{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,19]],"date-time":"2025-03-19T13:47:00Z","timestamp":1742392020197,"version":"3.28.0"},"reference-count":40,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5,1]]},"DOI":"10.1109\/host55118.2023.10133375","type":"proceedings-article","created":{"date-parts":[[2023,5,25]],"date-time":"2023-05-25T13:29:36Z","timestamp":1685021376000},"page":"238-248","source":"Crossref","is-referenced-by-count":2,"title":["Bits to BNNs: Reconstructing FPGA ML-IP with Joint Bitstream and Side-Channel Analysis"],"prefix":"10.1109","author":[{"given":"Brooks","family":"Olney","sequence":"first","affiliation":[{"name":"University of South Florida,Department of Computer Science and Engineering"}]},{"given":"Robert","family":"Karam","sequence":"additional","affiliation":[{"name":"University of South Florida,Department of Computer Science and Engineering"}]}],"member":"263","reference":[{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/HOST45689.2020.9300276"},{"key":"ref35","first-page":"515","article-title":"CSI NN: Reverse engi- neering of neural network architectures through electromagnetic side channel","author":"batina","year":"2019","journal-title":"28th USENIX Security Symposium (USENIX Security 19)"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/HOST45689.2020.9300274"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3400302.3415649"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/FCCM53951.2022.9786107"},{"key":"ref37","first-page":"1803","article-title":"The unpatchable silicon: A full break of the bitstream encryption of xilinx 7-series FPGAs","author":"ender","year":"2020","journal-title":"Proceedings of the 29th USENIX Conference on Security Symposium ser SEC'20"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3106169"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48405-1_25"},{"journal-title":"Xilinx\/brevitas","year":"2021","author":"pappalardo","key":"ref31"},{"journal-title":"Open neural network exchange","year":"0","key":"ref30"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ISCAS45731.2020.9180580"},{"key":"ref33","first-page":"1","article-title":"Reverse engineering convolutional neural networks through side-channel information leaks","author":"hua","year":"2018","journal-title":"Proceedings of the 55th Annual Design Automation Conference"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/FCCM.2019.00059"},{"journal-title":"Qonnx Representing arbitrary- precision quantized neural networks","year":"2022","author":"pappalardo","key":"ref32"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2020.113816"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/JBHI.2016.2636665"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2014.2331672"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10175-0_17"},{"journal-title":"7 Series FPGAs Configuration User Guide (ug470)","year":"2022","key":"ref16"},{"journal-title":"7 Series FPGA and Zynq-7000 SoC Libraries Guide (UG953)","year":"2021","key":"ref38"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.23919\/DATE48585.2020.9116222"},{"journal-title":"Project X-Ray","year":"0","key":"ref18"},{"key":"ref24","article-title":"Bi- narized neural networks","volume":"29","author":"hubara","year":"2016","journal-title":"Advances in neural information processing systems"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3287624.3288742"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.23919\/FPL.2017.8056823"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2017.09.046"},{"key":"ref20","article-title":"Interconnect-aware bitstream modification","author":"moraitis","year":"2020","journal-title":"Cryptology ePrint Archive"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/FPL.2012.6339165"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/1344671.1344729"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ASAP.2019.00-43"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3218603.3218615"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3431920.3439296"},{"key":"ref8","first-page":"601","article-title":"Stealing machine learning models via prediction APIs","author":"tramer","year":"2016","journal-title":"Proceedings of the 25th USENIX Conference on Security Symposium"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00028"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/2684746.2689060"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.2018.1700202"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3020078.3021744"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2890150"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/JETCAS.2021.3076151"}],"event":{"name":"2023 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)","start":{"date-parts":[[2023,5,1]]},"location":"San Jose, CA, USA","end":{"date-parts":[[2023,5,4]]}},"container-title":["2023 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10132842\/10132914\/10133375.pdf?arnumber=10133375","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,6,19]],"date-time":"2023-06-19T13:45:48Z","timestamp":1687182348000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10133375\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5,1]]},"references-count":40,"URL":"https:\/\/doi.org\/10.1109\/host55118.2023.10133375","relation":{},"subject":[],"published":{"date-parts":[[2023,5,1]]}}}