🤖 AI Summary
This work addresses the vulnerability of deep learning hardware deployed in safety-critical domains such as healthcare and finance to side-channel attacks, which can lead to the leakage of model architectures, parameters, and sensitive user data. The study systematically surveys existing vulnerabilities and presents the first comprehensive taxonomy of side-channel attack surfaces and defense strategies tailored to deep learning accelerators. By integrating hardware microarchitectural characteristics with physical leakage modeling, it establishes a holistic threat analysis framework that encompasses attack objectives, leakage sources, and mitigation mechanisms. Beyond clarifying the research landscape of current techniques, this paper identifies key challenges and outlines promising directions for future work, thereby offering both theoretical foundations and practical guidance for designing secure deep learning systems.
📝 Abstract
As deep learning models are increasingly deployed in critical sectors such as healthcare, finance, and security, ensuring their protection against emerging threats has become crucial. Among these threats, side-channel attacks (SCAs) represent a particular challenge since they can extract sensitive information such as model architectures, parameters, and even user inputs without requiring direct access to the model. By leveraging the physical and micro-architectural properties of the hardware, attackers can compromise systems. This survey begins by classifying leakage sources and attacker objectives, then analyzes representative studies that demonstrate practical side-channel exploits against deep-learning hardware. It also reviews existing defenses aimed at mitigating these vulnerabilities and concludes by outlining key open research challenges and potential future directions.