.312"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO50266.2020.00014"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/IVS.2018.8500504"},{"key":"ref27","first-page":"385","article-title":"Twice: preventing row-hammering by exploiting time window coun ters","author":"lee","year":"0","journal-title":"Proceedings of the International Symposium on Computer Architecture (ISCA)"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref5","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"ArXiv Preprint"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01410"},{"key":"ref8","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2016","journal-title":"ArXiv Preprint"},{"key":"ref7","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"ArXiv Preprint"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1001\/jamanetworkopen.2020.0265"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1038\/s41591-020-0842-3"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3394885.3431519"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00089"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00031"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3061639.3062281"},{"key":"ref23","doi-asserted-by":"crossref","first-page":"361","DOI":"10.1145\/2678373.2665726","article-title":"Flipping bits in memory without accessing them: An experimental study of dram disturbance errors","volume":"42","author":"kim","year":"2014","journal-title":"ACM SIGARCH Computer Architecture News"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3316781.3317866"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2018.00057"}],"event":{"name":"2021 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)","location":"Tysons Corner, VA, USA","start":{"date-parts":[[2021,12,12]]},"end":{"date-parts":[[2021,12,15]]}},"container-title":["2021 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9702149\/9702266\/09702292.pdf?arnumber=9702292","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,16]],"date-time":"2022-05-16T20:44:34Z","timestamp":1652733874000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9702292\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,12]]},"references-count":40,"URL":"https:\/\/doi.org\/10.1109\/host49136.2021.9702292","relation":{},"subject":[],"published":{"date-parts":[[2021,12,12]]}}}