{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,21]],"date-time":"2026-02-21T18:21:10Z","timestamp":1771698070418,"version":"3.50.1"},"reference-count":83,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T00:00:00Z","timestamp":1680307200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T00:00:00Z","timestamp":1680307200000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T00:00:00Z","timestamp":1680307200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T00:00:00Z","timestamp":1680307200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["NSF-2106828"],"award-info":[{"award-number":["NSF-2106828"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["NSF-2106725"],"award-info":[{"award-number":["NSF-2106725"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000028","name":"Semiconductor Research Corporation","doi-asserted-by":"publisher","award":["GRC-CADT 3103.001"],"award-info":[{"award-number":["GRC-CADT 3103.001"]}],"id":[{"id":"10.13039\/100000028","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000028","name":"Semiconductor Research Corporation","doi-asserted-by":"publisher","award":["3104.001"],"award-info":[{"award-number":["3104.001"]}],"id":[{"id":"10.13039\/100000028","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Comput.-Aided Des. Integr. Circuits Syst."],"published-print":{"date-parts":[[2023,4]]},"DOI":"10.1109\/tcad.2022.3199172","type":"journal-article","created":{"date-parts":[[2022,8,15]],"date-time":"2022-08-15T19:54:28Z","timestamp":1660593268000},"page":"1171-1184","source":"Crossref","is-referenced-by-count":5,"title":["The Dark Side: Security and Reliability Concerns in Machine Learning for EDA"],"prefix":"10.1109","volume":"42","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4442-592X","authenticated-orcid":false,"given":"Zhiyao","family":"Xie","sequence":"first","affiliation":[{"name":"Department of Electronic and Computer Engineering, Hong Kong University of Science and Technology, Sai Kung, Hong Kong"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7187-5205","authenticated-orcid":false,"given":"Jingyu","family":"Pan","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Duke University, Durham, NC, USA"}]},{"given":"Chen-Chia","family":"Chang","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Duke University, Durham, NC, USA"}]},{"given":"Jiang","family":"Hu","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Duke University, Durham, NC, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1486-8412","authenticated-orcid":false,"given":"Yiran","family":"Chen","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Texas A&#x0026;M University, College Station, TX, USA"}]}],"member":"263","reference":[{"key":"ref13","first-page":"1","article-title":"Efficient and reliable high-level synthesis design space explorer for FPGAs","author":"liu","year":"2016","journal-title":"Proc Int Conf Field Program Logic Appl (FPL)"},{"key":"ref57","first-page":"601","article-title":"Stealing machine learning models via prediction APIs","author":"tram\u00e8r","year":"2016","journal-title":"Proc Usenix Security Symp"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/2463209.2488795"},{"key":"ref56","year":"2021","journal-title":"IC compiler II for physical implementation"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218643"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1145\/3489517.3530578"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3316781.3317884"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1038\/nature16961"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD45719.2019.8942164"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/3316781.3317930"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/FPL.2019.00069"},{"key":"ref55","year":"2021","journal-title":"Innovus Implementation System"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/FCCM.2018.00029"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2007.907232"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3352460.3358322"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3466752.3480064"},{"key":"ref19","first-page":"1","article-title":"LSOracle: A logic synthesis framework driven by artificial intelligence","author":"neto","year":"2019","journal-title":"Proc Int Conf Comput -Aided Des (ICCAD)"},{"key":"ref18","first-page":"1","article-title":"Developing synthesis flows without human knowledge","author":"yu","year":"2018","journal-title":"Proc Des Autom Conf (DAC)"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3400302.3415624"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.23919\/DATE48585.2020.9116330"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218757"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.3850\/9783981537079_0923"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218515"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD45719.2019.8942062"},{"key":"ref42","first-page":"1","article-title":"A learning-based recommender system for autotuning design flows of industrial high-performance processors","author":"kwon","year":"2019","journal-title":"Proc Des Autom Conf (DAC)"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2019.2939329"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/3400302.3415685"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/ASP-DAC47756.2020.9045201"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.23919\/DATE48585.2020.9116329"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3394885.3431571"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.23919\/DATE48585.2020.9116489"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2020.3033749"},{"key":"ref4","year":"2021","journal-title":"DSO ai AI-Driven Design Applications"},{"key":"ref3","article-title":"MLCAD: A survey of research in machine learning for CAD keynote paper","author":"rapp","year":"2021","journal-title":"IEEE Trans Comp -Aided Des"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3408288"},{"key":"ref5","year":"2021","journal-title":"Cadence Cerebrus intelligent chip explorer"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1016\/0169-7439(87)80084-9"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00929"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2018.2837078"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"ref80","first-page":"125","article-title":"Adversarial examples are not bugs, they are features","author":"ilyas","year":"2019","journal-title":"Proc Int Conf Adv Neural Inf Process Syst (NeurIPS)"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3400302.3415712"},{"key":"ref79","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2017","journal-title":"arXiv 1706 06083"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3394885.3431562"},{"key":"ref78","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"arXiv 1412 6572"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/2024724.2024914"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218582"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD45719.2019.8942110"},{"key":"ref75","first-page":"1","article-title":"Towards reverse-engineering black-box neural networks","author":"oh","year":"2018","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ASP-DAC47756.2020.9045574"},{"key":"ref74","first-page":"14774","article-title":"Deep leakage from gradients","volume":"32","author":"zhu","year":"2019","journal-title":"Proc Int Conf Adv Neural Inf Process Syst"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD45719.2019.8942063"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3400302.3415714"},{"key":"ref76","article-title":"A survey of privacy attacks in machine learning","author":"rigaki","year":"2020","journal-title":"arXiv 2007 07646"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3451179"},{"key":"ref1","year":"2020","journal-title":"As chip design costs skyrocket 3nm process node is in jeopardy"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3316781.3317838"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/775832.775907"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref70","first-page":"267","article-title":"The secret sharer: Evaluating and testing unintended memorization in neural networks","author":"carlini","year":"2019","journal-title":"Proc Usenix Security Symp"},{"key":"ref73","first-page":"448","article-title":"Batch normalization: Accelerating deep network training by reducing internal covariate shift","author":"ioffe","year":"2015","journal-title":"Proc Int Conf Mach Learn (ICML)"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00874"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2022.3149977"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1145\/2717764.2723572"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/SLIP.2015.7171706"},{"key":"ref67","author":"albrecht","year":"2005","journal-title":"IWLS 2005 Benchmarks"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.23919\/DATE.2019.8715126"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1038\/s41586-021-03544-w"},{"key":"ref69","year":"2018","journal-title":"Nangate 45nm open cell library"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ASP-DAC47756.2020.9045559"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1145\/3372780.3375560"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD51958.2021.9643483"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3316781.3317857"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/54.867894"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18074.2021.9586230"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/ISCAS.1989.100747"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3316781.3317876"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3240765.3240843"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3400302.3415662"},{"key":"ref60","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","author":"mcmahan","year":"2017","journal-title":"Proc Int Conf Artif Intell Stat"},{"key":"ref62","article-title":"ML-leaks: Model and data independent membership inference attacks and defenses on machine learning models","author":"salem","year":"2018","journal-title":"arXiv 1806 01246"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1145\/2783258.2783417"}],"container-title":["IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/43\/10077488\/9858101-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/43\/10077488\/09858101.pdf?arnumber=9858101","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,4,10]],"date-time":"2023-04-10T19:16:28Z","timestamp":1681154188000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9858101\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4]]},"references-count":83,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tcad.2022.3199172","relation":{},"ISSN":["0278-0070","1937-4151"],"issn-type":[{"value":"0278-0070","type":"print"},{"value":"1937-4151","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,4]]}}}