{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T14:59:04Z","timestamp":1784213944057,"version":"3.55.0"},"reference-count":46,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2023,11,15]],"date-time":"2023-11-15T00:00:00Z","timestamp":1700006400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National key research and development program of China","award":["2021YFB3100902"],"award-info":[{"award-number":["2021YFB3100902"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62072263"],"award-info":[{"award-number":["62072263"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["92067206"],"award-info":[{"award-number":["92067206"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Des. Autom. Electron. Syst."],"published-print":{"date-parts":[[2024,1,31]]},"abstract":"<jats:p>\n            Graphics Processing Units (GPU) are widely used as deep learning accelerators because of its high performance and low power consumption. Additionally, it remains secure against hardware-induced transient fault injection attacks, a classic type of attacks that have been developed on other computing platforms. In this work, we demonstrate that well-trained machine learning models are robust against hardware fault injection attacks when the faults are generated randomly. However, we discover that these models have components, which we refer to as sensitive targets, that are vulnerable to faults. By exploiting this vulnerability, we propose the\n            <jats:italic>Lightning<\/jats:italic>\n            attack, which precisely strikes the model\u2019s sensitive targets with hardware-induced transient faults based on the Dynamic Voltage and Frequency Scaling (DVFS). We design a sensitive targets search algorithm to find the most critical processing units of Deep Neural Network (DNN) models determining the inference results, and develop a genetic algorithm to automatically optimize the attack parameters for DVFS to induce faults. Experiments on three commodity Nvidia GPUs for four widely-used DNN models show that the proposed\n            <jats:italic>Lightning<\/jats:italic>\n            attack can reduce the inference accuracy by 69.1% on average for non-targeted attacks, and, more interestingly, achieve a success rate of 67.9% for targeted attacks.\n          <\/jats:p>","DOI":"10.1145\/3617893","type":"journal-article","created":{"date-parts":[[2023,9,20]],"date-time":"2023-09-20T12:27:06Z","timestamp":1695212826000},"page":"1-22","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["Lightning: Leveraging DVFS-induced Transient Fault Injection to Attack Deep Learning Accelerator of GPUs"],"prefix":"10.1145","volume":"29","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9948-8653","authenticated-orcid":false,"given":"Rihui","family":"Sun","sequence":"first","affiliation":[{"name":"Harbin Institute of Technology, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-4043-2119","authenticated-orcid":false,"given":"Pengfei","family":"Qiu","sequence":"additional","affiliation":[{"name":"Beijing University of Posts and Telecommunications, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2573-963X","authenticated-orcid":false,"given":"Yongqiang","family":"Lyu","sequence":"additional","affiliation":[{"name":"Tsinghua University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2980-9431","authenticated-orcid":false,"given":"Jian","family":"Dong","sequence":"additional","affiliation":[{"name":"Harbin Institute of Technology, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-0474-5030","authenticated-orcid":false,"given":"Haixia","family":"Wang","sequence":"additional","affiliation":[{"name":"Tsinghua University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5779-9026","authenticated-orcid":false,"given":"Dongsheng","family":"Wang","sequence":"additional","affiliation":[{"name":"Tsinghua University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6759-8949","authenticated-orcid":false,"given":"Gang","family":"Qu","sequence":"additional","affiliation":[{"name":"University of Maryland, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,11,15]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"crossref","first-page":"23","DOI":"10.1109\/FDTC.2009.30","volume-title":"2009 Workshop on Fault Diagnosis and Tolerance in Cryptography (FDTC)","author":"Barenghi Alessandro","year":"2009","unstructured":"Alessandro Barenghi, Guido Bertoni, Emanuele Parrinello, and Gerardo Pelosi. 2009. Low voltage fault attacks on the RSA cryptosystem. In 2009 Workshop on Fault Diagnosis and Tolerance in Cryptography (FDTC). IEEE, Lausanne, Switzerland, 23\u201331."},{"key":"e_1_3_2_3_2","doi-asserted-by":"crossref","first-page":"7","DOI":"10.1109\/HST.2010.5513121","volume-title":"2010 IEEE International Symposium on Hardware-Oriented Security and Trust (HOST)","author":"Barenghi Alessandro","year":"2010","unstructured":"Alessandro Barenghi, Guido M. Bertoni, Luca Breveglieri, Mauro Pellicioli, and Gerardo Pelosi. 2010. Low voltage fault attacks to AES. In 2010 IEEE International Symposium on Hardware-Oriented Security and Trust (HOST). IEEE, Anaheim, CA, USA, 7\u201312."},{"key":"e_1_3_2_4_2","doi-asserted-by":"crossref","first-page":"229","DOI":"10.1007\/978-3-319-10175-0_16","volume-title":"International Workshop on Constructive Side-channel Analysis and Secure Design","author":"Courbon Franck","year":"2014","unstructured":"Franck Courbon, Philippe Loubet-Moundi, Jacques J. A. Fournier, and Assia Tria. 2014. Adjusting laser injections for fully controlled faults. In International Workshop on Constructive Side-channel Analysis and Secure Design. Springer International Publishing, Cham, 229\u2013242."},{"key":"e_1_3_2_5_2","first-page":"613","volume-title":"14th USENIX Symposium on Networked Systems Design and Implementation (NSDI 17)","author":"Crankshaw Daniel","year":"2017","unstructured":"Daniel Crankshaw, Xin Wang, Guilio Zhou, Michael J. Franklin, Joseph E. Gonzalez, and Ion Stoica. 2017. Clipper: A low-latency online prediction serving system. In 14th USENIX Symposium on Networked Systems Design and Implementation (NSDI 17). USENIX Association, Boston, MA, 613\u2013627. https:\/\/www.usenix.org\/conference\/nsdi17\/technical-sessions\/presentation\/crankshaw"},{"key":"e_1_3_2_6_2","doi-asserted-by":"crossref","first-page":"7","DOI":"10.1109\/FDTC.2012.15","volume-title":"2012 Workshop on Fault Diagnosis and Tolerance in Cryptography","author":"Dehbaoui Amine","year":"2012","unstructured":"Amine Dehbaoui, Jean-Max Dutertre, Bruno Robisson, and Assia Tria. 2012. Electromagnetic transient faults injection on a hardware and a software implementations of AES. In 2012 Workshop on Fault Diagnosis and Tolerance in Cryptography. IEEE, Leuven, Belgium, 7\u201315."},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCSI.2013.2290845"},{"key":"e_1_3_2_8_2","first-page":"103","volume-title":"IFIP International Conference on Network and Parallel Computing","author":"Di Bang","year":"2016","unstructured":"Bang Di, Jianhua Sun, and Hao Chen. 2016. A study of overflow vulnerabilities on GPUs. In IFIP International Conference on Network and Parallel Computing. Springer International Publishing, Cham, 103\u2013115."},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-011-0022-y"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2017.7863729"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.vlsi.2019.11.006"},{"key":"e_1_3_2_12_2","doi-asserted-by":"crossref","first-page":"75","DOI":"10.1109\/PRDC47002.2019.00029","volume-title":"2019 IEEE 24th Pacific Rim International Symposium on Dependable Computing (PRDC)","author":"Gabor Ulrich Thomas","year":"2019","unstructured":"Ulrich Thomas Gabor, Daniel Ferdinand Siegert, and Olaf Spinczyk. 2019. High-accuracy software fault injection in source code with clang. In 2019 IEEE 24th Pacific Rim International Symposium on Dependable Computing (PRDC). IEEE, Kyoto, Japan, 75\u20137509."},{"key":"e_1_3_2_13_2","volume-title":"FPGA Accelerator Architecture for Q-learning and its Applications in Space Exploration Rovers","author":"Gankidi Pranay Reddy","year":"2016","unstructured":"Pranay Reddy Gankidi. 2016. FPGA Accelerator Architecture for Q-learning and its Applications in Space Exploration Rovers. Ph.D. Dissertation. Arizona State University."},{"key":"e_1_3_2_14_2","unstructured":"Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. (2015). arxiv:stat.ML\/1412.6572"},{"key":"e_1_3_2_15_2","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1007\/978-3-030-31756-0_3","volume-title":"Deep Learning: Concepts and Architectures","author":"Gordienko Yuri","year":"2020","unstructured":"Yuri Gordienko, Yuriy Kochura, Vlad Taran, Nikita Gordienko, Alexandr Rokovyi, Oleg Alienin, and Sergii Stirenko. 2020. Scaling analysis of specialized tensor processing architectures for deep learning models. In Deep Learning: Concepts and Architectures. Springer International Publishing, Cham, 65\u201399."},{"key":"e_1_3_2_16_2","first-page":"184","volume-title":"2018 IEEE International Conference on Cloud Engineering (IC2E)","author":"Guo Tian","year":"2017","unstructured":"Tian Guo. 2017. Cloud-based or on-device: An empirical study of mobile deep inference. In 2018 IEEE International Conference on Cloud Engineering (IC2E). IEEE, Orlando, FL, USA, 184\u2013190."},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/43.811318"},{"key":"e_1_3_2_18_2","first-page":"219","volume-title":"International Conference on Smart Card Research and Advanced Applications","author":"Hutter Michael","year":"2013","unstructured":"Michael Hutter and J\u00f6rn-Marc Schmidt. 2013. The temperature side channel and heating fault attacks. In International Conference on Smart Card Research and Advanced Applications. Springer International Publishing, Cham, 219\u2013235."},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/MM.2015.4"},{"key":"e_1_3_2_20_2","doi-asserted-by":"crossref","first-page":"394","DOI":"10.1109\/HPCA.2016.7446081","volume-title":"2016 IEEE International Symposium on High Performance Computer Architecture (HPCA)","author":"Jiang Zhen Hang","year":"2016","unstructured":"Zhen Hang Jiang, Yunsi Fei, and David Kaeli. 2016. A complete key recovery timing attack on a GPU. In 2016 IEEE International Symposium on High Performance Computer Architecture (HPCA). IEEE, Barcelona, Spain, 394\u2013405."},{"key":"e_1_3_2_21_2","doi-asserted-by":"crossref","first-page":"67","DOI":"10.1109\/ICCD.2018.00020","volume-title":"2018 IEEE 36th International Conference on Computer Design (ICCD)","author":"Karimi Elmira","year":"2018","unstructured":"Elmira Karimi, Zhen Hang Jiang, Yunsi Fei, and David Kaeli. 2018. A timing side-channel attack on a mobile GPU. In 2018 IEEE 36th International Conference on Computer Design (ICCD). IEEE, Orlando, FL, USA, 67\u201374."},{"key":"e_1_3_2_22_2","first-page":"1445","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Kenjar Zijo","year":"2020","unstructured":"Zijo Kenjar, Tommaso Frassetto, David Gens, Michael Franz, and Ahmad-Reza Sadeghi. 2020. V0LTpwn: Attacking x86 processor integrity from software. In 29th USENIX Security Symposium (USENIX Security 20). USENIX Association, Boston, MA, USA, 1445\u20131461. https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/kenjar"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.3390\/sym10120738"},{"key":"e_1_3_2_24_2","first-page":"19","volume-title":"2014 IEEE Symposium on Security and Privacy","author":"Lee Sangho","year":"2014","unstructured":"Sangho Lee, Youngsok Kim, Jangwoo Kim, and Jong Kim. 2014. Stealing webpages rendered on your browser by exploiting GPU vulnerabilities. In 2014 IEEE Symposium on Security and Privacy. IEEE, San Jose, CA, USA, 19\u201333."},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2016.50"},{"key":"e_1_3_2_26_2","first-page":"1","volume-title":"Proceedings of the International Conference on Computer-Aided Design","author":"Luo Chao","year":"2018","unstructured":"Chao Luo, Yunsi Fei, and David Kaeli. 2018. GPU acceleration of RSA is vulnerable to side-channel timing attacks. In Proceedings of the International Conference on Computer-Aided Design. IEEE, San Diego, CA, USA, 1\u20138."},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2015.7357115"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1007\/s41635-018-0032-7"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-015-0251-1"},{"key":"e_1_3_2_30_2","doi-asserted-by":"crossref","first-page":"1466","DOI":"10.1109\/SP40000.2020.00057","volume-title":"2020 IEEE Symposium on Security and Privacy (SP)","author":"Murdock Kit","year":"2020","unstructured":"Kit Murdock, David Oswald, Flavio D. Garcia, Jo Van Bulck, Daniel Gruss, and Frank Piessens. 2020. Plundervolt: Software-based fault injection attacks against intel SGX. In 2020 IEEE Symposium on Security and Privacy (SP). IEEE, San Francisco, CA, USA, 1466\u20131482."},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243831"},{"key":"e_1_3_2_32_2","doi-asserted-by":"crossref","first-page":"273","DOI":"10.1007\/978-3-319-64701-2_20","volume-title":"International Conference on Network and System Security","author":"Nishikawa Naoki","year":"2017","unstructured":"Naoki Nishikawa, Hideharu Amano, and Keisuke Iwai. 2017. Implementation of bitsliced AES encryption on CUDA-enabled GPU. In International Conference on Network and System Security. Springer International Publishing, Cham, 273\u2013287."},{"issue":"75","key":"e_1_3_2_33_2","first-page":"150W","article-title":"Reverse engineering power management on NVIDIA GPUs-A detailed overview","volume":"75","author":"Peres Martin","year":"2013","unstructured":"Martin Peres. 2013. Reverse engineering power management on NVIDIA GPUs-A detailed overview. Power 75, 75W (2013), 150W.","journal-title":"Power"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354201"},{"key":"e_1_3_2_35_2","first-page":"1","volume-title":"2019 Asian Hardware Oriented Security and Trust Symposium (AsianHOST)","author":"Qiu Pengfei","year":"2019","unstructured":"Pengfei Qiu, Dongsheng Wang, Yongqiang Lyu, and Gang Qu. 2019. VoltJockey: Breaking SGX by software-controlled voltage-induced hardware faults. In 2019 Asian Hardware Oriented Security and Trust Symposium (AsianHOST). IEEE, Xi\u2019an, China, 1\u20136."},{"key":"e_1_3_2_36_2","first-page":"1","volume-title":"2018 IEEE Long Island Systems, Applications and Technology Conference (LISAT)","author":"Razaque Abdul","year":"2018","unstructured":"Abdul Razaque, Wang Jinrui, Wang Zancheng, Qassim Bani Hani, Murad Ali Khaskheli, and Waseem Ahmed Bhutto. 2018. Integration of CPU and GPU to accelerate RSA modular exponentiation operation. In 2018 IEEE Long Island Systems, Applications and Technology Conference (LISAT). IEEE, Farmingdale, NY, USA, 1\u20136."},{"key":"e_1_3_2_37_2","first-page":"1","volume-title":"2020 57th ACM\/IEEE Design Automation Conference (DAC)","author":"Sabbagh Majid","year":"2020","unstructured":"Majid Sabbagh, Yunsi Fei, and David Kaeli. 2020. A novel GPU overdrive fault attack. In 2020 57th ACM\/IEEE Design Automation Conference (DAC). IEEE, San Francisco, CA, USA, 1\u20136."},{"key":"e_1_3_2_38_2","first-page":"71","article-title":"Exploiting the DRAM rowhammer bug to gain kernel privileges","volume":"15","author":"Seaborn Mark","year":"2015","unstructured":"Mark Seaborn and Thomas Dullien. 2015. Exploiting the DRAM rowhammer bug to gain kernel privileges. Black Hat 15 (2015), 71.","journal-title":"Black Hat"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/IRPS.2010.5488831"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00024"},{"key":"e_1_3_2_41_2","first-page":"1057","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Tang Adrian","year":"2017","unstructured":"Adrian Tang, Simha Sethumadhavan, and Salvatore Stolfo. 2017. CLKSCREW: Exposing the perils of security-oblivious energy management. In 26th USENIX Security Symposium (USENIX Security 17). USENIX Association, Vancouver, BC, 1057\u20131074. https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/tang"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2018.2857280"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2019.2928972"},{"key":"e_1_3_2_44_2","first-page":"681","volume-title":"13th  \\(\\lbrace\\) USENIX \\(\\rbrace\\)  Symposium on Operating Systems Design and Implementation ( \\(\\lbrace\\) OSDI \\(\\rbrace\\)  18)","author":"Volos Stavros","year":"2018","unstructured":"Stavros Volos, Kapil Vaswani, and Rodrigo Bruno. 2018. Graviton: Trusted execution environments on GPUs. In 13th \\(\\lbrace\\) USENIX \\(\\rbrace\\) Symposium on Operating Systems Design and Implementation ( \\(\\lbrace\\) OSDI \\(\\rbrace\\) 18). USENIX Association, Carlsbad, CA, 681\u2013696."},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1145\/3489517.3530516"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2018.2821559"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/3330345.3330373"}],"container-title":["ACM Transactions on Design Automation of Electronic Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3617893","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3617893","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:37:57Z","timestamp":1750178277000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3617893"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":46,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2024,1,31]]}},"alternative-id":["10.1145\/3617893"],"URL":"https:\/\/doi.org\/10.1145\/3617893","relation":{},"ISSN":["1084-4309","1557-7309"],"issn-type":[{"value":"1084-4309","type":"print"},{"value":"1557-7309","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-03-12","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-08-12","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-11-15","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}