{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,7]],"date-time":"2026-02-07T02:41:55Z","timestamp":1770432115053,"version":"3.49.0"},"reference-count":93,"publisher":"Association for Computing Machinery (ACM)","issue":"8","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>\n                    The growing computational demand for deep neural networks (DNNs) has raised concerns about their energy consumption and carbon footprint, particularly as the size and complexity of the models continue to increase. To address these challenges, energy-efficient hardware and custom accelerators have become essential. Additionally, adaptable DNNs are being developed to dynamically balance performance and efficiency. The use of these strategies became more common to enable sustainable AI deployment. However, these efficiency-focused designs may also introduce vulnerabilities, as attackers can potentially exploit them to increase latency and energy usage by triggering their worst-case-performance scenarios. This new type of attack, called energy-latency attacks, has recently gained significant research attention, focusing on the vulnerability of DNNs to this emerging attack paradigm, which can trigger denial-of-service (DoS) attacks. This article provides a comprehensive overview of current research on energy-latency attacks, categorizing them using the established taxonomy for traditional adversarial attacks. We explore different metrics used to measure the success of these attacks and provide an analysis and comparison of existing attack strategies. We also analyze existing defense mechanisms and highlight current challenges and potential areas for future research in this developing field. The GitHub page for this work can be accessed at\n                    <jats:ext-link xmlns:xlink=\"http:\/\/www.w3.org\/1999\/xlink\" xlink:href=\"https:\/\/github.com\/hbrachemi\/Survey_energy_attacks\/\">https:\/\/github.com\/hbrachemi\/Survey_energy_attacks\/<\/jats:ext-link>\n                    .\n                  <\/jats:p>","DOI":"10.1145\/3785666","type":"journal-article","created":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T09:35:02Z","timestamp":1766396102000},"page":"1-34","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Energy-Latency Attacks: A New Adversarial Threat to Deep Learning"],"prefix":"10.1145","volume":"58","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-1399-4506","authenticated-orcid":false,"given":"Hanene F. Z.","family":"Brachemi Meftah","sequence":"first","affiliation":[{"name":"IETR, INSA-Rennes","place":["Rennes, France"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0143-1756","authenticated-orcid":false,"given":"Wassim","family":"Hamidouche","sequence":"additional","affiliation":[{"name":"INSA-Rennes","place":["Rennes, France"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6453-8588","authenticated-orcid":false,"given":"Sid Ahmed","family":"Fezza","sequence":"additional","affiliation":[{"name":"National Higher School of Telecommunications and ICT","place":["Oran, Algeria"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0750-0959","authenticated-orcid":false,"given":"Olivier","family":"Deforges","sequence":"additional","affiliation":[{"name":"INSA-Rennes","place":["Rennes, France"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,2,6]]},"reference":[{"key":"e_1_3_1_2_2","first-page":"1","article-title":"Adversarial example detection for DNN models: A review and experimental comparison","author":"Aldahdooh A.","year":"2022","unstructured":"A. Aldahdooh, W. Hamidouche, S. A. Fezza, and O. D\u00e9forges. 2022. Adversarial example detection for DNN models: A review and experimental comparison. Artificial Intelligence Review (2022), 1\u201360.","journal-title":"Artificial Intelligence Review"},{"key":"e_1_3_1_3_2","first-page":"484","volume-title":"Proceedings of the European Conference on Computer Vision","author":"Andriushchenko M.","year":"2020","unstructured":"M. Andriushchenko, F. Croce, N. Flammarion, and M. Hein. 2020. Square attack: A query-efficient black-box adversarial attack via random search. In Proceedings of the European Conference on Computer Vision. Springer, 484\u2013501."},{"issue":"1","key":"e_1_3_1_4_2","first-page":"20","article-title":"Adversarial attacks and countermeasures on image classification-based deep learning models in autonomous driving systems: A systematic review","volume":"57","author":"Badjie Bakary","year":"2024","unstructured":"Bakary Badjie, Jos\u00e9 Cec\u00edlio, and Antonio Casimiro. 2024. Adversarial attacks and countermeasures on image classification-based deep learning models in autonomous driving systems: A systematic review. ACM Computing Surveys 57, 1, Article 20 (Oct.2024), 52 pages.","journal-title":"ACM Computing Surveys"},{"key":"e_1_3_1_5_2","doi-asserted-by":"crossref","unstructured":"A. Baras A. Zolfi Y. Elovici and A. Shabtai. 2025. QuantAttack: Exploiting dynamic quantization to attack vision transformers. In Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision (WACV). Tucson AZ USA 2025 6730\u20136740. arXiv:2312.02220. Retrieved from https:\/\/arxiv.org\/abs\/2312.02220","DOI":"10.1109\/WACV61041.2025.00655"},{"key":"e_1_3_1_6_2","article-title":"Batch-shaping for learning conditional channel gated networks","author":"Bejnordi B. E.","year":"2020","unstructured":"B. E. Bejnordi, T. Blankevoort, and M. Welling. 2020. Batch-shaping for learning conditional channel gated networks. ICLR (2020).","journal-title":"ICLR"},{"key":"e_1_3_1_7_2","first-page":"2154","volume-title":"Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security","author":"Biggio B.","year":"2018","unstructured":"B. Biggio and F Roli. 2018. Wild patterns: Ten years after the rise of adversarial machine learning. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. 2154\u20132156."},{"key":"e_1_3_1_8_2","doi-asserted-by":"crossref","first-page":"1987","DOI":"10.1109\/SP46214.2022.9833641","volume-title":"Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP)","author":"Boucher N.","year":"2022","unstructured":"N. Boucher, I. Shumailov, R. Anderson, and N. Papernot. 2022. Bad characters: Imperceptible nlp attacks. In Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP). IEEE, 1987\u20132004."},{"key":"e_1_3_1_9_2","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1109\/ICFPT51103.2020.00023","volume-title":"Proceedings of the 2020 International Conference on Field-Programmable Technology (ICFPT)","author":"Boutros A.","year":"2020","unstructured":"A. Boutros, M. Hall, N. Papernot, and V. Betz. 2020. Neighbors from hell: Voltage attacks against deep learning accelerators on multi-tenant FPGAs. In Proceedings of the 2020 International Conference on Field-Programmable Technology (ICFPT). IEEE, 103\u2013111."},{"key":"e_1_3_1_10_2","doi-asserted-by":"crossref","first-page":"1897","DOI":"10.1109\/SP46214.2022.9833649","volume-title":"Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP)","author":"Carlini N.","year":"2022","unstructured":"N. Carlini, S. Chien, M. Nasr, S. Song, A. Terzis, and F. Tramer. 2022. Membership inference attacks from first principles. In Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP). IEEE, 1897\u20131914."},{"key":"e_1_3_1_11_2","first-page":"267","volume-title":"Proceedings of the 28th USENIX Security Symposium (USENIX Security 19)","author":"Carlini N.","year":"2019","unstructured":"N. Carlini, C. Liu, \u00da. Erlingsson, J. Kos, and D. Song. 2019. The secret sharer: Evaluating and testing unintended memorization in neural networks. In Proceedings of the 28th USENIX Security Symposium (USENIX Security 19). 267\u2013284."},{"key":"e_1_3_1_12_2","first-page":"39","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (sp)","author":"Carlini N.","year":"2017","unstructured":"N. Carlini and D. Wagner. 2017. Towards evaluating the robustness of neural networks. In Proceedings of the IEEE Symposium on Security and Privacy (sp). IEEE, 39\u201357."},{"key":"e_1_3_1_13_2","first-page":"24716","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Chen Erh-Chung","year":"2024","unstructured":"Erh-Chung Chen, Pin-Yu Chen, I-Hsin Chung, and Che-Rung Lee. 2024. Overload: Latency attacks on object detection for edge devices. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 24716\u201324725."},{"key":"e_1_3_1_14_2","doi-asserted-by":"crossref","first-page":"1277","DOI":"10.1109\/SP40000.2020.00045","volume-title":"Proceedings of the 2020 Ieee Symposium on Security and Privacy (sp)","author":"Chen J.","year":"2020","unstructured":"J. Chen, M. I Jordan, and M. J Wainwright. 2020. Hopskipjumpattack: A query-efficient decision-based attack. In Proceedings of the 2020 Ieee Symposium on Security and Privacy (sp). IEEE, 1277\u20131294."},{"key":"e_1_3_1_15_2","doi-asserted-by":"crossref","first-page":"175","DOI":"10.1007\/978-3-030-36708-4_15","volume-title":"Proceedings of the Neural Information Processing: 26th International Conference, ICONIP 2019, Sydney, NSW, Australia, December 12\u201315, 2019, Proceedings, Part I 26","author":"Chen J.","year":"2019","unstructured":"J. Chen, Z. Zhu, C. Li, and Y. Zhao. 2019. Self-adaptive network pruning. In Proceedings of the Neural Information Processing: 26th International Conference, ICONIP 2019, Sydney, NSW, Australia, December 12\u201315, 2019, Proceedings, Part I 26. Springer, 175\u2013186."},{"key":"e_1_3_1_16_2","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1145\/3128572.3140448","volume-title":"Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security","author":"Chen Pin-Yu","year":"2017","unstructured":"Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, and Cho-Jui Hsieh. 2017. Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security. 15\u201326."},{"key":"e_1_3_1_17_2","article-title":"Neural ordinary differential equations","volume":"31","author":"Chen R. T. Q.","year":"2018","unstructured":"R. T. Q. Chen, Y. Rubanova, J. Bettencourt, and D. K. Duvenaud. 2018. Neural ordinary differential equations. In Advances in Neural Information Processing Systems (NeurIPS 2018). Curran Associates, Inc., 31 (2018), 6572\u20136583.","journal-title":"Advances in Neural Information Processing Systems (NeurIPS 2018)"},{"key":"e_1_3_1_18_2","first-page":"24585","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Chen S.","year":"2023","unstructured":"S. Chen, H. Chen, M. Haque, C. Liu, and W. Yang. 2023. The dark side of dynamic routing neural networks: Towards efficiency backdoor injection. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 24585\u201324594."},{"key":"e_1_3_1_19_2","doi-asserted-by":"crossref","first-page":"1148","DOI":"10.1145\/3540250.3549102","volume-title":"Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering","author":"Chen S.","year":"2022","unstructured":"S. Chen, C. Liu, M. Haque, Z. Song, and W. Yang. 2022. Nmtsloth: Understanding and testing efficiency degradation of neural machine translation systems. In Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering. 1148\u20131160."},{"key":"e_1_3_1_20_2","first-page":"15365","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Chen S.","year":"2022","unstructured":"S. Chen, Z. Song, M. Haque, C. Liu, and W. Yang. 2022. Nicgslowdown: Evaluating the efficiency robustness of neural image caption generation models. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 15365\u201315374."},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11265-023-01895-3"},{"key":"e_1_3_1_22_2","volume-title":"Proceedings of the Annual Meeting of the Association for Computational Linguistics (ACL)","author":"Chen Y.","year":"2023","unstructured":"Y. Chen, S. Chen, Z. Li, W. Yang, C. Liu, R. T. Tan, and H. Li. 2023. Dynamic transformers provide a false sense of efficiency. In Proceedings of the Annual Meeting of the Association for Computational Linguistics (ACL)."},{"key":"e_1_3_1_23_2","first-page":"29830","article-title":"Amplifying membership exposure via data poisoning","volume":"35","author":"Chen Y.","year":"2022","unstructured":"Y. Chen, C. Shen, Y. Shen, C. Wang, and Y. Zhang. 2022. Amplifying membership exposure via data poisoning. Advances in Neural Information Processing Systems 35 (2022), 29830\u201329844.","journal-title":"Advances in Neural Information Processing Systems"},{"issue":"2","key":"e_1_3_1_24_2","doi-asserted-by":"crossref","first-page":"292","DOI":"10.1109\/JETCAS.2019.2910232","article-title":"Eyeriss v2: A flexible accelerator for emerging deep neural networks on mobile devices","volume":"9","author":"Chen Y.","year":"2019","unstructured":"Y. Chen, T. Yang, J. Emer, and V. Sze. 2019. Eyeriss v2: A flexible accelerator for emerging deep neural networks on mobile devices. IEEE Journal on Emerging and Selected Topics in Circuits and Systems 9, 2 (2019), 292\u2013308.","journal-title":"IEEE Journal on Emerging and Selected Topics in Circuits and Systems"},{"key":"e_1_3_1_25_2","first-page":"1148","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence","volume":"35","author":"Cheng S.","year":"2021","unstructured":"S. Cheng, Y. Liu, S. Ma, and X. Zhang. 2021. Deep feature space trojan attack of neural networks by controlled detoxification. In Proceedings of the AAAI Conference on Artificial Intelligence 35, 2 (2021), 1148\u20131156."},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2025.121905"},{"key":"e_1_3_1_27_2","doi-asserted-by":"crossref","first-page":"61113","DOI":"10.1109\/ACCESS.2024.3395118","article-title":"How deep learning sees the world: A survey on adversarial attacks & defenses","volume":"12","author":"Costa Joana C","year":"2024","unstructured":"Joana C Costa, Tiago Roxo, Hugo Proen\u00e7a, and Pedro Ricardo Morais Inacio. 2024. How deep learning sees the world: A survey on adversarial attacks & defenses. IEEE Access 12 (2024), 61113\u201361136.","journal-title":"IEEE Access"},{"key":"e_1_3_1_28_2","first-page":"30318","article-title":"Gpt3. int8 (): 8-bit matrix multiplication for transformers at scale","volume":"35","author":"Dettmers T.","year":"2022","unstructured":"T. Dettmers, M. Lewis, Y. Belkada, and L. Zettlemoyer. 2022. Gpt3. int8 (): 8-bit matrix multiplication for transformers at scale. Advances in Neural Information Processing Systems 35 (2022), 30318\u201330332.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_1_29_2","unstructured":"T. Dettmers M. Lewis Y. Belkada and L. Zettlemoyer. 2022. Llm. int8 (): 8-bit matrix multiplication for transformers at scale. In Proceedings of the 36th International Conference on Neural Information Processing Systems (NIPS\u201922). Curran Associates Inc. Red Hook NY USA Article no. 2198 30318\u201330332. arXiv:2208.07339. Retrieved from https:\/\/arxiv.org\/abs\/2208.07339"},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","unstructured":"J. Devlin M.-W. Chang K. Lee and K. N. Toutanova. 2019. BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. In Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies Volume 1 (Long and Short Papers). Association for Computational Linguistics Minneapolis Minnesota 4171\u20134186. 10.18653\/v1\/N19-1423","DOI":"10.18653\/v1\/N19-1423"},{"key":"e_1_3_1_31_2","first-page":"202","volume-title":"Proceedings of the 22nd ACM SIGMOD-SIGACT-SIGART Symposium on Principles of Database Systems","author":"Dinur I.","year":"2003","unstructured":"I. Dinur and K. Nissim. 2003. Revealing information while preserving privacy. In Proceedings of the 22nd ACM SIGMOD-SIGACT-SIGART Symposium on Principles of Database Systems. 202\u2013210."},{"issue":"3","key":"e_1_3_1_32_2","first-page":"79","article-title":"Survey on adversarial attack and defense for medical image analysis: Methods and challenges","volume":"57","author":"Dong Junhao","year":"2024","unstructured":"Junhao Dong, Junxi Chen, Xiaohua Xie, Jianhuang Lai, and Hao Chen. 2024. Survey on adversarial attack and defense for medical image analysis: Methods and challenges. ACM Computing Surveys 57, 3, Article 79 (Nov.2024), 38 pages.","journal-title":"ACM Computing Surveys"},{"key":"e_1_3_1_33_2","first-page":"1039","volume-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","author":"Figurnov M.","year":"2017","unstructured":"M. Figurnov, M. D Collins, Y. Zhu, L. Zhang, J. Huang, D. Vetrov, and R. Salakhutdinov. 2017. Spatially adaptive computation time for residual networks. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. 1039\u20131048."},{"key":"e_1_3_1_34_2","volume-title":"ICLR","author":"Gao Kuofeng","year":"2024","unstructured":"Kuofeng Gao, Yang Bai, Jindong Gu, Shu-Tao Xia, Philip Torr, Zhifeng Li, and Wei Liu. 2024. Inducing high energy-latency of large vision-language models with verbose images. In ICLR."},{"key":"e_1_3_1_35_2","unstructured":"Y. Gao B. G. Doan Z. Zhang S. Ma J. Zhang A. Fu S. Nepal and H. Kim. 2020. Backdoor attacks and countermeasures on deep learning: A comprehensive review. arXiv:2007.10760. Retrieved from https:\/\/arxiv.org\/abs\/2007.10760"},{"key":"e_1_3_1_36_2","unstructured":"I. J. Goodfellow J. Shlens and C. Szegedy. 2015. Explaining and harnessing adversarial examples. In Proceedings of the International Conference on Learning Representations (ICLR 2015)."},{"key":"e_1_3_1_37_2","unstructured":"T. Gu B. Dolan-Gavitt and S. Garg. 2017. Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv:1708.06733. Retrieved from https:\/\/arxiv.org\/abs\/1708.06733"},{"issue":"14","key":"e_1_3_1_38_2","first-page":"328","article-title":"Interpreting adversarial examples in deep learning: A review","volume":"55","author":"Han Sicong","year":"2023","unstructured":"Sicong Han, Chenhao Lin, Chao Shen, Qian Wang, and Xiaohong Guan. 2023. Interpreting adversarial examples in deep learning: A review. ACM Computing Surveys 55, 14s, Article 328 (July2023), 38 pages.","journal-title":"ACM Computing Surveys"},{"issue":"3","key":"e_1_3_1_39_2","doi-asserted-by":"crossref","first-page":"243","DOI":"10.1145\/3007787.3001163","article-title":"EIE: Efficient inference engine on compressed deep neural network","volume":"44","author":"Han S.","year":"2016","unstructured":"S. Han, X. Liu, H. Mao, J. Pu, A. Pedram, M. A Horowitz, and W. J. Dally. 2016. EIE: Efficient inference engine on compressed deep neural network. ACM SIGARCH Computer Architecture News 44, 3 (2016), 243\u2013254.","journal-title":"ACM SIGARCH Computer Architecture News"},{"key":"e_1_3_1_40_2","first-page":"14264","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Haque M.","year":"2020","unstructured":"M. Haque, A. Chauhan, C. Liu, and W. Yang. 2020. ILFO: Adversarial attack on adaptive neural networks. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 14264\u201314273."},{"key":"e_1_3_1_41_2","first-page":"1507","volume-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","author":"Haque M.","year":"2023","unstructured":"M. Haque, S. Chen, W. Haque, C. Liu, and W. Yang. 2023. AntiNODE: Evaluating efficiency robustness of neural ODEs. In Proceedings of the IEEE\/CVF International Conference on Computer Vision. 1507\u20131517."},{"key":"e_1_3_1_42_2","first-page":"1274","volume-title":"INTERSPEECH","author":"Haque Mirazul","year":"2023","unstructured":"Mirazul Haque, Rutvij Shah, Simin Chen, Berrak Sisman, Cong Liu, and Wei Yang. 2023. SlothSpeech: Denial-of-service attack against speech recognition models. In INTERSPEECH. 1274\u20131278."},{"key":"e_1_3_1_43_2","doi-asserted-by":"crossref","first-page":"835","DOI":"10.1145\/3510003.3510088","volume-title":"Proceedings of the 44th International Conference on Software Engineering","author":"Haque M.","year":"2022","unstructured":"M. Haque, Y. Yadlapalli, W. Yang, and C. Liu. 2022. EREBA: Black-box energy testing of adaptive neural networks. In Proceedings of the 44th International Conference on Software Engineering. 835\u2013846."},{"key":"e_1_3_1_44_2","unstructured":"Syed Mhamudul Hasan Hussein Zangoti Iraklis Anagnostopoulos and Abdur R Shahid. 2025. Sponge attacks on sensing AI: Energy-latency vulnerabilities and defense via model pruning. arXiv:2505.06454. Retrieved from https:\/\/arxiv.org\/abs\/2505.06454"},{"key":"e_1_3_1_45_2","first-page":"770","volume-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","author":"He Kaiming","year":"2016","unstructured":"Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep residual learning for image recognition. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. 770\u2013778."},{"issue":"241","key":"e_1_3_1_46_2","first-page":"1","article-title":"Sparsity in deep learning: Pruning and growth for efficient inference and training in neural networks","volume":"22","author":"Hoefler T.","year":"2021","unstructured":"T. Hoefler, D. Alistarh, T. Ben-Nun, N. Dryden, and A. Peste. 2021. Sparsity in deep learning: Pruning and growth for efficient inference and training in neural networks. Journal of Machine Learning Research 22, 241 (2021), 1\u2013124.","journal-title":"Journal of Machine Learning Research"},{"key":"e_1_3_1_47_2","series-title":"NIPS \u201922","volume-title":"Proceedings of the 36th International Conference on Neural Information Processing Systems","author":"Hoffmann Jordan","year":"2024","unstructured":"Jordan Hoffmann, Sebastian Borgeaud, Arthur Mensch, Elena Buchatskaya, Trevor Cai, Eliza Rutherford, Diego de Las Casas, Lisa Anne Hendricks, Johannes Welbl, Aidan Clark, et\u00a0al. 2024. Training compute-optimal large language models. In Proceedings of the 36th International Conference on Neural Information Processing Systems (New Orleans, LA, USA) (NIPS \u201922). Curran Associates Inc., Red Hook, NY, USA, Article 2176, 15 pages."},{"key":"e_1_3_1_48_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Hong Sanghyun","year":"2021","unstructured":"Sanghyun Hong, Yigitcan Kaya, Ionu\u021b-Vlad Modoranu, and Tudor Dumitras. 2021. A panda? No, it\u2019s a sloth: Slowdown attacks on adaptive multi-exit neural network inference. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_49_2","unstructured":"Andrew G Howard. 2017. Mobilenets: Efficient convolutional neural networks for mobile vision applications. arXiv:1704.04861. Retrieved from https:\/\/arxiv.org\/abs\/1704.04861"},{"key":"e_1_3_1_50_2","doi-asserted-by":"crossref","unstructured":"B. Huang L. Pang A. Fu S. F. Al-Sarawi D. C. Abbott and Y. Gao. 2024. Sponge attack against multi-exit networks with data poisoning. IEEE Access 12 (2024) 33843\u201333851.","DOI":"10.1109\/ACCESS.2024.3370849"},{"key":"e_1_3_1_51_2","unstructured":"G. Huang D. Chen T. Li F. Wu L. van der Maaten and K. Q. Weinberger. 2018. Multi\u2011scale dense networks for resource efficient image classification. In Proceedings of the International Conference on Learning Representations (ICLR 2018). arXiv:1703.09844. Retrieved from https:\/\/arxiv.org\/abs\/1703.09844"},{"key":"e_1_3_1_52_2","doi-asserted-by":"publisher","unstructured":"M. Jegorova C. Kaul C. Mayor A. Q. O\u2019Neil A. Weir R. Murray-Smith and S. A. Tsaftaris. 2022. Survey: Leakage and privacy at inference time. IEEE Transactions on Pattern Analysis and Machine Intelligence 45 7 (2022) 9090\u20139108. 10.1109\/TPAMI.2022.322959","DOI":"10.1109\/TPAMI.2022.322959"},{"issue":"11","key":"e_1_3_1_53_2","doi-asserted-by":"crossref","first-page":"4129","DOI":"10.1109\/TCAD.2020.3013077","article-title":"Sparsity turns adversarial: Energy and latency attacks on deep neural networks","volume":"39","author":"Krithivasan Sarada","year":"2020","unstructured":"Sarada Krithivasan, Sanchari Sen, and Anand Raghunathan. 2020. Sparsity turns adversarial: Energy and latency attacks on deep neural networks. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems 39, 11 (2020), 4129\u20134141.","journal-title":"IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems"},{"key":"e_1_3_1_54_2","doi-asserted-by":"crossref","first-page":"373","DOI":"10.1145\/3489517.3530443","volume-title":"Proceedings of the 59th ACM\/IEEE Design Automation Conference","author":"Krithivasan S.","year":"2022","unstructured":"S. Krithivasan, S. Sen, N. Rathi, K. Roy, and A. Raghunathan. 2022. Efficiency attacks on spiking neural networks. In Proceedings of the 59th ACM\/IEEE Design Automation Conference. 373\u2013378."},{"key":"e_1_3_1_55_2","unstructured":"Alex Krizhevsky. 2009. Learning Multiple Layers of Features from Tiny Images. Technical Report University of Toronto. https:\/\/www.cs.toronto.edu\/kriz\/cifar.html"},{"key":"e_1_3_1_56_2","first-page":"1605","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security 20)","author":"Leino K.","year":"2020","unstructured":"K. Leino and M. Fredrikson. 2020. Stolen memories: Leveraging model memorization for calibrated \\(\\lbrace\\) White-Box \\(\\rbrace\\) membership inference. In Proceedings of the 29th USENIX Security Symposium (USENIX Security 20). 1605\u20131622."},{"key":"e_1_3_1_57_2","unstructured":"K. Li and J. Malik. 2017. Learning to optimize. In Proceedings of the International Conference on Learning Representations (ICLR 2017). arXiv:1606.01885. Retrieved from https:\/\/arxiv.org\/abs\/1606.01885"},{"issue":"6","key":"e_1_3_1_58_2","first-page":"138","article-title":"A survey of robustness and safety of 2D and 3D deep learning models against adversarial attacks","volume":"56","author":"Li Yanjie","year":"2024","unstructured":"Yanjie Li, Bin Xie, Songtao Guo, Yuanyuan Yang, and Bin Xiao. 2024. A survey of robustness and safety of 2D and 3D deep learning models against adversarial attacks. ACM Computing Surveys 56, 6, Article 138 (Jan.2024), 37 pages.","journal-title":"ACM Computing Surveys"},{"key":"e_1_3_1_59_2","doi-asserted-by":"publisher","unstructured":"J. te Lintelo S. Koffas and S. Picek. 2025. The SkipSponge attack: Sponge weight poisoning of deep neural networks. ITU Journal on Future and Evolving Technologies 6 3 (2025) 247\u2013263. 10.52953\/XKBU4341","DOI":"10.52953\/XKBU4341"},{"key":"e_1_3_1_60_2","first-page":"5146","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Liu H.","year":"2023","unstructured":"H. Liu, Y. Wu, Z. Yu, Y. Vorobeychik, and N. Zhang. 2023. SlowLiDAR: Increasing the latency of LiDAR-based detection using adversarial examples. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 5146\u20135155."},{"key":"e_1_3_1_61_2","doi-asserted-by":"crossref","first-page":"182","DOI":"10.1007\/978-3-030-58607-2_11","volume-title":"Proceedings of the Computer Vision\u2013ECCV 2020: 16th European Conference, Glasgow, UK, August 23\u201328, 2020, Proceedings, Part X 16","author":"Liu Y.","year":"2020","unstructured":"Y. Liu, X. Ma, J. Bailey, and F. Lu. 2020. Reflection backdoor: A natural backdoor attack on deep neural networks. In Proceedings of the Computer Vision\u2013ECCV 2020: 16th European Conference, Glasgow, UK, August 23\u201328, 2020, Proceedings, Part X 16. Springer, 182\u2013199."},{"key":"e_1_3_1_62_2","first-page":"45","volume-title":"Proceedings of the 2017 IEEE International Conference on Computer Design (ICCD)","author":"Liu Y.","year":"2017","unstructured":"Y. Liu, Y. Xie, and A. Srivastava. 2017. Neural trojans. In Proceedings of the 2017 IEEE International Conference on Computer Design (ICCD). IEEE, 45\u201348."},{"key":"e_1_3_1_63_2","volume-title":"Proceedings of the 6th International Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada, Workshop Track Proceedings","author":"Lu Pei-Hsuan","year":"2018","unstructured":"Pei-Hsuan Lu, Pin-Yu Chen, and Chia-Mu Yu. 2018. On the limitation of local intrinsic dimensionality for characterizing the subspaces of adversarial examples. In Proceedings of the 6th International Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada, Workshop Track Proceedings."},{"issue":"1","key":"e_1_3_1_64_2","first-page":"8","article-title":"Adversarial machine learning in image classification: A survey toward the defender\u2019s perspective","volume":"55","author":"Machado Gabriel Resende","year":"2021","unstructured":"Gabriel Resende Machado, Eug\u00eanio Silva, and Ronaldo Ribeiro Goldschmidt. 2021. Adversarial machine learning in image classification: A survey toward the defender\u2019s perspective. ACM Computing Surveys 55, 1, Article 8 (Nov.2021), 38 pages.","journal-title":"ACM Computing Surveys"},{"key":"e_1_3_1_65_2","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry A.","year":"2018","unstructured":"A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu. 2018. Towards deep learning models resistant to adversarial attacks. In Proceedings of the International Conference on Learning Representations (ICLR 2018). arXiv:1706.06083. Retrieved from https:\/\/arxiv.org\/abs\/1706.06083","journal-title":"Proceedings of the International Conference on Learning Representations (ICLR 2018)"},{"key":"e_1_3_1_66_2","first-page":"1","volume-title":"Proceedings of the ICASSP 2025-2025 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","author":"Meftah Hanene Brachemi","year":"2025","unstructured":"Hanene Brachemi Meftah, Wassim Hamidouche, Sid Ahmed Fezza, Olivier D\u00e9forges, and Kassem Kallas. 2025. Energy backdoor attack to deep neural networks. In Proceedings of the ICASSP 2025-2025 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). 1\u20135."},{"key":"e_1_3_1_67_2","first-page":"12309","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Meng L.","year":"2022","unstructured":"L. Meng, H. Li, B. Chen, S. Lan, Z. Wu, Y. Jiang, and S. Lim. 2022. Adavit: Adaptive vision transformers for efficient image recognition. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 12309\u201312318."},{"key":"e_1_3_1_68_2","doi-asserted-by":"crossref","unstructured":"S.\u2011M. Moosavi\u2011Dezfooli A. Fawzi and P. Frossard. 2016. DeepFool: A simple and accurate method to fool deep neural networks. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR 2016). 2574\u20132582.","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_1_69_2","doi-asserted-by":"crossref","unstructured":"A. M\u00fcller and E. Quiring. 2024. The impact of uniform inputs on activation sparsity and energy-latency attacks in computer vision. In Proceedings of the IEEE Security and Privacy Workshops (SPW 2024) DLSP Workshop 104\u2013111.","DOI":"10.1109\/SPW63631.2024.00016"},{"key":"e_1_3_1_70_2","first-page":"24786","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Navaneet KL","year":"2024","unstructured":"KL Navaneet, Soroush Abbasi Koohpayegani, Essam Sleiman, and Hamed Pirsiavash. 2024. SlowFormer: Adversarial attack on compute and energy consumption of efficient vision transformers. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 24786\u201324797."},{"key":"e_1_3_1_71_2","article-title":"WaNet\u2013imperceptible warping-based backdoor attack","author":"Nguyen A.","year":"2021","unstructured":"A. Nguyen and A. Tran. 2021. WaNet\u2013imperceptible warping-based backdoor attack. In Proceedings of the International Conference on Learning Representations (ICLR 2021). arXiv:2102.10369. Retrieved from https:\/\/arxiv.org\/abs\/2102.10369","journal-title":"Proceedings of the International Conference on Learning Representations (ICLR 2021)"},{"key":"e_1_3_1_72_2","unstructured":"T. Nguyen P. Lai K. Tran N. Phan and M. T. Thai. 2023. Active membership inference attack under local differential privacy in federated learning. In Proceedings of the 26th International Conference on Artificial Intelligence and Statistics (AISTATS 2023) Proceedings of Machine Learning Research 206 (2023) 5714\u20135730."},{"key":"e_1_3_1_73_2","first-page":"637","volume-title":"Proceedings of the European Conference on Computer Vision","author":"Pan J.","year":"2022","unstructured":"J. Pan, Q. Zheng, Z. Fan, H. Rahmani, Q. Ke, and J. Liu. 2022. Gradauto: Energy-oriented attack on dynamic neural networks. In Proceedings of the European Conference on Computer Vision. Springer, 637\u2013653."},{"issue":"4","key":"e_1_3_1_74_2","first-page":"3243","article-title":"DefQ: Defensive quantization against inference slow-down attack for edge computing","volume":"10","author":"Qiu Han","year":"2021","unstructured":"Han Qiu, Tianwei Zhang, Tianzhu Zhang, Hongyu Li, and Meikang Qiu. 2021. DefQ: Defensive quantization against inference slow-down attack for edge computing. IEEE Internet of Things Journal 10, 4 (2021), 3243\u20133251.","journal-title":"IEEE Internet of Things Journal"},{"issue":"4","key":"e_1_3_1_75_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3624010","article-title":"A survey of privacy attacks in machine learning","volume":"56","author":"Rigaki M.","year":"2023","unstructured":"M. Rigaki and S. Garcia. 2023. A survey of privacy attacks in machine learning. ACM Computing Surveys 56, 4 (2023), 1\u201334.","journal-title":"ACM Computing Surveys"},{"key":"e_1_3_1_76_2","doi-asserted-by":"crossref","first-page":"148","DOI":"10.1016\/j.inffus.2022.09.011","article-title":"Survey on federated learning threats: Concepts, taxonomy on attacks and defences, experimental study and challenges","volume":"90","author":"Rodr\u00edguez-Barroso N.","year":"2023","unstructured":"N. Rodr\u00edguez-Barroso, D. Jim\u00e9nez-L\u00f3pez, M. V. Luz\u00f3n, F. Herrera, and E. Mart\u00ednez-C\u00e1mara. 2023. Survey on federated learning threats: Concepts, taxonomy on attacks and defences, experimental study and challenges. Information Fusion 90 (2023), 148\u2013173.","journal-title":"Information Fusion"},{"key":"e_1_3_1_77_2","first-page":"5558","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Sablayrolles A.","year":"2019","unstructured":"A. Sablayrolles, M. Douze, C. Schmid, Y. Ollivier, and H. J\u00e9gou. 2019. White-box vs black-box: Bayes optimal strategies for membership inference. In Proceedings of the International Conference on Machine Learning. PMLR, 5558\u20135567."},{"issue":"3","key":"e_1_3_1_78_2","first-page":"66","article-title":"Adversarial examples on object recognition: A comprehensive survey","volume":"53","author":"Serban Alex","year":"2020","unstructured":"Alex Serban, Erik Poll, and Joost Visser. 2020. Adversarial examples on object recognition: A comprehensive survey. ACM Computing Surveys 53, 3, Article 66 (June2020), 38 pages.","journal-title":"ACM Computing Surveys"},{"key":"e_1_3_1_79_2","first-page":"4571","volume-title":"Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision","author":"Shapira A.","year":"2023","unstructured":"A. Shapira, A. Zolfi, L. Demetrio, B. Biggio, and A. Shabtai. 2023. Phantom sponges: Exploiting non-maximum suppression to attack deep object detectors. In Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision. 4571\u20134580."},{"key":"e_1_3_1_80_2","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1109\/SP.2017.41","volume-title":"Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP)","author":"Shokri R.","year":"2017","unstructured":"R. Shokri, M. Stronati, C. Song, and V. Shmatikov. 2017. Membership inference attacks against machine learning models. In Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP). IEEE, 3\u201318."},{"key":"e_1_3_1_81_2","doi-asserted-by":"crossref","first-page":"212","DOI":"10.1109\/EuroSP51992.2021.00024","volume-title":"Proceedings of the 2021 IEEE European Symposium on Security and Privacy (EuroS&P)","author":"Shumailov I.","year":"2021","unstructured":"I. Shumailov, Y. Zhao, D. Bates, N. Papernot, R. Mullins, and R. Anderson. 2021. Sponge examples: Energy-latency attacks on neural networks. In Proceedings of the 2021 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE, 212\u2013231."},{"key":"e_1_3_1_82_2","doi-asserted-by":"crossref","unstructured":"Emma Strubell Ananya Ganesh and Andrew McCallum. 2019. Energy and policy considerations for deep learning in NLP. arXiv:1906.02243. Retrieved from https:\/\/arxiv.org\/abs\/1906.02243","DOI":"10.18653\/v1\/P19-1355"},{"key":"e_1_3_1_83_2","unstructured":"C. Szegedy W. Zaremba I. Sutskever J. Bruna D. Erhan I. Goodfellow and R. Fergus. 2013. Intriguing properties of neural networks. arXiv:1312.6199. Retrieved from https:\/\/arxiv.org\/abs\/1312.6199"},{"key":"e_1_3_1_84_2","unstructured":"Amirhossein Tavanaei. 2020. Embedded encoder-decoder in convolutional networks towards explainable AI. arXiv:2007.06712. Retrieved from https:\/\/arxiv.org\/abs\/2007.06712"},{"key":"e_1_3_1_85_2","first-page":"2464","volume-title":"Proceedings of the 2016 23rd International Conference on Pattern Recognition (ICPR)","author":"Teerapittayanon S.","year":"2016","unstructured":"S. Teerapittayanon, B. McDanel, and H. Kung. 2016. Branchynet: Fast inference via early exiting from deep neural networks. In Proceedings of the 2016 23rd International Conference on Pattern Recognition (ICPR). IEEE, 2464\u20132469."},{"key":"e_1_3_1_86_2","unstructured":"Ashish Vaswani Noam Shazeer Niki Parmar Jakob Uszkoreit Llion Jones Aidan N. Gomez \u0141ukasz Kaiser and Illia Polosukhin. 2017. Attention is all you need. In Proceedings of the 31st International Conference on Neural Information Processing Systems (NIPS\u201917). Curran Associates Inc. Red Hook NY USA 6000\u20136010."},{"key":"e_1_3_1_87_2","first-page":"409","volume-title":"Proceedings of the European Conference on Computer Vision (ECCV)","author":"Wang X.","year":"2018","unstructured":"X. Wang, F. Yu, Z. Dou, T. Darrell, and J. E. Gonzalez. 2018. Skipnet: Learning dynamic routing in convolutional networks. In Proceedings of the European Conference on Computer Vision (ECCV). 409\u2013424."},{"key":"e_1_3_1_88_2","doi-asserted-by":"crossref","unstructured":"Y. Wang T. Sun S. Li X. Yuan W. Ni E. Hossain and H. V. Poor. 2023. Adversarial attacks and defenses in machine learning-empowered communication systems and networks: A contemporary survey. IEEE Communications Surveys & Tutorials 25 4 (2023) 2245\u20132298.","DOI":"10.1109\/COMST.2023.3319492"},{"key":"e_1_3_1_89_2","series-title":"SecTL \u201923","volume-title":"Proceedings of the 2023 Secure and Trustworthy Deep Learning Systems Workshop","author":"Wang Zijian","year":"2023","unstructured":"Zijian Wang, Shuo Huang, Yujin Huang, and Helei Cui. 2023. Energy-latency attacks to on-device neural networks via sponge poisoning. In Proceedings of the 2023 Secure and Trustworthy Deep Learning Systems Workshop (Melbourne, VIC, Australia) (SecTL \u201923). Association for Computing Machinery, New York, NY, USA, Article 4, 11 pages."},{"key":"e_1_3_1_90_2","first-page":"10809","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Yin Hongxu","year":"2022","unstructured":"Hongxu Yin, Arash Vahdat, Jose M Alvarez, Arun Mallya, Jan Kautz, and Pavlo Molchanov. 2022. A-vit: Adaptive tokens for efficient vision transformer. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 10809\u201310818."},{"issue":"8","key":"e_1_3_1_91_2","first-page":"159","article-title":"Adversarial perturbation defense on deep neural networks","volume":"54","author":"Zhang Xingwei","year":"2021","unstructured":"Xingwei Zhang, Xiaolong Zheng, and Wenji Mao. 2021. Adversarial perturbation defense on deep neural networks. ACM Computing Surveys 54, 8, Article 159 (Oct.2021), 36 pages.","journal-title":"ACM Computing Surveys"},{"issue":"9","key":"e_1_3_1_92_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3724113","article-title":"The federation strikes back: A survey of federated learning privacy attacks, defenses, applications, and policy landscape","volume":"57","author":"Zhao Joshua","year":"2025","unstructured":"Joshua Zhao, Saurabh Bagchi, Salman Avestimehr, Kevin Chan, Somali Chaterji, Dimitris Dimitriadis, Jiacheng Li, Ninghui Li, Arash Nourian, and Holger Roth. 2025. The federation strikes back: A survey of federated learning privacy attacks, defenses, applications, and policy landscape. ACM Computing Surveys 57, 9 (2025), 1\u201337.","journal-title":"ACM Computing Surveys"},{"issue":"8","key":"e_1_3_1_93_2","first-page":"163","article-title":"Adversarial attacks and defenses in deep learning: From a perspective of cybersecurity","volume":"55","author":"Zhou Shuai","year":"2022","unstructured":"Shuai Zhou, Chi Liu, Dayong Ye, Tianqing Zhu, Wanlei Zhou, and Philip S. Yu. 2022. Adversarial attacks and defenses in deep learning: From a perspective of cybersecurity. ACM Computing Surveys 55, 8, Article 163 (Dec.2022), 39 pages.","journal-title":"ACM Computing Surveys"},{"key":"e_1_3_1_94_2","first-page":"2968","volume-title":"Proceedings of the 59th Annual Meeting of the Association for Computational Linguistics and the 11th International Joint Conference on Natural Language Processing (Volume 1: Long Papers)","author":"Zhu W.","year":"2021","unstructured":"W. Zhu. 2021. LeeBERT: Learned early exit for BERT with cross-level optimization. In Proceedings of the 59th Annual Meeting of the Association for Computational Linguistics and the 11th International Joint Conference on Natural Language Processing (Volume 1: Long Papers). 2968\u20132980."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3785666","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,6]],"date-time":"2026-02-06T13:28:24Z","timestamp":1770384504000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3785666"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2,6]]},"references-count":93,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3785666"],"URL":"https:\/\/doi.org\/10.1145\/3785666","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2,6]]},"assertion":[{"value":"2025-03-04","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-12-09","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-02-06","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}