{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,7]],"date-time":"2026-02-07T19:07:33Z","timestamp":1770491253568,"version":"3.49.0"},"reference-count":41,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"11","license":[{"start":{"date-parts":[[2020,11,1]],"date-time":"2020-11-01T00:00:00Z","timestamp":1604188800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2020,11,1]],"date-time":"2020-11-01T00:00:00Z","timestamp":1604188800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,11,1]],"date-time":"2020-11-01T00:00:00Z","timestamp":1604188800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Center for Brain Inspired Computing (C-BRIC), one of six centers in JUMP"},{"DOI":"10.13039\/100000028","name":"Semiconductor Research Corporation Program, sponsored by DARPA","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000028","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Comput.-Aided Des. Integr. Circuits Syst."],"published-print":{"date-parts":[[2020,11]]},"DOI":"10.1109\/tcad.2020.3013077","type":"journal-article","created":{"date-parts":[[2020,10,2]],"date-time":"2020-10-02T20:24:18Z","timestamp":1601670258000},"page":"4129-4141","source":"Crossref","is-referenced-by-count":10,"title":["Sparsity Turns Adversarial: Energy and Latency Attacks on Deep Neural Networks"],"prefix":"10.1109","volume":"39","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2958-1377","authenticated-orcid":false,"given":"Sarada","family":"Krithivasan","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0080-2882","authenticated-orcid":false,"given":"Sanchari","family":"Sen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anand","family":"Raghunathan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","author":"lecun","year":"2010","journal-title":"MNIST Handwritten Digit Database"},{"key":"ref38","author":"pang","year":"2019","journal-title":"Improving adversarial robustness via promoting ensemble diversity"},{"key":"ref33","author":"guo","year":"2017","journal-title":"Countering adversarial images using input transformations"},{"key":"ref32","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"Proc Int Conf Learn Represent (ICLR)ICLR"},{"key":"ref31","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"Proc Int Conf Learn Represent (ICLR)ICLR"},{"key":"ref30","author":"liu","year":"2016","journal-title":"Delving into transferable adversarial examples and black-box attacks"},{"key":"ref37","first-page":"1","article-title":"EMPIR: Ensembles of mixed precision deep networks for increased robustness against adversarial attacks","author":"sen","year":"2020","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2939352"},{"key":"ref35","author":"samangouei","year":"2018","journal-title":"Defense-GAN Protecting classifiers against adversarial attacks using generative models"},{"key":"ref34","author":"abadi","year":"2015","journal-title":"TensorFlow Large-Scale Machine Learning on Heterogeneous Systems"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3352460.3358275"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3352460.3358269"},{"key":"ref12","author":"simonyan","year":"2014","journal-title":"Very Deep Convolutional Networks for Large-scale Image Recognition"},{"key":"ref13","year":"2019","journal-title":"Self Driving Car Reaction Time"},{"key":"ref14","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009"},{"key":"ref15","author":"kurakin","year":"2016","journal-title":"Adversarial examples in the physical world"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.220"},{"key":"ref17","author":"brown","year":"2020","journal-title":"Language models are few-shot learners"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref19","author":"dong","year":"2017","journal-title":"Discovering adversarial examples with momentum"},{"key":"ref28","author":"palossi","year":"2018","journal-title":"Ultra Low Power Deep-Learning-powered Autonomous Nano Drones"},{"key":"ref4","article-title":"Deep compression: Compressing deep neural networks with pruning, trained quantization and Huffman coding","author":"han","year":"2016","journal-title":"Proc 4th Int Conf Learn Represent (ICLR)"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD.2017.8203770"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2205597"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3007787.3001138"},{"key":"ref29","first-page":"1139","article-title":"On the importance of initialization and momentum in deep learning","author":"sutskever","year":"2013","journal-title":"Proc ICML"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3140659.3080254"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2018.2879434"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/JETCAS.2019.2910232"},{"key":"ref2","author":"hannun","year":"2014","journal-title":"Deep speech Scaling up end-to-end speech recognition"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3352460.3358291"},{"key":"ref1","author":"he","year":"2015","journal-title":"Deep residual learning for image recognition"},{"key":"ref20","author":"chen","year":"2017","journal-title":"Proc 10th ACM Workshop Artif Intell Secur (AISEC)"},{"key":"ref22","author":"papernot","year":"2016","journal-title":"Practical Black-Box Attacks against Deep Learning Systems using Adversarial Examples"},{"key":"ref21","author":"guo","year":"2019","journal-title":"Simple black-box adversarial attacks"},{"key":"ref24","author":"shokri","year":"2016","journal-title":"Membership inference attacks against machine learning models"},{"key":"ref41","first-page":"1","article-title":"Striving for simplicity: The all convolutional net","author":"springenberg","year":"2015","journal-title":"Proc ICLR"},{"key":"ref23","author":"duddu","year":"2018","journal-title":"Stealing Neural Networks via Timing Side Channels"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/HPEC.2019.8916519"},{"key":"ref25","author":"rakin","year":"2019","journal-title":"Bit-flip attack Crushing neural network withprogressive bit search"}],"container-title":["IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/43\/9244237\/09211473.pdf?arnumber=9211473","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,27]],"date-time":"2022-04-27T14:03:24Z","timestamp":1651068204000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9211473\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,11]]},"references-count":41,"journal-issue":{"issue":"11"},"URL":"https:\/\/doi.org\/10.1109\/tcad.2020.3013077","relation":{},"ISSN":["0278-0070","1937-4151"],"issn-type":[{"value":"0278-0070","type":"print"},{"value":"1937-4151","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,11]]}}}