Side-Channel Extraction of Dataflow AI Accelerator Hardware Parameters

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Lomet, Guillaume, Salvador, Ruben, Colombier, Brice, Grosso, Vincent, Sentieys, Olivier, Killian, Cedric
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911172803952640
author Lomet, Guillaume
Salvador, Ruben
Colombier, Brice
Grosso, Vincent
Sentieys, Olivier
Killian, Cedric
author_facet Lomet, Guillaume
Salvador, Ruben
Colombier, Brice
Grosso, Vincent
Sentieys, Olivier
Killian, Cedric
contents Dataflow neural network accelerators efficiently process AI tasks on FPGAs, with deployment simplified by ready-to-use frameworks and pre-trained models. However, this convenience makes them vulnerable to malicious actors seeking to reverse engineer valuable Intellectual Property (IP) through Side-Channel Attacks (SCA). This paper proposes a methodology to recover the hardware configuration of dataflow accelerators generated with the FINN framework. Through unsupervised dimensionality reduction, we reduce the computational overhead compared to the state-of-the-art, enabling lightweight classifiers to recover both folding and quantization parameters. We demonstrate an attack phase requiring only 337 ms to recover the hardware parameters with an accuracy of more than 95% and 421 ms to fully recover these parameters with an averaging of 4 traces for a FINN-based accelerator running a CNN, both using a random forest classifier on side-channel traces, even with the accelerator dataflow fully loaded. This approach offers a more realistic attack scenario than existing methods, and compared to SoA attacks based on tsfresh, our method requires 940x and 110x less time for preparation and attack phases, respectively, and gives better results even without averaging traces.
format Preprint
id arxiv_https___arxiv_org_abs_2506_15432
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Side-Channel Extraction of Dataflow AI Accelerator Hardware Parameters
Lomet, Guillaume
Salvador, Ruben
Colombier, Brice
Grosso, Vincent
Sentieys, Olivier
Killian, Cedric
Cryptography and Security
Dataflow neural network accelerators efficiently process AI tasks on FPGAs, with deployment simplified by ready-to-use frameworks and pre-trained models. However, this convenience makes them vulnerable to malicious actors seeking to reverse engineer valuable Intellectual Property (IP) through Side-Channel Attacks (SCA). This paper proposes a methodology to recover the hardware configuration of dataflow accelerators generated with the FINN framework. Through unsupervised dimensionality reduction, we reduce the computational overhead compared to the state-of-the-art, enabling lightweight classifiers to recover both folding and quantization parameters. We demonstrate an attack phase requiring only 337 ms to recover the hardware parameters with an accuracy of more than 95% and 421 ms to fully recover these parameters with an averaging of 4 traces for a FINN-based accelerator running a CNN, both using a random forest classifier on side-channel traces, even with the accelerator dataflow fully loaded. This approach offers a more realistic attack scenario than existing methods, and compared to SoA attacks based on tsfresh, our method requires 940x and 110x less time for preparation and attack phases, respectively, and gives better results even without averaging traces.
title Side-Channel Extraction of Dataflow AI Accelerator Hardware Parameters
topic Cryptography and Security
url https://arxiv.org/abs/2506.15432