{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,19]],"date-time":"2026-06-19T02:35:43Z","timestamp":1781836543605,"version":"3.54.5"},"reference-count":33,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,26]],"date-time":"2025-10-26T00:00:00Z","timestamp":1761436800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,26]],"date-time":"2025-10-26T00:00:00Z","timestamp":1761436800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100008451","name":"Binghamton University","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100008451","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,26]]},"DOI":"10.1109\/iccad66269.2025.11240849","type":"proceedings-article","created":{"date-parts":[[2025,11,20]],"date-time":"2025-11-20T18:39:34Z","timestamp":1763663974000},"page":"1-8","source":"Crossref","is-referenced-by-count":1,"title":["Non-Negative AdderNet: Algorithm-Hardware Co-design for Lightweight Defense of Adversarial Bit-Flip Attacks"],"prefix":"10.1109","author":[{"given":"Yunxiang","family":"Zhang","sequence":"first","affiliation":[{"name":"Binghamton University,Binghamton,New York,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sabbir","family":"Ahmed","sequence":"additional","affiliation":[{"name":"Binghamton University,Binghamton,New York,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Abeer Matar A","family":"Almalky","sequence":"additional","affiliation":[{"name":"Binghamton University,Binghamton,New York,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Adnan Siraj","family":"Rakin","sequence":"additional","affiliation":[{"name":"Binghamton University,Binghamton,New York,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenfeng","family":"Zhao","sequence":"additional","affiliation":[{"name":"Binghamton University,Binghamton,New York,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.5555\/2999134.2999257"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2020.3048878"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298965"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00286"},{"key":"ref5","article-title":"Deep compression: Compressing deep neural networks with pruning, trained quantization and huffman coding","author":"Han","year":"2015"},{"key":"ref6","article-title":"Binarized neural networks: Training deep neural networks with weights and activations constrained to+ 1 or-1","author":"Courbariaux","year":"2016"},{"key":"ref7","article-title":"Binaryconnect: Training deep neural networks with binary weights during propagations","volume-title":"Advances in neural information processing systems","volume":"28","author":"Courbariaux"},{"key":"ref8","article-title":"Learning both weights and connections for efficient neural network","volume-title":"Advances in neural information processing systems","volume":"28","author":"Han"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00154"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00130"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01321"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833743"},{"key":"ref13","first-page":"497","article-title":"Terminal brain damage: Exposing the graceless degradation in deep neural networks under hardware fault attacks","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Hong"},{"key":"ref14","article-title":"Deephammer: Depleting the intelligence of deep neural networksthrough targeted chain of bit flips","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Yao"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00432"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3296408"},{"key":"ref17","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-031-78186-5_28","article-title":"What makes vision transformers robust towards bit-flip attack?","volume-title":"ICLR 2024 Workshop on Mathematical and Empirical Understanding of Foundation Models","author":"Zhou"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00762"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/2678373.2665726"},{"key":"ref20","first-page":"1","article-title":"Wsq-addernet: Efficient weight standardization based quantized addernet fpga accelerator design with high-density int8 dsp-lut co-packing optimization","volume-title":"Proceedings of the 41st IEEE\/ACM International Conference on Computer-Aided Design","author":"Zhang"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3649329.3658487"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3112932"},{"key":"ref23","first-page":"2003","article-title":"Cache telepathy: Leveraging shared resource attacks to learn dnn architectures","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Yan"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3579371.3589063"},{"key":"ref25","article-title":"Cifar-10 (canadian institute for advanced research)","author":"Krizhevsky","year":"2010"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref27","article-title":"Sgdr: Stochastic gradient descent with warm restarts","author":"Loshchilov","year":"2016"},{"key":"ref28","article-title":"Ra-bnn: Constructing robust & accurate binary neural network to simultaneously defend adversarial bit-flip attack and improve accuracy","author":"Rakin","year":"2021"},{"key":"ref29","article-title":"Towards deep learning models resistant to adversarial attacks","volume-title":"International Conference on Learning Representations","author":"Madry"},{"key":"ref30","article-title":"Aegis: Mitigating targeted bit-flip attacks against deep neural networks","author":"Wang","year":"2023"},{"key":"ref31","first-page":"6347","article-title":"{NeuroPots}: realtime proactive defense against {Bit-Flip} attacks in neural networks","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Liu"},{"key":"ref32","first-page":"1349","article-title":"Forget and rewire: Enhancing the resilience of transformer-based models against {Bit-Flip} attacks","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Nazari"},{"key":"ref33","article-title":"Towards stable and robust addernets","volume-title":"Advances in Neural Information Processing Systems","author":"Dong"}],"event":{"name":"2025 IEEE\/ACM International Conference On Computer Aided Design (ICCAD)","location":"Munich, Germany","start":{"date-parts":[[2025,10,26]]},"end":{"date-parts":[[2025,10,30]]}},"container-title":["2025 IEEE\/ACM International Conference On Computer Aided Design (ICCAD)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11240608\/11240621\/11240849.pdf?arnumber=11240849","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,21]],"date-time":"2025-11-21T05:45:17Z","timestamp":1763703917000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11240849\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,26]]},"references-count":33,"URL":"https:\/\/doi.org\/10.1109\/iccad66269.2025.11240849","relation":{},"subject":[],"published":{"date-parts":[[2025,10,26]]}}}