{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T10:07:52Z","timestamp":1781258872251,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":97,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,1,27]],"date-time":"2023-01-27T00:00:00Z","timestamp":1674777600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,1,27]]},"DOI":"10.1145\/3575693.3575738","type":"proceedings-article","created":{"date-parts":[[2023,1,30]],"date-time":"2023-01-30T22:56:55Z","timestamp":1675119415000},"page":"385-399","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["HuffDuff: Stealing Pruned DNNs from Sparse Accelerators"],"prefix":"10.1145","author":[{"given":"Dingqing","family":"Yang","sequence":"first","affiliation":[{"name":"University of British Columbia, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Prashant J.","family":"Nair","sequence":"additional","affiliation":[{"name":"University of British Columbia, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mieszko","family":"Lis","sequence":"additional","affiliation":[{"name":"University of British Columbia, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,1,30]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2018.00061"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2016.11"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2016.7783725"},{"key":"e_1_3_2_1_4_1","volume-title":"Proceedings of the 28th USENIX Conference on Security Symposium (SEC\u201919)","author":"Batina Lejla","year":"2019","unstructured":"Lejla Batina , Shivam Bhasin , Dirmanto Jap , and Stjepan Picek . 2019 . CSI NN: Reverse Engineering of Neural Network Architectures through Electromagnetic Side Channel . In Proceedings of the 28th USENIX Conference on Security Symposium (SEC\u201919) . USENIX Association, USA. 515\u2013532. isbn:978 1939133069 Lejla Batina, Shivam Bhasin, Dirmanto Jap, and Stjepan Picek. 2019. CSI NN: Reverse Engineering of Neural Network Architectures through Electromagnetic Side Channel. In Proceedings of the 28th USENIX Conference on Security Symposium (SEC\u201919). USENIX Association, USA. 515\u2013532. isbn:9781939133069"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3278519"},{"key":"e_1_3_2_1_6_1","unstructured":"Cerebras. 2021. Wafer-Scale Engine: The Largest Chip Ever Built. https:\/\/f.hubspotusercontent30.net\/hubfs\/8968533\/WSE-2%20Datasheet.pdf \t\t\t\t  Cerebras. 2021. Wafer-Scale Engine: The Largest Chip Ever Built. https:\/\/f.hubspotusercontent30.net\/hubfs\/8968533\/WSE-2%20Datasheet.pdf"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2541940.2541967"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2014.58"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2016.40"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/JETCAS.2019.2910232"},{"key":"e_1_3_2_1_11_1","first-page":"1","article-title":"Intel SGX Explained","volume":"2016","author":"Costan Victor","year":"2016","unstructured":"Victor Costan and Srinivas Devadas . 2016 . Intel SGX Explained .. IACR Cryptol. ePrint Arch. , 2016 , 86 (2016), 1 \u2013 118 . Victor Costan and Srinivas Devadas. 2016. Intel SGX Explained.. IACR Cryptol. ePrint Arch., 2016, 86 (2016), 1\u2013118.","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"e_1_3_2_1_12_1","volume-title":"AMD Memory Encryption \u2013 A White Paper. https:\/\/developer.amd.com\/wordpress\/media\/2013\/12\/AMD_Memory_Encryption_Whitepaper_v7-Public.pdf [Online","author":"David Kaplan Tom Woller","year":"2022","unstructured":"Tom Woller David Kaplan , Jeremy Powell . 2016. AMD Memory Encryption \u2013 A White Paper. https:\/\/developer.amd.com\/wordpress\/media\/2013\/12\/AMD_Memory_Encryption_Whitepaper_v7-Public.pdf [Online ; accessed 7- July - 2022 ] Tom Woller David Kaplan, Jeremy Powell. 2016. AMD Memory Encryption \u2013 A White Paper. https:\/\/developer.amd.com\/wordpress\/media\/2013\/12\/AMD_Memory_Encryption_Whitepaper_v7-Public.pdf [Online; accessed 7-July-2022]"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_1_14_1","volume-title":"CirCNN: Accelerating and Compressing Deep Neural Networks Using Block-Circulant Weight Matrices. In 2017 50th Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO). 395\u2013408","author":"Ding Caiwen","year":"2017","unstructured":"Caiwen Ding , Siyu Liao , Yanzhi Wang , Zhe Li , Ning Liu , Youwei Zhuo , Chao Wang , Xuehai Qian , Yu Bai , Geng Yuan , Xiaolong Ma , Yipeng Zhang , Jian Tang , Qinru Qiu , Xue Lin , and Bo Yuan . 2017 . CirCNN: Accelerating and Compressing Deep Neural Networks Using Block-Circulant Weight Matrices. In 2017 50th Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO). 395\u2013408 . Caiwen Ding, Siyu Liao, Yanzhi Wang, Zhe Li, Ning Liu, Youwei Zhuo, Chao Wang, Xuehai Qian, Yu Bai, Geng Yuan, Xiaolong Ma, Yipeng Zhang, Jian Tang, Qinru Qiu, Xue Lin, and Bo Yuan. 2017. CirCNN: Accelerating and Compressing Deep Neural Networks Using Block-Circulant Weight Matrices. In 2017 50th Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO). 395\u2013408."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2749469.2750389"},{"key":"e_1_3_2_1_16_1","volume-title":"A guide to convolution arithmetic for deep learning. CoRR, abs\/1603.07285","author":"Dumoulin Vincent","year":"2016","unstructured":"Vincent Dumoulin and Francesco Visin . 2016. A guide to convolution arithmetic for deep learning. CoRR, abs\/1603.07285 ( 2016 ), arXiv:1603.07285. arxiv:1603.07285 Vincent Dumoulin and Francesco Visin. 2016. A guide to convolution arithmetic for deep learning. CoRR, abs\/1603.07285 (2016), arXiv:1603.07285. arxiv:1603.07285"},{"key":"e_1_3_2_1_17_1","volume-title":"Trainable Neural Networks. In 7th International Conference on Learning Representations, ICLR 2019","author":"Frankle Jonathan","year":"2019","unstructured":"Jonathan Frankle and Michael Carbin . 2019 . The Lottery Ticket Hypothesis: Finding Sparse , Trainable Neural Networks. In 7th International Conference on Learning Representations, ICLR 2019 , New Orleans, LA, USA , May 6-9, 2019. OpenReview.net. https:\/\/openreview.net\/forum?id=rJl-b3RcF7 Jonathan Frankle and Michael Carbin. 2019. The Lottery Ticket Hypothesis: Finding Sparse, Trainable Neural Networks. In 7th International Conference on Learning Representations, ICLR 2019, New Orleans, LA, USA, May 6-9, 2019. OpenReview.net. https:\/\/openreview.net\/forum?id=rJl-b3RcF7"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304014"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/233551.233553"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3352460.3358291"},{"key":"e_1_3_2_1_21_1","volume-title":"Generative Adversarial Nets. In Advances in Neural Information Processing Systems 27: Annual Conference on Neural Information Processing Systems 2014","author":"Goodfellow Ian J.","year":"2014","unstructured":"Ian J. Goodfellow , Jean Pouget-Abadie , Mehdi Mirza , Bing Xu , David Warde-Farley , Sherjil Ozair , Aaron C. Courville , and Yoshua Bengio . 2014 . Generative Adversarial Nets. In Advances in Neural Information Processing Systems 27: Annual Conference on Neural Information Processing Systems 2014 , December 8-13 2014, Montreal, Quebec, Canada, Zoubin Ghahramani, Max Welling, Corinna Cortes, Neil D. Lawrence, and Kilian Q. Weinberger (Eds.). 2672\u20132680. https:\/\/proceedings.neurips.cc\/paper\/ 2014\/hash\/5ca3e9b122f61f8f06494c97b1afccf3-Abstract.html Ian J. Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron C. Courville, and Yoshua Bengio. 2014. Generative Adversarial Nets. In Advances in Neural Information Processing Systems 27: Annual Conference on Neural Information Processing Systems 2014, December 8-13 2014, Montreal, Quebec, Canada, Zoubin Ghahramani, Max Welling, Corinna Cortes, Neil D. Lawrence, and Kilian Q. Weinberger (Eds.). 2672\u20132680. https:\/\/proceedings.neurips.cc\/paper\/2014\/hash\/5ca3e9b122f61f8f06494c97b1afccf3-Abstract.html"},{"key":"e_1_3_2_1_22_1","volume-title":"3rd International Conference on Learning Representations, ICLR","author":"Goodfellow Ian J.","year":"2015","unstructured":"Ian J. Goodfellow , Jonathon Shlens , and Christian Szegedy . 2015. Explaining and Harnessing Adversarial Examples . In 3rd International Conference on Learning Representations, ICLR 2015 , San Diego, CA , USA, May 7-9, 2015, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds .). arxiv:1412.6572 Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds.). arxiv:1412.6572"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1111\/j.1538-4632.1983.tb00794.x"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1111\/j.1467-9787.1983.tb00996.x"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3317549.3319721"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1506409.1506429"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2016.30"},{"key":"e_1_3_2_1_28_1","volume-title":"Dally","author":"Han Song","year":"2016","unstructured":"Song Han , Huizi Mao , and William J . Dally . 2016 . Deep Compression : Compressing Deep Neural Network with Pruning, Trained Quantization and Huffman Coding. In 4th International Conference on Learning Representations, ICLR 2016, San Juan, Puerto Rico, May 2-4, 2016, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds .). arxiv:1510.00149 Song Han, Huizi Mao, and William J. Dally. 2016. Deep Compression: Compressing Deep Neural Network with Pruning, Trained Quantization and Huffman Coding. In 4th International Conference on Learning Representations, ICLR 2016, San Juan, Puerto Rico, May 2-4, 2016, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds.). arxiv:1510.00149"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3352460.3358275"},{"key":"e_1_3_2_1_31_1","volume-title":"Proceedings of the 28th USENIX Conference on Security Symposium (SEC\u201919)","author":"Hong Sanghyun","year":"2019","unstructured":"Sanghyun Hong , Pietro Frigo , Yi\u011fitcan Kaya , Cristiano Giuffrida , and Tudor Dumitra\u015f . 2019 . Terminal Brain Damage: Exposing the Graceless Degradation in Deep Neural Networks under Hardware Fault Attacks . In Proceedings of the 28th USENIX Conference on Security Symposium (SEC\u201919) . USENIX Association, USA. 497\u2013514. isbn:978 1939133069 Sanghyun Hong, Pietro Frigo, Yi\u011fitcan Kaya, Cristiano Giuffrida, and Tudor Dumitra\u015f. 2019. Terminal Brain Damage: Exposing the Graceless Degradation in Deep Neural Networks under Hardware Fault Attacks. In Proceedings of the 28th USENIX Conference on Security Symposium (SEC\u201919). USENIX Association, USA. 497\u2013514. isbn:9781939133069"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00745"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378460"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3489517.3530439"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/DAC.2018.8465773"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3352460.3358283"},{"key":"e_1_3_2_1_37_1","unstructured":"Andrew Huang. 2002. Hacking the Xbox: An Introduction to Reverse Engineering. \t\t\t\t  Andrew Huang. 2002. Hacking the Xbox: An Introduction to Reverse Engineering."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3352460.3358263"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2579668"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPEC.2019.8916519"},{"key":"e_1_3_2_1_41_1","volume-title":"Practical Handbook on Image Processing for Scientific and Technical Applications","author":"Jahne Bernd","unstructured":"Bernd Jahne . 2004. Practical Handbook on Image Processing for Scientific and Technical Applications . CRC Press . Bernd Jahne. 2004. Practical Handbook on Image Processing for Scientific and Technical Applications. CRC Press."},{"key":"e_1_3_2_1_42_1","unstructured":"JEDEC Standard. 2015. Lpw Power Double Data Rate 3 SDRAM (LPDDR3). In JESD209-3C. \t\t\t\t  JEDEC Standard. 2015. Lpw Power Double Data Rate 3 SDRAM (LPDDR3). In JESD209-3C."},{"key":"e_1_3_2_1_43_1","unstructured":"JEDEC Standard. 2021. Addendum No. 1 to JESD209-4 Low Power Double Data Rate 4X (LPDDR4X). In JESD209-4-1A. \t\t\t\t  JEDEC Standard. 2021. Addendum No. 1 to JESD209-4 Low Power Double Data Rate 4X (LPDDR4X). In JESD209-4-1A."},{"key":"e_1_3_2_1_44_1","unstructured":"JEDEC Standard. 2021. Low Power Double Data Rate 4 (LPDDR4). In JESD209-4D. \t\t\t\t  JEDEC Standard. 2021. Low Power Double Data Rate 4 (LPDDR4). In JESD209-4D."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3079856.3080246"},{"key":"e_1_3_2_1_46_1","volume-title":"Sayeh Sharify, and Andreas Moshovos.","author":"Judd Patrick","year":"2017","unstructured":"Patrick Judd , Alberto Delmas Lascorz , Sayeh Sharify, and Andreas Moshovos. 2017 . Cnvlutin2: Ineffectual-Activation-and-Weight-Free Deep Neural Network Computing. CoRR , abs\/1705.00125 (2017), arXiv:1705.00125. arxiv:1705.00125 Patrick Judd, Alberto Delmas Lascorz, Sayeh Sharify, and Andreas Moshovos. 2017. Cnvlutin2: Ineffectual-Activation-and-Weight-Free Deep Neural Network Computing. CoRR, abs\/1705.00125 (2017), arXiv:1705.00125. arxiv:1705.00125"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSCC.2019.8662447"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/MDAT.2017.2741463"},{"key":"e_1_3_2_1_49_1","volume-title":"A Pytorch Repository for Adversarial Attacks. CoRR, abs\/2010.01950","author":"Kim Hoki","year":"2020","unstructured":"Hoki Kim . 2020. Torchattacks : A Pytorch Repository for Adversarial Attacks. CoRR, abs\/2010.01950 ( 2020 ), arXiv:2010.01950. arxiv:2010.01950 Hoki Kim. 2020. Torchattacks : A Pytorch Repository for Adversarial Attacks. CoRR, abs\/2010.01950 (2020), arXiv:2010.01950. arxiv:2010.01950"},{"key":"e_1_3_2_1_50_1","volume-title":"Learning Multiple Layers of Features from Tiny Images. Master\u2019s thesis","author":"Krizhevsky Alex","unstructured":"Alex Krizhevsky . 2009. Learning Multiple Layers of Features from Tiny Images. Master\u2019s thesis . University of Toronto . Alex Krizhevsky. 2009. Learning Multiple Layers of Features from Tiny Images. Master\u2019s thesis. University of Toronto."},{"key":"e_1_3_2_1_51_1","volume-title":"Hinton","author":"Krizhevsky Alex","year":"2012","unstructured":"Alex Krizhevsky , Ilya Sutskever , and Geoffrey E . Hinton . 2012 . ImageNet Classification with Deep Convolutional Neural Networks. In Advances in Neural Information Processing Systems 25: 26th Annual Conference on Neural Information Processing Systems 2012. Proceedings of a meeting held December 3-6, 2012, Lake Tahoe, Nevada, United States, Peter L. Bartlett, Fernando C. N. Pereira, Christopher J. C. Burges, L\u00e9on Bottou, and Kilian Q. Weinberger (Eds .). 1106\u20131114. https:\/\/proceedings.neurips.cc\/paper\/2012\/hash\/c399862d3b9d6b76c8436e924a68c45b-Abstract.html Alex Krizhevsky, Ilya Sutskever, and Geoffrey E. Hinton. 2012. ImageNet Classification with Deep Convolutional Neural Networks. In Advances in Neural Information Processing Systems 25: 26th Annual Conference on Neural Information Processing Systems 2012. Proceedings of a meeting held December 3-6, 2012, Lake Tahoe, Nevada, United States, Peter L. Bartlett, Fernando C. N. Pereira, Christopher J. C. Burges, L\u00e9on Bottou, and Kilian Q. Weinberger (Eds.). 1106\u20131114. https:\/\/proceedings.neurips.cc\/paper\/2012\/hash\/c399862d3b9d6b76c8436e924a68c45b-Abstract.html"},{"key":"e_1_3_2_1_52_1","volume-title":"5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24-26, 2017, Workshop Track Proceedings. OpenReview.net. https:\/\/openreview.net\/forum?id=HJGU3Rodl","author":"Kurakin Alexey","year":"2017","unstructured":"Alexey Kurakin , Ian J. Goodfellow , and Samy Bengio . 2017 . Adversarial examples in the physical world . In 5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24-26, 2017, Workshop Track Proceedings. OpenReview.net. https:\/\/openreview.net\/forum?id=HJGU3Rodl Alexey Kurakin, Ian J. Goodfellow, and Samy Bengio. 2017. Adversarial examples in the physical world. In 5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24-26, 2017, Workshop Track Proceedings. OpenReview.net. https:\/\/openreview.net\/forum?id=HJGU3Rodl"},{"key":"e_1_3_2_1_53_1","volume-title":"Stitch-X: An Accelerator Architecture for Exploiting Unstructured Sparsity in Deep Neural Networks. In SysML Conference. 120","author":"Lee Ching-En","year":"2018","unstructured":"Ching-En Lee , Yakun Sophia Shao , Jie-Fang Zhang , Angshuman Parashar , Joel Emer , Stephen W Keckler , and Zhengya Zhang . 2018 . Stitch-X: An Accelerator Architecture for Exploiting Unstructured Sparsity in Deep Neural Networks. In SysML Conference. 120 . Ching-En Lee, Yakun Sophia Shao, Jie-Fang Zhang, Angshuman Parashar, Joel Emer, Stephen W Keckler, and Zhengya Zhang. 2018. Stitch-X: An Accelerator Architecture for Exploiting Unstructured Sparsity in Deep Neural Networks. In SysML Conference. 120."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA53966.2022.00025"},{"key":"e_1_3_2_1_55_1","volume-title":"Michael Sullivan, Timothy Tsai, Karthik Pattabiraman, Joel Emer, and Stephen W. Keckler.","author":"Li Guanpeng","year":"2017","unstructured":"Guanpeng Li , Siva Kumar Sastry Hari , Michael Sullivan, Timothy Tsai, Karthik Pattabiraman, Joel Emer, and Stephen W. Keckler. 2017 . Understanding Error Propagation in Deep Learning Neural Network (DNN) Accelerators and Applications. In SC17: International Conference for High Performance Computing, Networking, Storage and Analysis . 1\u201312. Guanpeng Li, Siva Kumar Sastry Hari, Michael Sullivan, Timothy Tsai, Karthik Pattabiraman, Joel Emer, and Stephen W. Keckler. 2017. Understanding Error Propagation in Deep Learning Neural Network (DNN) Accelerators and Applications. In SC17: International Conference for High Performance Computing, Networking, Storage and Analysis. 1\u201312."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2019.2924215"},{"key":"e_1_3_2_1_57_1","unstructured":"Tailin Liang Lei Wang Shaobo Shi and John Glossner. 2018. Dynamic runtime feature map pruning. arXiv preprint arXiv:1812.09922. \t\t\t\t  Tailin Liang Lei Wang Shaobo Shi and John Glossner. 2018. Dynamic runtime feature map pruning. arXiv preprint arXiv:1812.09922."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/HCS55958.2022.9895479"},{"key":"e_1_3_2_1_59_1","volume-title":"5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24-26, 2017, Conference Track Proceedings. OpenReview.net. https:\/\/openreview.net\/forum?id=Sys6GJqxl","author":"Liu Yanpei","year":"2017","unstructured":"Yanpei Liu , Xinyun Chen , Chang Liu , and Dawn Song . 2017 . Delving into Transferable Adversarial Examples and Black-box Attacks . In 5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24-26, 2017, Conference Track Proceedings. OpenReview.net. https:\/\/openreview.net\/forum?id=Sys6GJqxl Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song. 2017. Delving into Transferable Adversarial Examples and Black-box Attacks. In 5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24-26, 2017, Conference Track Proceedings. OpenReview.net. https:\/\/openreview.net\/forum?id=Sys6GJqxl"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASAP49362.2020.00042"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/1873951.1874254"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243831"},{"key":"e_1_3_2_1_63_1","unstructured":"NVIDIA. 2017. NVIDIA Deep Learning Accelerator (NVDLA). http:\/\/nvdla.org\/ \t\t\t\t  NVIDIA. 2017. NVIDIA Deep Learning Accelerator (NVDLA). http:\/\/nvdla.org\/"},{"key":"e_1_3_2_1_64_1","unstructured":"NVIDIA. 2020. NVIDIA A100 Tensor Core GPU Architecture. https:\/\/images.nvidia.com\/aem-dam\/en-zz\/Solutions\/data-center\/nvidia-ampere-architecture-whitepaper.pdf \t\t\t\t  NVIDIA. 2020. NVIDIA A100 Tensor Core GPU Architecture. https:\/\/images.nvidia.com\/aem-dam\/en-zz\/Solutions\/data-center\/nvidia-ampere-architecture-whitepaper.pdf"},{"key":"e_1_3_2_1_65_1","volume-title":"6th International Conference on Learning Representations, ICLR","author":"Oh Seong Joon","year":"2018","unstructured":"Seong Joon Oh , Max Augustin , Mario Fritz , and Bernt Schiele . 2018. Towards Reverse-Engineering Black-Box Neural Networks . In 6th International Conference on Learning Representations, ICLR 2018 , Vancouver, BC , Canada, April 30 - May 3, 2018, Conference Track Proceedings. OpenReview .net. https:\/\/openreview.net\/forum?id=BydjJte0- Seong Joon Oh, Max Augustin, Mario Fritz, and Bernt Schiele. 2018. Towards Reverse-Engineering Black-Box Neural Networks. In 6th International Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada, April 30 - May 3, 2018, Conference Track Proceedings. OpenReview.net. https:\/\/openreview.net\/forum?id=BydjJte0-"},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447818.3460378"},{"key":"e_1_3_2_1_67_1","unstructured":"OpenAI. 2019. Better Language Models and Their Implications. https:\/\/openai.com\/blog\/better-language-models\/ \t\t\t\t  OpenAI. 2019. Better Language Models and Their Implications. https:\/\/openai.com\/blog\/better-language-models\/"},{"key":"e_1_3_2_1_68_1","unstructured":"OpenAI. 2019. GPT-2: 1.5B Release. https:\/\/openai.com\/blog\/gpt-2-1-5b-release\/ \t\t\t\t  OpenAI. 2019. GPT-2: 1.5B Release. https:\/\/openai.com\/blog\/gpt-2-1-5b-release\/"},{"key":"e_1_3_2_1_69_1","unstructured":"OpenAI. 2019. GPT-2: 6-Month Follow-Up. https:\/\/openai.com\/blog\/gpt-2-6-month-follow-up\/ \t\t\t\t  OpenAI. 2019. GPT-2: 6-Month Follow-Up. https:\/\/openai.com\/blog\/gpt-2-6-month-follow-up\/"},{"key":"e_1_3_2_1_70_1","unstructured":"OpenAI. 2020. OpenAI API. https:\/\/openai.com\/blog\/openai-api\/ \t\t\t\t  OpenAI. 2020. OpenAI API. https:\/\/openai.com\/blog\/openai-api\/"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/3079856.3080254"},{"key":"e_1_3_2_1_73_1","volume-title":"High-Performance Deep Learning Library. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019","author":"Paszke Adam","year":"2019","unstructured":"Adam Paszke , Sam Gross , Francisco Massa , Adam Lerer , James Bradbury , Gregory Chanan , Trevor Killeen , Zeming Lin , Natalia Gimelshein , Luca Antiga , Alban Desmaison , Andreas K\u00f6pf , Edward Z. Yang , Zachary DeVito , Martin Raison , Alykhan Tejani , Sasank Chilamkurthy , Benoit Steiner , Lu Fang , Junjie Bai , and Soumith Chintala . 2019 . PyTorch: An Imperative Style , High-Performance Deep Learning Library. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019 , NeurIPS 2019, December 8-14, 2019, Vancouver, BC, Canada, Hanna M. Wallach, Hugo Larochelle, Alina Beygelzimer, Florence d\u2019Alch\u00e9-Buc, Emily B. Fox, and Roman Garnett (Eds.). 8024\u20138035. https:\/\/proceedings.neurips.cc\/paper\/2019\/hash\/bdbca288fee7f92f2bfa9f7012727740-Abstract.html Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, Alban Desmaison, Andreas K\u00f6pf, Edward Z. Yang, Zachary DeVito, Martin Raison, Alykhan Tejani, Sasank Chilamkurthy, Benoit Steiner, Lu Fang, Junjie Bai, and Soumith Chintala. 2019. PyTorch: An Imperative Style, High-Performance Deep Learning Library. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019, December 8-14, 2019, Vancouver, BC, Canada, Hanna M. Wallach, Hugo Larochelle, Alina Beygelzimer, Florence d\u2019Alch\u00e9-Buc, Emily B. Fox, and Roman Garnett (Eds.). 8024\u20138035. https:\/\/proceedings.neurips.cc\/paper\/2019\/hash\/bdbca288fee7f92f2bfa9f7012727740-Abstract.html"},{"key":"e_1_3_2_1_74_1","volume-title":"Surface Mount Technology: Principles and Practice","author":"Prasad Ray","unstructured":"Ray Prasad . 2013. Surface Mount Technology: Principles and Practice . Springer Science & Business Media . Ray Prasad. 2013. Surface Mount Technology: Principles and Practice. Springer Science & Business Media."},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00130"},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24574-4_28"},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/73560.73562"},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00474"},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01428"},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_81_1","volume-title":"Sarangi","author":"Shrivastava Nivedita","year":"2022","unstructured":"Nivedita Shrivastava and Smruti R . Sarangi . 2022 . Seculator : A Fast and Secure Neural Processing Unit. CoRR , abs\/2204.08951 (2022), https:\/\/doi.org\/10.48550\/arXiv.2204.08951 arXiv:2204.08951. 10.48550\/arXiv.2204.08951 Nivedita Shrivastava and Smruti R. Sarangi. 2022. Seculator: A Fast and Secure Neural Processing Unit. CoRR, abs\/2204.08951 (2022), https:\/\/doi.org\/10.48550\/arXiv.2204.08951 arXiv:2204.08951."},{"key":"e_1_3_2_1_82_1","volume-title":"3rd International Conference on Learning Representations, ICLR","author":"Simonyan Karen","year":"2015","unstructured":"Karen Simonyan and Andrew Zisserman . 2015. Very Deep Convolutional Networks for Large-Scale Image Recognition . In 3rd International Conference on Learning Representations, ICLR 2015 , San Diego, CA , USA, May 7-9, 2015, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds .). arxiv:1409.1556 Karen Simonyan and Andrew Zisserman. 2015. Very Deep Convolutional Networks for Large-Scale Image Recognition. In 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds.). arxiv:1409.1556"},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2018.00068"},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSD.2018.00070"},{"key":"e_1_3_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1109\/RTAS54340.2022.00032"},{"key":"e_1_3_2_1_86_1","unstructured":"Keysight Technologies. 2014. W2637A W2638A and W2639A LPDDR BGA Probes for Logic Analyzers and Oscilloscopes. https:\/\/www.keysight.com\/us\/en\/assets\/7018-02123\/data-sheets\/5990-3892.pdf \t\t\t\t  Keysight Technologies. 2014. W2637A W2638A and W2639A LPDDR BGA Probes for Logic Analyzers and Oscilloscopes. https:\/\/www.keysight.com\/us\/en\/assets\/7018-02123\/data-sheets\/5990-3892.pdf"},{"key":"e_1_3_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"e_1_3_2_1_88_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-5906-5_511"},{"key":"e_1_3_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48063.2020.00031"},{"key":"e_1_3_2_1_90_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD51958.2021.9643512"},{"key":"e_1_3_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCSII.2020.2973007"},{"key":"e_1_3_2_1_92_1","volume-title":"Proceedings of the 29th USENIX Conference on Security Symposium (SEC\u201920)","author":"Yan Mengjia","year":"2020","unstructured":"Mengjia Yan , Christopher W. Fletcher , and Josep Torrellas . 2020 . Cache Telepathy: Leveraging Shared Resource Attacks to Learn DNN Architectures . In Proceedings of the 29th USENIX Conference on Security Symposium (SEC\u201920) . USENIX Association, USA. Article 113, 18 pages. isbn:978-1-939133-17-5 Mengjia Yan, Christopher W. Fletcher, and Josep Torrellas. 2020. Cache Telepathy: Leveraging Shared Resource Attacks to Learn DNN Architectures. In Proceedings of the 29th USENIX Conference on Security Symposium (SEC\u201920). USENIX Association, USA. Article 113, 18 pages. isbn:978-1-939133-17-5"},{"key":"e_1_3_2_1_93_1","doi-asserted-by":"publisher","DOI":"10.1109\/VLSIC.2018.8502404"},{"key":"e_1_3_2_1_94_1","unstructured":"ZeroPoint. 2022. ZeroPoint Technologies Signs Memory Encryption Contract. https:\/\/www.zeropoint-tech.com\/news\/zeropoint-technologies-signs-memory-encryption-contract \t\t\t\t  ZeroPoint. 2022. ZeroPoint Technologies Signs Memory Encryption Contract. https:\/\/www.zeropoint-tech.com\/news\/zeropoint-technologies-signs-memory-encryption-contract"},{"key":"e_1_3_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.23919\/VLSIC.2019.8778193"},{"key":"e_1_3_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2016.7783723"},{"key":"e_1_3_2_1_97_1","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18074.2021.9586199"}],"event":{"name":"ASPLOS '23: 28th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2","location":"Vancouver BC Canada","acronym":"ASPLOS '23","sponsor":["SIGARCH ACM Special Interest Group on Computer Architecture","SIGOPS ACM Special Interest Group on Operating Systems","SIGPLAN ACM Special Interest Group on Programming Languages"]},"container-title":["Proceedings of the 28th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3575693.3575738","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3575693.3575738","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:51:20Z","timestamp":1750182680000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3575693.3575738"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,1,27]]},"references-count":97,"alternative-id":["10.1145\/3575693.3575738","10.1145\/3575693"],"URL":"https:\/\/doi.org\/10.1145\/3575693.3575738","relation":{},"subject":[],"published":{"date-parts":[[2023,1,27]]},"assertion":[{"value":"2023-01-30","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}