Skip to main navigation Skip to search Skip to main content

Security of Approximate Neural Networks against Power Side-channel Attacks

  • Aditya Japa
  • , Jack Miskelly
  • , Maire O’Neill
  • , Chongyan Gu

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Emerging low-energy computing technologies, in particular approximate computing, are becoming increasingly relevant in key applications. A significant use case for these technologies is reduced energy consumption in Artificial Neural Networks (ANNs), an increasingly pressing concern with the rapid growth of AI deployments. It is essential we understand the security implications of approximate computing in an ANN context before this practice becomes commonplace. In this work, we examine the test case of approximate ANN processing elements (PE) in terms of information leakage via the power side channel. We perform a weight extraction correlation Power Analysis (CPA) attack under three approximation scenarios: overclocking, voltage scaling, and circuit level bitwise approximation. We demonstrate that as the degree of approximation increases the Signal to Noise Ratio (SNR) of power traces rapidly degrades. We show that the Measurement to Disclosure (MTD) increases for all approximate techniques. An MTD of 48 under precise computing is increased to at minimum 200 (bitwise approximate circuit at 25% approximation), and under some approximation scenarios >1024. i.e. an increase in attack difficulty of at least x4 and potentially over x20. A relative Security-Power-Delay (SPD) analysis reveals that, in addition to the across the board improvement vs precise computing, voltage and clock scaling both significantly outperform approximate circuits with voltage scaling as the highest performing technique.
Original languageEnglish
Title of host publication2025 62nd ACM/IEEE Design Automation Conference (DAC)
PublisherIEEE
Pages1-7
Number of pages7
ISBN (Electronic)979-8-3315-0304-8
ISBN (Print)979-8-3315-0305-5
DOIs
Publication statusPublished online - 15 Sept 2025
Event2025 62nd ACM/IEEE Design Automation Conference (DAC) - San Francisco, United States
Duration: 22 Jun 202525 Jun 2025

Conference

Conference2025 62nd ACM/IEEE Design Automation Conference (DAC)
Country/TerritoryUnited States
CitySan Francisco
Period22/06/2525/06/25

Bibliographical note

Publisher Copyright:
© 2025 IEEE.

Funding

This work was supported by EPSRC (UK) under the Grant EP/X009602/1.

FundersFunder number
Engineering and Physical Sciences Research CouncilEP/X009602/1

    UN SDGs

    This output contributes to the following UN Sustainable Development Goals (SDGs)

    1. SDG 7 - Affordable and Clean Energy
      SDG 7 Affordable and Clean Energy

    Keywords

    • Neural network hardware
    • Power Side-channel attacks
    • Approximate computing
    • Artificial intelligence

    Fingerprint

    Dive into the research topics of 'Security of Approximate Neural Networks against Power Side-channel Attacks'. Together they form a unique fingerprint.

    Cite this