PermuteV: A Performant Side-channel-Resistant RISC-V Core Securing Edge AI Inference

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Narkthong, Nuntipat, Xu, Xiaolin
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866918256876453888
author Narkthong, Nuntipat
Xu, Xiaolin
author_facet Narkthong, Nuntipat
Xu, Xiaolin
contents Edge AI inference is becoming prevalent thanks to the emergence of small yet high-performance microprocessors. This shift from cloud to edge processing brings several benefits in terms of energy savings, improved latency, and increased privacy. On the downside, bringing computation to the edge makes them more vulnerable to physical side-channel attacks (SCA), which aim to extract the confidentiality of neural network models, e.g., architecture and weight. To address this growing threat, we propose PermuteV, a performant side-channel resistant RISC-V core designed to secure neural network inference. PermuteV employs a hardware-accelerated defense mechanism that randomly permutes the execution order of loop iterations, thereby obfuscating the electromagnetic (EM) signature associated with sensitive operations. We implement PermuteV on FPGA and perform evaluations in terms of side-channel security, hardware area, and runtime overhead. The experimental results demonstrate that PermuteV can effectively defend against EM SCA with minimal area and runtime overhead.
format Preprint
id arxiv_https___arxiv_org_abs_2512_18132
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle PermuteV: A Performant Side-channel-Resistant RISC-V Core Securing Edge AI Inference
Narkthong, Nuntipat
Xu, Xiaolin
Cryptography and Security
Hardware Architecture
Edge AI inference is becoming prevalent thanks to the emergence of small yet high-performance microprocessors. This shift from cloud to edge processing brings several benefits in terms of energy savings, improved latency, and increased privacy. On the downside, bringing computation to the edge makes them more vulnerable to physical side-channel attacks (SCA), which aim to extract the confidentiality of neural network models, e.g., architecture and weight. To address this growing threat, we propose PermuteV, a performant side-channel resistant RISC-V core designed to secure neural network inference. PermuteV employs a hardware-accelerated defense mechanism that randomly permutes the execution order of loop iterations, thereby obfuscating the electromagnetic (EM) signature associated with sensitive operations. We implement PermuteV on FPGA and perform evaluations in terms of side-channel security, hardware area, and runtime overhead. The experimental results demonstrate that PermuteV can effectively defend against EM SCA with minimal area and runtime overhead.
title PermuteV: A Performant Side-channel-Resistant RISC-V Core Securing Edge AI Inference
topic Cryptography and Security
Hardware Architecture
url https://arxiv.org/abs/2512.18132