{"id":"02bd0519-b20a-4f59-9f86-35942bfacb36","arxiv_id":"2607.04055","paper_version":1,"verdict":"ACCEPT","confidence":"HIGH","novelty_score":3.0,"correctness_risk":"low","formal_verification":"none","parameter_count":0,"one_line_summary":"Hardware side-channel attacks can recover deep-learning model architecture, parameters and inputs; this survey taxonomizes the leaks, attacks and countermeasures.","lead":"This survey classifies side-channel leakage sources and attacker goals for deep-learning hardware, reviews representative attacks that extract model architecture, weights or inputs, and catalogs defenses. It matters because deployed neural nets in cloud, edge and IoT devices leak IP and private data through power, EM, cache and timing channels that software isolation does not stop.","discovery_kind":"review","skeptic_critique":{"model":"grok-4.5","headline":"No significant objection identified","rationale":"The manuscript meets the modest goals of a survey: it supplies a DL-specific taxonomy, representative attack pipelines with concrete steps, a defense-overhead table, and open problems (transformers, hybrid HW/SW surfaces, SCA-resilient watermarking). Because no new empirical result or formal proof is claimed, the only plausible soft spot is literature completeness. That soft spot does not undermine the strongest claim once the cited case studies are accepted as representative. The reader’s ACCEPT / low correctness-risk assessment is therefore left unchanged; the suggested spot-check is a routine verification step rather than a condition that would flip the verdict.","tokens_in":19355,"tokens_out":466,"duration_ms":3960,"concrete_test":"Spot-check three high-impact works outside the 2020–2025 high-citation filter (e.g., Batina et al. CSI NN 2019, Hua et al. DAC 2018, and one non-English or low-citation FPGA power-analysis paper) against the taxonomy of Figure 1 and the gap list in §5; if any introduces a qualitatively new leakage source or defense class missing from the survey, the completeness claim would need a minor revision. Otherwise the coverage stands.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper is a survey whose central claim is taxonomic and descriptive rather than experimental or theoretical: hardware SCAs can extract DL architecture/parameters/inputs via power/EM/cache/timing/context-switch leakage, and defenses leave gaps. That claim is supported by the concrete case studies in §3 (Cache Telepathy, DeepCache, BarraCUDA, Leaky DNN, memory-access reverse-engineering, SPA/DPA pipelines) and the defense mapping in Table 2 / §4. The reader’s weakest-assumption concern about the §1.4 literature-search methodology (high-citation + 2020–2025 + ~30–40 papers) is real for any survey but is not load-bearing here: the taxonomy in Figure 1 and the attack/defense coverage are already sufficient to establish the existence of the threat surface and residual gaps. No internal inconsistency, circular reasoning, or unsupported quantitative claim appears.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.5","summary":"This survey paper organizes the landscape of hardware side-channel attacks (SCAs) against deep-learning models. It classifies leakage sources (cache, memory, timing, power, EM, context-switch), adversary capabilities (passive/active, physical/remote), and attacker objectives (architecture, parameters, inputs), then maps those objectives to post-extraction abuses (Table 1). Section 2 surveys DL hardware platforms (CPUs, GPUs, FPGAs, custom accelerators) and their characteristic leakages; Section 3 presents detailed case studies of representative attacks (SPA/DPA pipelines, BarraCUDA EM analysis, Cache Telepathy, DeepCache, memory-access reverse-engineering, Leaky DNN context-switch attacks); Section 4 reviews defenses (masking, hiding, randomization, noise injection, cache partitioning/randomization, dummy operations, runtime detection) and summarizes them with overheads in Table 2; Section 5 lists open directions (Transformers/LSTMs, hybrid HW/SW surfaces, SCA-resilient watermarking). The central claim is taxonomic and descriptive: hardware SCAs can extract model architecture, parameters and inputs, and existing defenses leave significant residual gaps.","tokens_in":19545,"tokens_out":844,"duration_ms":8083,"significance":"The paper fills a genuine gap. While SCAs on cryptographic hardware are mature, the DL-specific literature has been scattered across power/EM, cache, and GPU context-switch papers. The unified taxonomy (Figure 1), the concrete attack pipelines in §3, and the defense-to-leakage mapping in Table 2 give practitioners and researchers a single reference that makes the threat surface and residual gaps explicit. The work is timely given the rapid deployment of MLaaS and edge AI accelerators. Strengths include the systematic literature-search description (§1.4), the clear separation of leakage sources from objectives, and the explicit call-outs of open problems (Transformers, hybrid surfaces, watermarking under SCA). No machine-checked proofs or new experimental results are claimed; the contribution is organizational and synthetic, which is appropriate for a survey.","major_comments":[],"minor_comments":[{"comment":"§1.4 states that the survey concentrates on ~30–40 representative studies from 2020–2025. A short explicit list (or a table) of the included papers, perhaps as an appendix, would make the coverage claim fully auditable and help readers locate the primary sources.","section":null},{"comment":"Table 2 lists overheads qualitatively (“Latency↑, moderate power overhead”). Where the cited papers report concrete numbers (area %, energy %, throughput loss), adding those figures would strengthen the comparison without changing the table structure.","section":null},{"comment":"Several 2025 arXiv preprints are cited ([13], [14], [17], etc.). A brief note that these works are not yet peer-reviewed would help readers calibrate confidence.","section":null},{"comment":"Figure 1 is referenced early but its caption and visual layout are not described in the text. A one-sentence walk-through of the taxonomy axes would improve accessibility.","section":null},{"comment":"Minor typographical issues: missing spaces after some citations, occasional hyphenation inconsistencies (“side-channel” vs “side channel”), and a few incomplete sentences in the author biographies. These are easily fixed in copy-editing.","section":null}],"recommendation":"accept","confidential_remarks":"The manuscript is a clean, well-structured survey that meets the standards of a specialized security journal. The literature-search methodology is typical for the genre and does not undermine the central taxonomic claim. I see no reason for major revision; the minor presentation points can be handled in production. Fit with the journal’s scope is excellent."},"author_rebuttal":null,"desk_editor":{"model":"grok-4.5","letter":"This is a clean, well-organized survey of hardware side-channel attacks on deep-learning systems. Nothing experimental or theoretical is new, but the authors give a practical map of leakage sources (power/EM, cache, timing, memory access, GPU context switch), attacker goals (architecture, parameters, inputs), and post-extraction abuses, then walk through representative attacks and defenses.\n\nWhat works: the taxonomy in Figure 1 is tailored to DL hardware rather than generic crypto SCA taxonomies, and the case studies in §3 are concrete and accurate—Cache Telepathy, DeepCache, BarraCUDA, Leaky DNN, the memory-access reverse-engineering work, and the SPA/DPA pipelines from the SoK paper. Table 2 maps defenses to attack types and notes overheads without overselling them. The open problems (transformers, hybrid HW/SW surfaces, watermarking under SCA) are the right ones. Citations look solid for a 2020–2025 survey; the methodology in §1.4 is explicit about selecting ~30–40 high-citation/recent papers, so the coverage claim is not overstated.\n\nSoft spots are minor and expected for this genre. The literature filter can miss low-citation or non-English work, but that does not break the taxonomy or the gap analysis—the existence of the threat surface is already established by the cited attacks. A few 2025 arXiv preprints appear without peer-review flags; that is a small hygiene issue, not a soundness problem. No circular reasoning, no invented quantitative claims, no internal contradictions.\n\nThis is for hardware-security and ML-systems people who need a readable entry point or a reference map before designing defenses or new attacks. It is not for someone looking for a new mechanism. I would send it to peer review as a survey; it meets its stated goals and is useful enough to referee. I would cite the taxonomy and the defense table myself if I were writing on the topic.","headline":"Solid, usable survey of DL hardware SCAs with a clear taxonomy and concrete case studies; incremental novelty but no load-bearing flaws.","tokens_in":20102,"tokens_out":494,"would_cite":true,"duration_ms":4887,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.5","headline":"Deep-learning hardware leaks model architecture, weights and inputs through power, EM, cache and timing side channels, and current defenses leave major gaps.","keywords":["Side-Channel Attacks","Deep Learning Models","Model Reverse Engineering","Intellectual Property","Side-Channel Protection","Model Security","Hardware Security","Cache Timing"],"falsifier":"Discovery of a high-impact side-channel attack or defence on deep-learning hardware that falls outside every category of the paper’s taxonomy and was published in a major venue before mid-2025 would show that the survey’s coverage and gap analysis are incomplete.","tokens_in":20266,"feed_emoji":"🔓","tokens_out":850,"duration_ms":9461,"temperature":0.7,"pith_summary":"Deep learning models are valuable intellectual property and privacy-sensitive assets, yet the CPUs, GPUs, FPGAs and accelerators that run them were built for performance, not side-channel resistance. This survey shows that passive observation of power draw, electromagnetic emissions, cache timing, memory-access patterns or GPU context-switch latency is enough for an attacker to reconstruct network topology, recover trained parameters and even steal private inputs. It organises the attack surface into a taxonomy by leakage source, access model and objective, then walks through concrete case studies on commercial hardware. Existing countermeasures such as masking, balanced logic, cache partitioning and runtime detection are catalogued together with their area, power and latency costs, revealing that none yet provide comprehensive protection. The paper therefore argues that systematic, cross-layer defences and evaluation of newer architectures remain urgent open problems.","feed_headline":"Side channels let attackers steal deep-learning models from hardware","feed_subtitle":"Power, EM and cache leaks expose architecture, weights and private inputs; defences still lag.","key_machinery":"The unified taxonomy of Figure 1 that classifies every attack by leakage source (cache, memory, timing, power, EM, context-switch), adversary access (passive/active, physical/remote), target platform and objective (architecture/parameters/inputs), thereby organising the entire literature and exposing the gaps.","core_discovery":"Hardware side-channel attacks can extract deep-learning model architecture, parameters and inputs by observing physical and micro-architectural leakage, and the defences surveyed so far leave significant residual vulnerabilities that must be closed by future research.","pith_inferences":["Because the taxonomy already links architecture recovery to model stealing and input recovery to privacy breaches, any future SCA-resistant accelerator must simultaneously protect all three objectives or the remaining unprotected channel will still enable the post-extraction abuses listed in Table 1.","The heavy reliance on chosen-input DPA/CEMA for weight recovery implies that simply randomising or encrypting the input interface could raise the cost of parameter extraction far more than masking alone.","Runtime detection pipelines developed for cryptographic caches can be repurposed almost unchanged for DNN executables, giving an immediately deployable first line of defence while hardware redesigns mature."],"forward_implications":["Model owners must treat physical and micro-architectural leakage as first-class threats equivalent to software model extraction.","Cloud multi-tenant GPU and FPGA platforms require isolation mechanisms that specifically block cache, power and context-switch channels.","Edge and IoT deployments need low-overhead power/EM countermeasures that fit resource-constrained devices.","Transformer and other emerging architectures will inherit the same leakage vectors unless new defences are designed for them.","Watermarking schemes that claim IP protection must be re-evaluated against power, cache and timing extraction attacks."],"fun_headline_variants":["Side-channel attacks extract deep-learning models via hardware","Power and EM leaks expose DL architectures and parameters","Hardware side channels steal model weights and private inputs","Survey maps side-channel threats to deep-learning hardware","Defenses lag as side channels reveal DL models from leaks"],"cache_read_input_tokens":16512,"weakest_assumption_plain":"The literature-search method that privileges high-citation and recent papers and then samples only about thirty to forty studies is assumed to give complete, unbiased coverage of the attack surface.","fun_headline_variants_meta":{"raw":{"variants":["Side-channel attacks extract deep-learning models via hardware","Power and EM leaks expose DL architectures and parameters","Hardware side channels steal model weights and private inputs","Survey maps side-channel threats to deep-learning hardware","Defenses lag as side channels reveal DL models from leaks"]},"model":"grok-4.5","effort":"low","cost_usd":0.008616,"raw_usage":{"total_tokens":1890,"prompt_tokens":633,"num_sources_used":0,"completion_tokens":80,"cost_in_usd_ticks":86160000,"prompt_tokens_details":{"text_tokens":633,"audio_tokens":0,"image_tokens":0,"cached_tokens":128},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":1177,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":633,"tokens_out":80,"duration_ms":10382,"temperature":1.0,"reasoning_tokens":1177,"cache_read_input_tokens":128,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-11T21:59:26.347728+00:00","model_set":{"reader":"grok-4.5"},"falsifier":"Discovery of a high-impact side-channel attack or defence on deep-learning hardware that falls outside every category of the paper’s taxonomy and was published in a major venue before mid-2025 would show that the survey’s coverage and gap analysis are incomplete.","supporting_citations":[],"review_version":1}