Attack on a PUF-based Secure Binary Neural Network

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Basak, Bijeet, Patil, Nupur, Polachan, Kurian, Vivek, Srinivas
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914118578995200
author Basak, Bijeet
Patil, Nupur
Polachan, Kurian
Vivek, Srinivas
author_facet Basak, Bijeet
Patil, Nupur
Polachan, Kurian
Vivek, Srinivas
contents Binarized Neural Networks (BNNs) deployed on memristive crossbar arrays provide energy-efficient solutions for edge computing but are susceptible to physical attacks due to memristor nonvolatility. Recently, Rajendran et al. (IEEE Embedded Systems Letter 2025) proposed a Physical Unclonable Function (PUF)-based scheme to secure BNNs against theft attacks. Specifically, the weight and bias matrices of the BNN layers were secured by swapping columns based on device's PUF key bits. In this paper, we demonstrate that this scheme to secure BNNs is vulnerable to PUF-key recovery attack. As a consequence of our attack, we recover the secret weight and bias matrices of the BNN. Our approach is motivated by differential cryptanalysis and reconstructs the PUF key bit-by-bit by observing the change in model accuracy, and eventually recovering the BNN model parameters. Evaluated on a BNN trained on the MNIST dataset, our attack could recover 85% of the PUF key, and recover the BNN model up to 93% classification accuracy compared to the original model's 96% accuracy. Our attack is very efficient and it takes a couple of minutes to recovery the PUF key and the model parameters.
format Preprint
id arxiv_https___arxiv_org_abs_2510_24422
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Attack on a PUF-based Secure Binary Neural Network
Basak, Bijeet
Patil, Nupur
Polachan, Kurian
Vivek, Srinivas
Cryptography and Security
Hardware Architecture
Machine Learning
Binarized Neural Networks (BNNs) deployed on memristive crossbar arrays provide energy-efficient solutions for edge computing but are susceptible to physical attacks due to memristor nonvolatility. Recently, Rajendran et al. (IEEE Embedded Systems Letter 2025) proposed a Physical Unclonable Function (PUF)-based scheme to secure BNNs against theft attacks. Specifically, the weight and bias matrices of the BNN layers were secured by swapping columns based on device's PUF key bits. In this paper, we demonstrate that this scheme to secure BNNs is vulnerable to PUF-key recovery attack. As a consequence of our attack, we recover the secret weight and bias matrices of the BNN. Our approach is motivated by differential cryptanalysis and reconstructs the PUF key bit-by-bit by observing the change in model accuracy, and eventually recovering the BNN model parameters. Evaluated on a BNN trained on the MNIST dataset, our attack could recover 85% of the PUF key, and recover the BNN model up to 93% classification accuracy compared to the original model's 96% accuracy. Our attack is very efficient and it takes a couple of minutes to recovery the PUF key and the model parameters.
title Attack on a PUF-based Secure Binary Neural Network
topic Cryptography and Security
Hardware Architecture
Machine Learning
url https://arxiv.org/abs/2510.24422