{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T03:28:04Z","timestamp":1783567684744,"version":"3.55.0"},"reference-count":44,"publisher":"IEEE","license":[{"start":{"date-parts":[[2021,11,8]],"date-time":"2021-11-08T00:00:00Z","timestamp":1636329600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,11,8]],"date-time":"2021-11-08T00:00:00Z","timestamp":1636329600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,11,8]],"date-time":"2021-11-08T00:00:00Z","timestamp":1636329600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,11,8]]},"DOI":"10.1109\/nanoarch53687.2021.9642246","type":"proceedings-article","created":{"date-parts":[[2021,12,16]],"date-time":"2021-12-16T20:45:19Z","timestamp":1639687519000},"page":"1-6","source":"Crossref","is-referenced-by-count":3,"title":["Deep Neural Network Security From a Hardware Perspective"],"prefix":"10.1109","author":[{"given":"Tong","family":"Zhou","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuheng","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shijin","family":"Duan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yukui","family":"Luo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaolin","family":"Xu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref39","article-title":"Dissecting the polaris architecture","year":"2016","journal-title":"A Technical Report"},{"key":"ref38","first-page":"71","article-title":"Exploiting the dram rowhammer bug to gain kernel privileges","volume":"15","author":"seaborn","year":"2015","journal-title":"Black Hat"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-81645-2_7"},{"key":"ref32","first-page":"515","article-title":"{CSI}{NN}: Reverse engineering of neural network architectures through electromagnetic side channel","author":"batina","year":"2019","journal-title":"28th USENIX Security Symposium ( USENIX Security 19)"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3278519"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00130"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978406"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00089"},{"key":"ref35","year":"2019","journal-title":"CUDA Toolkit Documentation CUPTI"},{"key":"ref34","article-title":"Teledyne lecroy. summit analyzer","year":"2012"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/FCCM51124.2021.00037"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218690"},{"key":"ref11","article-title":"Deephammer: Depleting the intelligence of deep neural networks through targeted chain of bit flips","author":"yao","year":"2020","journal-title":"29th USENIX Security Symposium USENIX Security 20"},{"key":"ref12","article-title":"Deep-dup: An adversarial weight duplication attack framework to crush deep neural network in multi-tenant fpga","author":"rakin","year":"2020"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref15","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013"},{"key":"ref16","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref18","first-page":"2574","article-title":"Deepfool: a simple and accurate method to fool deep neural networks","author":"moosavi-dezfooli","year":"2016","journal-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/2678373.2665726"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2016.7783721"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1007\/s10916-018-1088-1"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/FCCM.2018.00023"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD.2017.8203770"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/2847263.2847265"},{"key":"ref8","first-page":"557","article-title":"Snooping attacks on deep reinforcement learning","author":"inkawhich","year":"2020","journal-title":"Proc of International Conference on Autonomous Agents and Multiagent Systems"},{"key":"ref7","article-title":"Hermes attack: Steal {DNN} models with lossless inference accuracy","author":"zhu","year":"2021","journal-title":"30th USENIX Security Symposium ( USENIX Security 21)"},{"key":"ref2","article-title":"End to end learning for self-driving cars","author":"bojarski","year":"2016"},{"key":"ref1","article-title":"Deepid3: Face recognition with very deep neural networks","author":"sun","year":"2015"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48063.2020.00031"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref22","first-page":"601","article-title":"Stealing machine learning models via prediction apis","author":"tram\u00e8r","year":"2016","journal-title":"25th USENIX Security Symposium ( USENIX Security 16)"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24178"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/HOST45689.2020.9300274"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00038"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/DSN-S52858.2021.00035"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/THS.2017.7943475"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD50377.2020.00097"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2015.84"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18074.2021.9586262"},{"key":"ref25","article-title":"Dnn model extraction attacks using prediction interfaces","author":"dmitrenko","year":"2018"}],"event":{"name":"2021 IEEE\/ACM International Symposium on Nanoscale Architectures (NANOARCH)","location":"AB, Canada","start":{"date-parts":[[2021,11,8]]},"end":{"date-parts":[[2021,11,10]]}},"container-title":["2021 IEEE\/ACM International Symposium on Nanoscale Architectures (NANOARCH)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9642231\/9642232\/09642246.pdf?arnumber=9642246","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,10]],"date-time":"2022-05-10T16:58:08Z","timestamp":1652201888000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9642246\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,8]]},"references-count":44,"URL":"https:\/\/doi.org\/10.1109\/nanoarch53687.2021.9642246","relation":{},"subject":[],"published":{"date-parts":[[2021,11,8]]}}}