{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T14:54:49Z","timestamp":1781794489238,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":23,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T00:00:00Z","timestamp":1782086400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6,22]]},"DOI":"10.1145\/3787109.3815303","type":"proceedings-article","created":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T14:17:19Z","timestamp":1781792239000},"page":"509-515","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["METAttack: Quantifying the Vulnerabilities of Metadata Bit Flips in N:M Sparse Models"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-4256-2633","authenticated-orcid":false,"given":"Qiang","family":"Fu","sequence":"first","affiliation":[{"name":"Electrical and Computer Engineering, Binghamton University, Binghamton, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2933-750X","authenticated-orcid":false,"given":"Wenfeng","family":"Zhao","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering, Binghamton University, Binghamton, NY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,22]]},"reference":[{"key":"e_1_3_3_2_2_2","unstructured":"Kamran Chitsaz Goncalo Mordido Jean-Pierre David and Fran\u00e7ois Leduc-Primeau. 2023. Training DNNs resilient to adversarial and random bit-flips by learning quantization ranges. Transactions on Machine Learning Research (2023)."},{"key":"e_1_3_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/3123939.3124552"},{"key":"e_1_3_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00432"},{"key":"e_1_3_3_2_6_2","doi-asserted-by":"crossref","unstructured":"Chao Fang Aojun Zhou and Zhongfeng Wang. 2022. An algorithm\u2013hardware co-optimized framework for accelerating N: M sparse transformers. IEEE Transactions on Very Large Scale Integration (VLSI) Systems 30 11 (2022) 1573\u20131586.","DOI":"10.1109\/TVLSI.2022.3197282"},{"key":"e_1_3_3_2_7_2","unstructured":"Yiwen Guo Anbang Yao and Yurong Chen. 2016. Dynamic network surgery for efficient dnns. Advances in neural information processing systems 29 (2016)."},{"key":"e_1_3_3_2_8_2","unstructured":"Song Han Jeff Pool John Tran and William Dally. 2015. Learning both weights and connections for efficient neural network. Advances in neural information processing systems 28 (2015)."},{"key":"e_1_3_3_2_9_2","first-page":"497","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Hong Sanghyun","year":"2019","unstructured":"Sanghyun Hong, Pietro Frigo, Yigitcan Kaya, Cristiano Giuffrida, and Tudor Dumitra\u015f. 2019. Terminal Brain Damage: Exposing the Graceless Degradation in Deep Neural Networks Under Hardware Fault Attacks. In 28th USENIX Security Symposium (USENIX Security 19). 497\u2013514."},{"key":"e_1_3_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00286"},{"key":"e_1_3_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2014.6853210"},{"key":"e_1_3_3_2_12_2","unstructured":"Alex Krizhevsky Vinod Nair and Geoffrey Hinton. 2010. Cifar-10 (canadian institute for advanced research)."},{"key":"e_1_3_3_2_13_2","volume-title":"Advances in Neural Information Processing Systems","author":"Krizhevsky Alex","year":"2012","unstructured":"Alex Krizhevsky, Ilya Sutskever, and Geoffrey\u00a0E Hinton. 2012. ImageNet Classification with Deep Convolutional Neural Networks. In Advances in Neural Information Processing Systems , F.\u00a0Pereira, C.J. Burges, L.\u00a0Bottou, and K.Q. Weinberger (Eds.), Vol.\u00a025. Curran Associates, Inc."},{"key":"e_1_3_3_2_14_2","first-page":"6347","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Liu Qi","year":"2023","unstructured":"Qi Liu, Jieming Yin, Wujie Wen, Chengmo Yang, and Shi Sha. 2023. { NeuroPots} : realtime proactive defense against { Bit-Flip} attacks in neural networks. In 32nd USENIX Security Symposium (USENIX Security 23). 6347\u20136364."},{"key":"e_1_3_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/3579371.3589063"},{"key":"e_1_3_3_2_16_2","unstructured":"Asit Mishra Jorge Albericio\u00a0Latorre Jeff Pool Darko Stosic Dusan Stosic Ganesh Venkatesh Chong Yu and Paulius Micikevicius. 2021. Accelerating Sparse Deep Neural Networks. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2104.08378 (2021). https:\/\/arxiv.org\/abs\/2104.08378"},{"key":"e_1_3_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00130"},{"key":"e_1_3_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52734.2025.01872"},{"key":"e_1_3_3_2_19_2","unstructured":"Jialai Wang Ziyuan Zhang Meiqi Wang Han Qiu Tianwei Zhang Qi Li Zongpeng Li Tao Wei and Chao Zhang. 2023. Aegis: Mitigating Targeted Bit-flip Attacks against Deep Neural Networks. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2302.13520 (2023)."},{"key":"e_1_3_3_2_20_2","unstructured":"Wei Wen Chunpeng Wu Yandan Wang Yiran Chen and Hai Li. 2016. Learning structured sparsity in deep neural networks. Advances in neural information processing systems 29 (2016)."},{"key":"e_1_3_3_2_21_2","first-page":"2003","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Yan Mengjia","year":"2020","unstructured":"Mengjia Yan, Christopher\u00a0W Fletcher, and Josep Torrellas. 2020. Cache telepathy: Leveraging shared resource attacks to learn DNN architectures. In 29th USENIX Security Symposium (USENIX Security 20). 2003\u20132020."},{"key":"e_1_3_3_2_22_2","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Yao Fan","year":"2020","unstructured":"Fan Yao, Adnan Rakin, and Deliang Fan. 2020. DeepHammer: Depleting the Intelligence of Deep Neural Networksthrough Targeted Chain of Bit Flips. In 29th USENIX Security Symposium (USENIX Security 20)."},{"key":"e_1_3_3_2_23_2","doi-asserted-by":"crossref","unstructured":"Lu Yin Gen Li Meng Fang Li Shen Tianjin Huang Zhangyang Wang Vlado Menkovski Xiaolong Ma Mykola Pechenizkiy Shiwei Liu et\u00a0al. 2023. Dynamic sparsity is channel-level sparsity learner. Advances in Neural Information Processing Systems 36 (2023) 67993\u201368012.","DOI":"10.52202\/075280-2975"},{"key":"e_1_3_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD66269.2025.11240849"}],"event":{"name":"GLSVLSI '26: Great Lakes Symposium on VLSI 2026","location":"Canandaigua , NY , USA","acronym":"GLSVLSI '26","sponsor":["SIGDA ACM Special Interest Group on Design Automation","IEEE CEDA"]},"container-title":["Proceedings of the Great Lakes Symposium on VLSI 2026"],"original-title":[],"deposited":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T14:22:25Z","timestamp":1781792545000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3787109.3815303"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,22]]},"references-count":23,"alternative-id":["10.1145\/3787109.3815303","10.1145\/3787109"],"URL":"https:\/\/doi.org\/10.1145\/3787109.3815303","relation":{},"subject":[],"published":{"date-parts":[[2026,6,22]]},"assertion":[{"value":"2026-06-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}