Abstract
Emerging low-energy computing technologies, in particular approximate computing, are becoming increasingly relevant in key applications. A significant use case for these technologies is reduced energy consumption in Artificial Neural Networks (ANNs), an increasingly pressing concern with the rapid growth of AI deployments. It is essential we understand the security implications of approximate computing in an ANN context before this practice becomes commonplace. In this work, we examine the test case of approximate ANN processing elements (PE) in terms of information leakage via the power side channel. We perform a weight extraction correlation Power Analysis (CPA) attack under three approximation scenarios: overclocking, voltage scaling, and circuit level bitwise approximation. We demonstrate that as the degree of approximation increases the Signal to Noise Ratio (SNR) of power traces rapidly degrades. We show that the Measurement to Disclosure (MTD) increases for all approximate techniques. An MTD of 48 under precise computing is increased to at minimum 200 (bitwise approximate circuit at 25% approximation), and under some approximation scenarios >1024. i.e. an increase in attack difficulty of at least x4 and potentially over x20. A relative Security-Power-Delay (SPD) analysis reveals that, in addition to the across the board improvement vs precise computing, voltage and clock scaling both significantly outperform approximate circuits with voltage scaling as the highest performing technique.
| Original language | English |
|---|---|
| Title of host publication | 2025 62nd ACM/IEEE Design Automation Conference (DAC) |
| Publisher | IEEE |
| Pages | 1-7 |
| Number of pages | 7 |
| ISBN (Electronic) | 979-8-3315-0304-8 |
| ISBN (Print) | 979-8-3315-0305-5 |
| DOIs | |
| Publication status | Published online - 15 Sept 2025 |
| Event | 2025 62nd ACM/IEEE Design Automation Conference (DAC) - San Francisco, United States Duration: 22 Jun 2025 → 25 Jun 2025 |
Conference
| Conference | 2025 62nd ACM/IEEE Design Automation Conference (DAC) |
|---|---|
| Country/Territory | United States |
| City | San Francisco |
| Period | 22/06/25 → 25/06/25 |
Bibliographical note
Publisher Copyright:© 2025 IEEE.
Funding
This work was supported by EPSRC (UK) under the Grant EP/X009602/1.
| Funders | Funder number |
|---|---|
| Engineering and Physical Sciences Research Council | EP/X009602/1 |
UN SDGs
This output contributes to the following UN Sustainable Development Goals (SDGs)
-
SDG 7 Affordable and Clean Energy
Keywords
- Neural network hardware
- Power Side-channel attacks
- Approximate computing
- Artificial intelligence
Fingerprint
Dive into the research topics of 'Security of Approximate Neural Networks against Power Side-channel Attacks'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver