{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,20]],"date-time":"2025-12-20T22:06:27Z","timestamp":1766268387600,"version":"build-2065373602"},"reference-count":30,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2023,3,27]],"date-time":"2023-03-27T00:00:00Z","timestamp":1679875200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100000028","name":"SRC","doi-asserted-by":"publisher","award":["2847.001","CNS-1722557","CCF-1718474","DGE-1723687","DGE-1821766"],"award-info":[{"award-number":["2847.001","CNS-1722557","CCF-1718474","DGE-1723687","DGE-1821766"]}],"id":[{"id":"10.13039\/100000028","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"NSF","doi-asserted-by":"publisher","award":["2847.001","CNS-1722557","CCF-1718474","DGE-1723687","DGE-1821766"],"award-info":[{"award-number":["2847.001","CNS-1722557","CCF-1718474","DGE-1723687","DGE-1821766"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Cryptography"],"abstract":"<jats:p>Spiking neural networks (SNNs) are quickly gaining traction as a viable alternative to deep neural networks (DNNs). Compared to DNNs, SNNs are computationally more powerful and energy efficient. The design metrics (synaptic weights, membrane threshold, etc.) chosen for such SNN architectures are often proprietary and constitute confidential intellectual property (IP). Our study indicates that SNN architectures implemented using conventional analog neurons are susceptible to side channel attack (SCA). Unlike the conventional SCAs that are aimed to leak private keys from cryptographic implementations, SCANN (SCA\u0332 of spiking n\u0332eural n\u0332etworks) can reveal the sensitive IP implemented within the SNN through the power side channel. We demonstrate eight unique SCANN attacks by taking a common analog neuron (axon hillock neuron) as the test case. We chose this particular model since it is biologically plausible and is hence a good fit for SNNs. Simulation results indicate that different synaptic weights, neurons\/layer, neuron membrane thresholds, and neuron capacitor sizes (which are the building blocks of SNN) yield distinct power and spike timing signatures, making them vulnerable to SCA. We show that an adversary can use templates (using foundry-calibrated simulations or fabricating known design parameters in test chips) and analysis to identify the specifications of the implemented SNN.<\/jats:p>","DOI":"10.3390\/cryptography7020017","type":"journal-article","created":{"date-parts":[[2023,3,27]],"date-time":"2023-03-27T06:46:19Z","timestamp":1679899579000},"page":"17","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["SCANN: Side Channel Analysis of Spiking Neural Networks"],"prefix":"10.3390","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0518-4940","authenticated-orcid":false,"given":"Karthikeyan","family":"Nagarajan","sequence":"first","affiliation":[{"name":"School of Electrical Engineering and Computer Science, The Pennsylvania State University, State College, PA 16801, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rupshali","family":"Roy","sequence":"additional","affiliation":[{"name":"School of Electrical Engineering and Computer Science, The Pennsylvania State University, State College, PA 16801, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8759-6959","authenticated-orcid":false,"given":"Rasit Onur","family":"Topaloglu","sequence":"additional","affiliation":[{"name":"IBM Corporation, Hopewell Junction, NY 12533, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sachhidh","family":"Kannan","sequence":"additional","affiliation":[{"name":"Ampere Computing, Portland, OR 97209, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8753-490X","authenticated-orcid":false,"given":"Swaroop","family":"Ghosh","sequence":"additional","affiliation":[{"name":"School of Electrical Engineering and Computer Science, The Pennsylvania State University, State College, PA 16801, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2023,3,27]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Kaiser, J., Tieck, J.C.V., Hubschneider, C., Wolf, P., Weber, M., Hoff, M., Friedrich, A., Wojtasik, K., Roennau, A., and Kohlhaas, R. (2016, January 13\u201316). Towards a framework for end-to-end control of a simulated vehicle with spiking neural networks. Proceedings of the 2016 IEEE International Conference on Simulation, Modeling, and Programming for Autonomous Robots (SIMPAR), San Francisco, CA, USA.","DOI":"10.1109\/SIMPAR.2016.7862386"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1138","DOI":"10.1109\/TBCAS.2020.3036081","article-title":"Hardware implementation of deep network accelerators towards healthcare and biomedical applications","volume":"14","author":"Azghadi","year":"2020","journal-title":"IEEE Trans. Biomed. Circuits Syst."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"2722","DOI":"10.1109\/JSSC.2018.2841824","article-title":"DNN engine: A 28-nm timing-error tolerant sparse deep neural network processor for IoT applications","volume":"53","author":"Whatmough","year":"2018","journal-title":"IEEE J. -Solid-State Circuits"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"54","DOI":"10.1007\/s11263-014-0788-3","article-title":"Spiking deep convolutional neural networks for energy-efficient object recognition","volume":"113","author":"Cao","year":"2015","journal-title":"Int. J. Comput. Vis."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"1659","DOI":"10.1016\/S0893-6080(97)00011-7","article-title":"Networks of spiking neurons: The third generation of neural network models","volume":"10","author":"Maass","year":"1997","journal-title":"Neural Netw."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1007\/s10827-018-0693-9","article-title":"Firing-rate models for neurons with a broad repertoire of spiking behaviors","volume":"45","author":"Heiberg","year":"2018","journal-title":"J. Comput. Neurosci."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"668","DOI":"10.1126\/science.1254642","article-title":"A million spiking-neuron integrated circuit with a scalable communication network and interface","volume":"345","author":"Merolla","year":"2014","journal-title":"Science"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"82","DOI":"10.1109\/MM.2018.112130359","article-title":"Loihi: A neuromorphic manycore processor with on-chip learning","volume":"38","author":"Davies","year":"2018","journal-title":"IEEE Micro"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1016\/j.neunet.2018.12.002","article-title":"Deep learning in spiking neural networks","volume":"111","author":"Tavanaei","year":"2019","journal-title":"Neural Netw."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Bagheri, A., Simeone, O., and Rajendran, B. (2018, January 25\u201328). Adversarial training for probabilistic spiking neural networks. Proceedings of the 2018 IEEE 19th International Workshop on Signal Processing Advances in Wireless Communications (SPAWC), Kalamata, Greece.","DOI":"10.1109\/SPAWC.2018.8446003"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Venceslai, V., Marchisio, A., Alouani, I., Martina, M., and Shafique, M. (2020, January 19\u201324). Neuroattack: Undermining spiking neural networks security through externally triggered bit-flips. Proceedings of the 2020 International Joint Conference on Neural Networks (IJCNN), Glasgow, UK.","DOI":"10.1109\/IJCNN48605.2020.9207351"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Marchisio, A., Nanfa, G., Khalid, F., Hanif, M.A., Martina, M., and Shafique, M. (2020, January 19\u201324). Is spiking secure? A comparative study on the security vulnerabilities of spiking and deep neural networks. Proceedings of the 2020 International Joint Conference on Neural Networks (IJCNN), Glasgow, UK.","DOI":"10.1109\/IJCNN48605.2020.9207297"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"801999","DOI":"10.3389\/fnano.2021.801999","article-title":"Fault injection attacks in spiking neural networks and countermeasures","volume":"3","author":"Nagarajan","year":"2022","journal-title":"Front. Nanotechnol."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Nagarajan, K., Li, J., Ensan, S.S., Khan, M.N.I., Kannan, S., and Ghosh, S. (2022, January 14\u201323). Analysis of power-oriented fault injection attacks on spiking neural networks. Proceedings of the 2022 Design, Automation & Test in Europe Conference & Exhibition (DATE), Antwerp, Belgium.","DOI":"10.23919\/DATE54114.2022.9774577"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Kocher, P., Jaffe, J., and Jun, B. (1999, January 15\u201318). Differential power analysis. Proceedings of the Annual International Cryptology Conference, Santa Barbara, CA, USA.","DOI":"10.1007\/3-540-48405-1_25"},{"key":"ref_16","unstructured":"Brier, E., Clavier, C., and Olivier, F. (2003). Cryptology ePrint Archive, International Association for Cryptologic Research."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Koblitz, N. (1996). Proceedings of the Advances in Cryptology\u2014CRYPTO \u201996, Santa Barbara, CA, USA, 18\u201322 August 1996, Springer.","DOI":"10.1007\/3-540-68697-5"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"701","DOI":"10.1016\/j.comnet.2005.01.010","article-title":"Remote timing attacks are practical","volume":"48","author":"Brumley","year":"2005","journal-title":"Comput. Netw."},{"key":"ref_19","unstructured":"Quisquater, J.J., and Samyde, D. (2001). Proceedings of the International Conference on Research in Smart Cards, Cannes, France, 19\u201321 September 2001, Springer."},{"key":"ref_20","unstructured":"Gandolfi, K., Mourtel, C., and Olivier, F. (2001). Proceedings of the International Workshop on Cryptographic Hardware and Embedded Systems, Taipei, Taiwan, 25\u201328 September 2017, Springer."},{"key":"ref_21","unstructured":"Batina, L., Bhasin, S., Jap, D., and Picek, S. (2018). CSI neural network: Using side-channels to recover your artificial neural network information. arXiv."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Garaffa, L.C., Aljuffri, A., Reinbrecht, C., Hamdioui, S., Taouil, M., and Sepulveda, J. (2021, January 1\u20133). Revealing the Secrets of Spiking Neural Networks: The Case of Izhikevich Neuron. Proceedings of the 2021 24th Euromicro Conference on Digital System Design (DSD), Palermo, Spain.","DOI":"10.1109\/DSD53832.2021.00083"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"73","DOI":"10.3389\/fnins.2011.00073","article-title":"Neuromorphic silicon neuron circuits","volume":"5","author":"Indiveri","year":"2011","journal-title":"Front. Neurosci."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"330","DOI":"10.1002\/adfm.200901335","article-title":"An organic nanoparticle transistor behaving as a biological spiking synapse","volume":"20","author":"Alibart","year":"2010","journal-title":"Adv. Funct. Mater."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"5309","DOI":"10.1038\/s41467-019-13177-3","article-title":"Optimal solid state neurons","volume":"10","author":"Taylor","year":"2019","journal-title":"Nat. Commun."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"7176","DOI":"10.1002\/adma.201503674","article-title":"Neuromorphic functions in PEDOT: PSS organic electrochemical transistors","volume":"27","author":"Gkoupidenis","year":"2015","journal-title":"Adv. Mater."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"3513","DOI":"10.1109\/TED.2014.2346700","article-title":"Neurons in polymer: Hardware neural units based on polymer memristive devices and polymer transistors","volume":"61","author":"Nawrocki","year":"2014","journal-title":"IEEE Trans. Electron Devices"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Mead, C., and Ismail, M. (1989). Analog VLSI Implementation of Neural Systems, Springer.","DOI":"10.1007\/978-1-4613-1639-8"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"57","DOI":"10.3389\/fnins.2016.00057","article-title":"Emulating the electrical activity of the neuron using a silicon oxide RRAM cell","volume":"10","author":"Mehonic","year":"2016","journal-title":"Front. Neurosci."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"484","DOI":"10.1109\/LED.2018.2805822","article-title":"PCMO RRAM for integrate-and-fire neuron in spiking neural networks","volume":"39","author":"Lashkare","year":"2018","journal-title":"IEEE Electron Device Lett."}],"container-title":["Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2410-387X\/7\/2\/17\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T19:04:00Z","timestamp":1760123040000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2410-387X\/7\/2\/17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,3,27]]},"references-count":30,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2023,6]]}},"alternative-id":["cryptography7020017"],"URL":"https:\/\/doi.org\/10.3390\/cryptography7020017","relation":{},"ISSN":["2410-387X"],"issn-type":[{"type":"electronic","value":"2410-387X"}],"subject":[],"published":{"date-parts":[[2023,3,27]]}}}