REVIEW 4 major objections 7 minor 183 references
SoK: A Systems Perspective on Compound AI Threats and Countermeasures
T0 review · 4 major / 7 minor · reviewed 2026-08-12 · deepseek-v4-flash
Pith's one-line read This SoK argues that attack techniques from the application, software, and hardware layers can be sequenced into end-to-end attacks on compound AI systems, often with weaker attacker assumptions than any single component attack requires.
desk verdict Useful SoK on compound-AI system threats, but its biggest claim about composable cross-layer attacks is asserted rather than demonstrated. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is the compound AI pipeline—query pre-processing, retrieval, generation, and query post-processing—decomposed into application, software, and hardware layers. The mechanism that carries the argument is the notion of an "attack widget": a discrete attack technique with an attached attacker capability and asset target. The paper's primary analytical tool is a mapping of these widgets onto the MITRE ATT&CK framework, which lets the authors show how reconnaissance, initial access, privilege escalation, and exfiltration steps in different layers can be chained. The case studies, such as hardware timing side-channel plus shadow-model training for extraction, and SQL injection plus ConfusedPilot for RAG misinformation, demonstrate the sequencing logic.
What would settle it
A concrete test would be to implement one of the Section 6.2 chains—say, a memory-safety bug to redirect a function call, a malicious grounding block, and a rowhammer bit flip—against a deployed RAG/MoE service and observe whether the attacker can produce a degraded or private-data-leaking response that passes fact-checking. If the chain fails at any step (for example, the bit flip is corrected, the grounding block rejects the output, or the malicious package is caught), the strongest claim would need revision.
Extended reading notes
Core claim
The paper's central claim is that "combining cross-layer attack observations can enable powerful end-to-end attacks with minimal assumptions about the threat model." Concretely, an attacker can treat each published vulnerability, side channel, or algorithmic attack as a "widget": a building block with a specific capability and a specific cost. By sequencing widgets from different layers—an OOB write to redirect a function call, a supply-chain package to create a covert timing channel, a rowhammer bit flip to corrupt a MoE router—the attacker can satisfy the preconditions of each step using a weaker overall threat model than any isolated attack requires. The paper supports this by cataloging software CVEs and hardware side-channel and fault attacks, aligning them with MITRE ATT&CK, and describing four existing cross-layer attack case studies plus qualitative emerging attack chains on compound AI systems.
Load-bearing premise
The load-bearing premise is that the attacks from different layers can actually be stitched into the described end-to-end chains on a real compound AI system without the steps interfering with each other or being detected.
Editorial extensions
If this is right
- Security evaluations of compound AI systems should treat attacks as composable paths across application, software, and hardware layers, not as isolated algorithmic threats.
- The MITRE ATT&CK mapping gives system designers a common language to position attack steps by threat model, asset, and impact, and to select layer-appropriate defenses.
- Cross-layer composition can lower the bar for existing attacks: a hardware side channel can turn a black-box model-extraction attempt into a white-box one, and an SQL injection can remove the need for direct write access to a RAG knowledge database.
- Defenses must be holistic: software supply-chain and memory-safety controls, hardware TEE and link-encryption and reliable-storage templates, and cross-layer information-flow control, rather than single-layer fixes.
- Critical targets in compound AI—knowledge databases, grounding blocks, MoE router bits, and the LLM agent—should receive prioritized protection.
Reading between the lines
- If widget sequencing is as general as the paper argues, a practical next step is to build a public benchmark of compound AI attack chains, measuring success rates and interference between steps; that would test the composability assumption directly.
- The same mapping could be turned into a red-team playbook: enterprise security teams could deliberately chain known CVEs and side channels against their own RAG and agent deployments before adversaries do.
- The paper's call for severity scoring suggests that isolated-attack severity scores should be reweighted by how well an attack serves as reconnaissance or initial access for another layer, which current scoring does not capture.
- Extending the argument, reusable attack chains may become packaged "exploit kits" for standardized compound AI stacks; the paper's framework could help anticipate which components those kits would target.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This SoK paper categorizes security threats to compound AI systems across application, software, and hardware layers. It compiles software CVEs for frameworks/packages/libraries, surveys hardware attacks on memory/interconnect/compute, maps attacks onto the MITRE ATT&CK framework, and identifies four existing and four emerging cross-layer attack chains. The central thesis, stated in the abstract and reiterated in Section 7.1, is that individual attack 'widgets' can be sequenced into powerful end-to-end attacks against compound AI systems while reducing or minimizing threat-model assumptions. The paper also surveys defenses and lists open research challenges for holistic secure-by-design compound AI platforms.
Significance. If the central composition claim were established, the paper would broaden security evaluation for compound AI from isolated algorithmic attacks to composable cross-layer system attacks. The paper's organizational value is real: it brings together a wide range of software CVEs and hardware attacks, defines a clear asset/threat-model/trust-entity taxonomy, and attempts a MITRE-style mapping for AI-specific attacks. It does not provide machine-checked proofs, reproducible code, or experimental demonstrations; its value is primarily taxonomic and hypothesis-generating. The strongest contributions are the layered model in Figure 2/3 and the assembled catalogues in Tables 1 and 2. The weakest point is that the central 'minimal threat model assumptions' claim rests entirely on qualitative chains in Section 6.2, none of which is demonstrated or analyzed for composability, so the paper currently reads as a promising framework rather than a validated systematization of cross-layer attacks.
major comments (4)
- [Abstract, §6.2, §7.1 Takeaway 1] The central claim that attack widgets 'can be sequenced to launch an end-to-end attack on a compound AI system with minimal threat model assumptions' is not supported by the evidence in the paper. Section 6.2 explicitly labels the new cross-layer attacks as qualitative, and the described chains require heterogeneous capabilities at different trust boundaries. For example, 'Generation accuracy degradation' requires (i) a memory-safety vulnerability or boot attack to learn the physical address of the MoE router multiplexer, (ii) installation of a malicious grounding block, and (iii) a Rowhammer attack during live inference. These are not minimal assumptions; they are the union of a memory-corruption exploit, a software supply-chain or privileged-software compromise, and physical or near-physical fault injection. The paper does not demonstrate any single end-to-end chain, nor does it argue why the stages compose without interference or detection. This load-bearing premise needs either a concrete demonstration, an explicit composability analysis, or a reframing of the contribution as an open hypothesis with the actual capability requirements stated.
- [§4.1, Table 1] The CVE corpus in Table 1 is not validated systematically and contains internal inconsistencies. CVE-2024-42479 is listed for both 'LLama-OOB Write' and 'LLama-Heap Ovf.', and CVE-2023-31035 appears three times under different categories (vGPU OOB Write, Firmware Config Error, and vGPU OOB Write again). The text does not describe the CVE search protocol, inclusion criteria, or how each CVE was mapped to a specific attack category and threat model. Since the software vulnerability taxonomy is a core contribution of the SoK, these entries need to be audited, deduplicated, and accompanied by a transparent methodology; otherwise the table cannot serve as a reliable reference.
- [§6.1.1] The claimed benefit of cross-layer composition is confused in the model-extraction example. The text says that hardware attacks 'transform weaker threat model assumptions of algorithmic attacks into a more realistic threat model,' but the example starts with cold-boot attacks (physical access) or Deepsniffer-style digital side-channel monitoring, which are stronger capabilities than the remote query access already assumed by black-box model extraction. If the intended point is that side-channel information supplies the white-box knowledge that the algorithmic attack would otherwise lack, the paper should state this directly. As written, the direction of threat-model relaxation is reversed, which undermines the argument that cross-layer sequencing reduces assumptions.
- [§5.1, Table 2] The hardware attack catalogue is presented as a systematization, but the selection criteria are not stated and several entries are asserted rather than demonstrated in a compound AI context. For instance, Table 2 lists 'Sesame [11]' as a compute attack, yet the cited work is a design proposal for secure multi-tenant inference accelerators rather than a demonstrated attack on a deployed compound AI system. Similarly, the 'emerging cross-layer attacks' in Section 6.2 rely on capabilities such as inserting a hardware Trojan into an FPGA accelerator or modifying function-call addresses via an OOB write, with no evidence that these stages can be achieved by the same adversary under a single threat model. The paper should either provide systematic inclusion criteria for Table 2 or explicitly mark which entries are demonstrated attacks and which are hypothetical or extrapolated.
minor comments (7)
- [Figure 4 caption] The caption says 'Three attack cases' while Section 6.1 presents four cases; the caption or the enumeration should be corrected.
- [§3.1] There is a grammatical slip: 'as as techniques' should read 'as techniques'.
- [§4.2] The phrase 'address-space-linear randomization' should be 'address space layout randomization (ASLR)'.
- [Table 1 legend] The black/white square legend is ambiguous in grayscale printing; distinct symbols or textual labels should be used.
- [Throughout] The citation to MITRE appears variously as 'M itre', 'Mitre', and 'MITRE'; please standardize to 'MITRE ATT&CK' with a single canonical reference.
- [§5.1] The text mentions 'Rowpress [117]' in the memory attacks discussion, but Table 2 lists only Rowhammer-class bitflip attacks; either add Rowpress to the table or align the narrative with the table.
- [§3.2] The four threat models are presented as an ordered severity ladder, but 'Privileged software access' and 'Digital hardware access' can overlap (e.g., a hypervisor admin with access to performance counters); a sentence clarifying the intended disjointness or overlap would help.
Circularity Check
No load-bearing circularity: self-citations are illustrative only, and the MITRE mapping and cross-layer cases rest mainly on external CVEs and third-party attacks.
full rationale
This paper is a systematization rather than a formal derivation, so the usual circularity patterns (fitted input called prediction, uniqueness theorem imported from authors, ansatz smuggled via citation, equation-level self-definition) do not apply. The central claim that attack widgets can be sequenced into end-to-end attacks is supported by the four Section 6.1 cases, which combine external CVEs (e.g., Langchain CVE-2023-36189, vGPU CVE-2023-31035) and third-party research (DeepSniffer, Deephammer, Cache Telepathy, Rowhammer, Rambleed) with a small number of same-author results. ConfusedPilot is used as one component in case 6.1.4 ('After tampering the database, the ConfusedPilot algorithmic attack can be deployed'), but the cross-layer step that removes the database-admin assumption is supplied by an external SQL-injection CVE, not by ConfusedPilot itself. Similarly, Sesame, Triton, Obsidian, and the bandwidth side-channel are cited as examples in surveys of existing attacks and defenses; no load-bearing inference depends on accepting these same-author works as proof. The Section 6.2 'emerging' chains are explicitly qualitative discussions, not demonstrated end-to-end attacks; that is an evidentiary weakness about composability and feasibility, not circularity, because the paper does not define the claimed attack outcomes in terms of its own inputs or fitted parameters. The MITRE mapping and the proposed cross-layer arrangements are independent content. The score of 2 reflects the unusually high number of same-author citations in the paper while noting that none of them is load-bearing in a circular sense.
Assumptions & free parameters
assumptions (4)
- domain assumption MITRE ATT&CK is a suitable framework for categorizing AI system attacks.
- domain assumption The threat model categories (remote software, privileged software, digital hardware, physical hardware) cover the relevant adversaries.
- domain assumption CVE entries selected in Table 1 are accurate and applicable to compound AI systems.
- domain assumption Prior attacks cited in Tables 1 and 2 are valid and generalizable to compound AI deployments.
Cite this review
Pith. "Pith review of SoK: A Systems Perspective on Compound AI Threats and Countermeasures." pith.science (2026). https://pith.science/paper/EEFAHCPI
@misc{pith2026241113459,
author = {Pith},
title = {Pith review of: SoK: A Systems Perspective on Compound AI Threats and Countermeasures},
year = {2026},
howpublished = {\url{https://pith.science/paper/EEFAHCPI}},
note = {Machine review of arXiv:2411.13459}
}
read the original abstract
Large language models (LLMs) used across enterprises often use proprietary models and operate on sensitive inputs and data. The wide range of attack vectors identified in prior research - targeting various software and hardware components used in training and inference - makes it extremely challenging to enforce confidentiality and integrity policies. As we advance towards constructing compound AI inference pipelines that integrate multiple large language models (LLMs), the attack surfaces expand significantly. Attackers now focus on the AI algorithms as well as the software and hardware components associated with these systems. While current research often examines these elements in isolation, we find that combining cross-layer attack observations can enable powerful end-to-end attacks with minimal assumptions about the threat model. Given, the sheer number of existing attacks at each layer, we need a holistic and systemized understanding of different attack vectors at each layer. This SoK discusses different software and hardware attacks applicable to compound AI systems and demonstrates how combining multiple attack mechanisms can reduce the threat model assumptions required for an isolated attack. Next, we systematize the ML attacks in lines with the Mitre Att&ck framework to better position each attack based on the threat model. Finally, we outline the existing countermeasures for both software and hardware layers and discuss the necessity of a comprehensive defense strategy to enable the secure and high-performance deployment of compound AI systems.
Figures
Figures from the paper (1 more)
Reference graph
Works this paper leans on
-
[11]
SESAME: Software defined Enclaves to Secure Inference Accelerators with Multi-tenant Execution
S. Banerjee, P. Ramrakhyani, S. Wei, and M. Tiwari, “Sesame: Software defined enclaves to secure inference accelerators with multi-tenant execution,” arXiv preprint arXiv:2007.06751 , 2020
work page Pith review arXiv 2007
-
[1]
Chatgpt
ChatGPT, “Chatgpt.” https://chatgpt.com/
-
[2]
Gemini, “Gemini.” https://gemini.google.com/app
-
[3]
Copilot
Copilot, “Copilot.” https://copilot.microsoft.com/
-
[4]
Autopilot and full self-driving (supervised) — tesla support
Tesla, “Autopilot and full self-driving (supervised) — tesla support.” https://www.tesla.com/support/autopilot
-
[5]
Ocr software, data extraction tool - amazon textract - aws
Textract, “Ocr software, data extraction tool - amazon textract - aws.” https://aws.amazon.com/textract/
-
[6]
Membership inference attacks against machine learning models,
R. Shokri, M. Stronati, C. Song, and V . Shmatikov, “Membership inference attacks against machine learning models,” in 2017 IEEE symposium on security and privacy (SP) , pp. 3–18, IEEE, 2017
2017
-
[7]
Stealing machine learning models via prediction {APIs},
F. Tram `er, F. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart, “Stealing machine learning models via prediction {APIs},” in 25th USENIX security symposium (USENIX Security 16) , pp. 601–618, 2016
2016
Show all 183 references
-
[8]
Model recon- struction from model explanations,
S. Milli, L. Schmidt, A. D. Dragan, and M. Hardt, “Model recon- struction from model explanations,” in Proceedings of the Confer- ence on Fairness, Accountability, and Transparency , pp. 1–9, 2019
2019
-
[9]
A comprehensive survey on poisoning attacks and countermeasures in machine learning,
Z. Tian, L. Cui, J. Liang, and S. Yu, “A comprehensive survey on poisoning attacks and countermeasures in machine learning,” ACM Computing Surveys, vol. 55, no. 8, pp. 1–35, 2022
2022
-
[10]
Dnn model theft through trojan side-channel on edge fpga accelerator,
S. Chandrasekar, S.-K. Lam, and S. Thambipillai, “Dnn model theft through trojan side-channel on edge fpga accelerator,” in Interna- tional Symposium on Applied Reconfigurable Computing , pp. 146– 158, Springer, 2023
2023
-
[12]
Triton: Software-defined threat model for secure multi-tenant ml inference accelerators,
S. Banerjee, S. Wei, P. Ramrakhyani, and M. Tiwari, “Triton: Software-defined threat model for secure multi-tenant ml inference accelerators,” in Proceedings of the 12th International Workshop on Hardware and Architectural Support for Security and Privacy , pp. 19–28, 2023
2023
-
[13]
Prada: protecting against dnn model stealing attacks,
M. Juuti, S. Szyller, S. Marchal, and N. Asokan, “Prada: protecting against dnn model stealing attacks,” in 2019 IEEE European Sym- posium on Security and Privacy (EuroS&P) , pp. 512–527, IEEE, 2019
2019
-
[14]
Machine un- learning,
L. Bourtoule, V . Chandrasekaran, C. A. Choquette-Choo, H. Jia, A. Travers, B. Zhang, D. Lie, and N. Papernot, “Machine un- learning,” in 2021 IEEE Symposium on Security and Privacy (SP) , pp. 141–159, IEEE, 2021
2021
-
[15]
Strong data augmenta- tion sanitizes poisoning and backdoor attacks without an accuracy tradeoff,
E. Borgnia, V . Cherepanova, L. Fowl, A. Ghiasi, J. Geiping, M. Goldblum, T. Goldstein, and A. Gupta, “Strong data augmenta- tion sanitizes poisoning and backdoor attacks without an accuracy tradeoff,” in ICASSP 2021-2021 IEEE International Conference on Acoustics, Speech and ...
2021
-
[16]
Privacy side channels in machine learning systems,
E. Debenedetti, G. Severi, N. Carlini, C. A. Choquette-Choo, M. Jagielski, M. Nasr, E. Wallace, and F. Tram `er, “Privacy side channels in machine learning systems,” in 33rd USENIX Security Symposium (USENIX Security 24) , pp. 6861–6848, 2024
2024
-
[17]
The shift from models to compound ai systems
M. Zaharia, O. Khattab, L. Chen, J. Q. Davis, H. Miller, C. Potts, J. Zou, M. Carbin, J. Frankle, N. Rao, and A. Ghodsi, “The shift from models to compound ai systems.” https://bair.berkeley.edu/bl og/2024/02/18/compound-ai-systems/, 2024
2024
-
[18]
Langchain framework
Langchain, “Langchain framework.” https://www.langchain.com/
-
[19]
Pytorch
pyTorch, “Pytorch.” https://pytorch.org/
-
[20]
Cuda® deep neural network library
Nvidia, “Cuda® deep neural network library.” https://developer.nv idia.com/cudnn
-
[21]
Rowhammer: A retrospective,
O. Mutlu and J. S. Kim, “Rowhammer: A retrospective,” IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, vol. 39, no. 8, pp. 1555–1571, 2019
2019
-
[22]
Sok: Memorization in general-purpose large language models,
V . Hartmann, A. Suri, V . Bindschaedler, D. Evans, S. Tople, and R. West, “Sok: Memorization in general-purpose large language models,” arXiv preprint arXiv:2310.18362 , 2023
2023 arXiv
-
[23]
Sok: Security and privacy in machine learning,
N. Papernot, P. McDaniel, A. Sinha, and M. P. Wellman, “Sok: Security and privacy in machine learning,” in 2018 IEEE European symposium on security and privacy (EuroS&P) , pp. 399–414, IEEE, 2018
2018
-
[24]
Sok: Membership inference is harder than previously thought,
A. Dionysiou and E. Athanasopoulos, “Sok: Membership inference is harder than previously thought,” Proceedings on Privacy Enhanc- ing Technologies, 2023
2023
-
[25]
Sok: Model inversion attack landscape: Taxonomy, challenges, and future roadmap,
S. V . Dibbo, “Sok: Model inversion attack landscape: Taxonomy, challenges, and future roadmap,” in 2023 IEEE 36th Computer Security Foundations Symposium (CSF) , pp. 439–456, IEEE, 2023
2023
-
[26]
Mitre attack framework
Mitre, “Mitre attack framework.” https://attack.mitre.org/
-
[27]
In-datacenter performance analysis of a tensor processing unit,
N. P. Jouppi, C. Young, N. Patil, D. Patterson, G. Agrawal, R. Bajwa, S. Bates, S. Bhatia, N. Boden, A. Borchers, et al. , “In-datacenter performance analysis of a tensor processing unit,” in Proceedings of the 44th annual international symposium on computer architecture , pp....
2017
-
[28]
Github copilot
Github, “Github copilot.” https://github.com/features/copilot
-
[29]
Amazon q developer
Amazon, “Amazon q developer.” https://aws.amazon.com/q/develop er/
-
[30]
Mistral ai
Mistral, “Mistral ai.” https://mistral.ai/news/mixtral-of-experts/
-
[31]
Clip-decoder: Zeroshot multilabel classifica- tion using multimodal clip aligned representations,
M. Ali and S. Khan, “Clip-decoder: Zeroshot multilabel classifica- tion using multimodal clip aligned representations,” in Proceedings of the IEEE/CVF International Conference on Computer Vision , pp. 4675–4679, 2023
2023
-
[32]
Mitre att&ck: Design and philosophy,
B. E. Strom, A. Applebaum, D. P. Miller, K. C. Nickels, A. G. Pen- nington, and C. B. Thomas, “Mitre att&ck: Design and philosophy,” in Technical report, The MITRE Corporation, 2018
2018
-
[33]
Ev- erywhere all at once: Co-location attacks on public cloud faas,
Z. N. Zhao, A. Morrison, C. W. Fletcher, and J. Torrellas, “Ev- erywhere all at once: Co-location attacks on public cloud faas,” in Proceedings of the 29th ACM International Conference on Architec- tural Support for Programming Languages and Operating Systems, Volume 1, ASPLOS...
2024
-
[34]
Theory and practice of finding eviction sets,
P. Vila, B. K ¨opf, and J. F. Morales, “Theory and practice of finding eviction sets,” in 2019 IEEE Symposium on Security and Privacy (SP), pp. 39–54, IEEE, 2019
2019
-
[35]
Flush+ reload: A high resolution, low noise, l3 cache side-channel attack,
Y . Yarom and K. Falkner, “Flush+ reload: A high resolution, low noise, l3 cache side-channel attack,” in 23rd USENIX security sym- posium (USENIX security 14) , pp. 719–732, 2014
2014
-
[36]
Cache missing for fun and profit,
C. Percival, “Cache missing for fun and profit,” 2005
2005
-
[37]
Confusedpilot: Confused deputy risks in rag-based llms,
A. RoyChowdhury, M. Luo, P. Sahu, S. Banerjee, and M. Tiwari, “Confusedpilot: Confused deputy risks in rag-based llms,” 2024
2024
-
[39]
Cache telepathy: Lever- aging shared resource attacks to learn dnn architectures,
M. Yan, C. W. Fletcher, and J. Torrellas, “Cache telepathy: Lever- aging shared resource attacks to learn dnn architectures,” in 29th USENIX Security Symposium (USENIX Security 20), pp. 2003–2020, 2020
2003
-
[40]
Hugging face
Huggingface, “Hugging face.” https://huggingface.co/
-
[41]
Google tensorflow
Google, “Google tensorflow.” https://www.tensorflow.org/
-
[42]
Apache spark
Apache, “Apache spark.” https://spark.apache.org/
-
[43]
Apache hadoop
Apache, “Apache hadoop.” https://hadoop.apache.org/
-
[44]
Snowflake
Snowflake, “Snowflake.” https://www.snowflake.com/en/
-
[45]
Bentoml
BentoML, “Bentoml.” https://www.bentoml.com/
-
[46]
Kubernetes
Kubernetes, “Kubernetes.” https://kubernetes.io/
-
[47]
Pyyaml package
Pyyaml, “Pyyaml package.” https://pypi.org/project/PyYAML/
-
[48]
Cve-2023-31035
Mitre, “Cve-2023-31035.” https://cve.mitre.org/cgi-bin/cvename.cgi ?name=CVE-2023-31035, 2023
2023
-
[49]
Cve-2024-3095
Mitre, “Cve-2024-3095.” https://cve.mitre.org/cgi-bin/cvename.cgi ?name=CVE-2024-3095, 2024
2024
-
[50]
Formal verification methods,
O. Hasan and S. Tahar, “Formal verification methods,” in Encyclope- dia of Information Science and Technology, Third Edition, pp. 7162– 7170, IGI global, 2015
2015
-
[51]
Hfl: Hybrid fuzzing on the linux kernel.,
K. Kim, D. R. Jeong, C. H. Kim, Y . Jang, I. Shin, and B. Lee, “Hfl: Hybrid fuzzing on the linux kernel.,” in NDSS, 2020
2020
-
[52]
Sok: A defense- oriented evaluation of software supply chain security,
E. Abu Ishgair, M. S. Melara, and S. Torres-Arias, “Sok: A defense- oriented evaluation of software supply chain security,” arXiv e- prints, pp. arXiv–2405, 2024
2024
-
[53]
Sok: Taxonomy of attacks on open-source software supply chains,
P. Ladisa, H. Plate, M. Martinez, and O. Barais, “Sok: Taxonomy of attacks on open-source software supply chains,” in 2023 IEEE Symposium on Security and Privacy (SP) , pp. 1509–1526, IEEE, 2023
2023
-
[54]
Practical automated detection of ma- licious npm packages,
A. Sejfia and M. Sch ¨afer, “Practical automated detection of ma- licious npm packages,” in Proceedings of the 44th International Conference on Software Engineering , pp. 1681–1692, 2022
2022
-
[55]
Immutability and encapsulation for sound oo information flow control,
T. Runge, M. Servetto, A. Potanin, and I. Schaefer, “Immutability and encapsulation for sound oo information flow control,” ACM Transactions on Programming Languages and Systems , vol. 45, no. 1, pp. 1–35, 2023
2023
-
[56]
Raksha: a flexible information flow architecture for software security,
M. Dalton, H. Kannan, and C. Kozyrakis, “Raksha: a flexible information flow architecture for software security,” ACM SIGARCH Computer Architecture News, vol. 35, no. 2, pp. 482–493, 2007
2007
-
[57]
Mod- ular information flow through ownership,
W. Crichton, M. Patrignani, M. Agrawala, and P. Hanrahan, “Mod- ular information flow through ownership,” in Proceedings of the 43rd ACM SIGPLAN International Conference on Programming Language Design and Implementation , pp. 1–14, 2022
2022
-
[58]
Rethinking privacy in machine learning pipelines from an information flow control perspective,
L. Wutschitz, B. K ¨opf, A. Paverd, S. Rajmohan, A. Salem, S. Tople, S. Zanella-B ´eguelin, M. Xia, and V . R ¨uhle, “Rethinking privacy in machine learning pipelines from an information flow control perspective,” 2023
2023
-
[59]
Rust ai engine
“Rust ai engine.” https://rust-ml.github.io/book/
-
[60]
Rusty linux: Advances in rust for linux kernel development,
S. K. Panter and N. U. Eisty, “Rusty linux: Advances in rust for linux kernel development,” arXiv preprint arXiv:2407.18431 , 2024
2024 arXiv
-
[61]
Erim: Secure, efficient in-process isolation with memory protection keys,
A. Vahldiek-Oberwagner, E. Elnikety, N. O. Duarte, M. Samm- ler, P. Druschel, and D. Garg, “Erim: Secure, efficient in-process isolation with memory protection keys,” in 28th USENIX Security Symposium, 2019
2019
-
[62]
Securecells: A secure compartmentalized architecture,
A. Bhattacharyya, F. Hofhammer, Y . Li, S. Gupta, A. Sanchez, B. Falsafi, and M. Payer, “Securecells: A secure compartmentalized architecture,” in 2023 IEEE Symposium on Security and Privacy (SP), 2023
2023
-
[63]
Retrofitting fine grain isola- tion in the firefox renderer,
S. Narayan, C. Disselkoen, T. Garfinkel, N. Froyd, E. Rahm, S. Lerner, H. Shacham, and D. Stefan, “Retrofitting fine grain isola- tion in the firefox renderer,” in 29th USENIX Security Symposium , 2020
2020
-
[64]
Going beyond the limits of sfi: Flexible and secure hardware-assisted in-process isolation with hfi,
S. Narayan, T. Garfinkel, M. Taram, J. Rudek, D. Moghimi, E. John- son, C. Fallin, A. Vahldiek-Oberwagner, M. LeMay, R. Sahita, D. Tullsen, , and D. Stefan, “Going beyond the limits of sfi: Flexible and secure hardware-assisted in-process isolation with hfi,” in Proceedings of...
2023
-
[65]
Cheri: A hybrid capability-system architecture for scalable software compart- mentalization,
R. N. Watson, J. Woodruff, P. G. Neumann, S. W. Moore, J. An- derson, D. Chisnall, N. Dave, B. Davis, K. Gudka, B. Laurie, S. J. Murdoch, R. Norton, M. Roe, S. Son, and M. Vadera, “Cheri: A hybrid capability-system architecture for scalable software compart- mentalization,” in...
2015
-
[66]
Morpheus: A vulnerability-tolerant secure architecture based on ensembles of moving target defenses with churn,
M. Gallagher, L. Biernacki, S. Chen, Z. B. Aweke, S. F. Yitbarek, M. T. Aga, A. Harris, Z. Xu, B. Kasikci, V . Bertacco, S. Malik, M. Tiwari, and T. Austin, “Morpheus: A vulnerability-tolerant secure architecture based on ensembles of moving target defenses with churn,” in Pro...
2019
-
[67]
Boosting microservice resilience: An evaluation of istio’s impact on kubernetes clusters under chaos,
S. Singh, C. H. Muntean, and S. Gupta, “Boosting microservice resilience: An evaluation of istio’s impact on kubernetes clusters under chaos,” in 2024 9th International Conference on Fog and Mobile Edge Computing (FMEC) , pp. 245–252, IEEE, 2024
2024
-
[68]
Rethinking system audit architectures for high event coverage and synchronous log availability,
V . Gandhi, S. Banerjee, A. Agrawal, A. Ahmad, S. Lee, and M. Peinado, “Rethinking system audit architectures for high event coverage and synchronous log availability,” in 32nd USENIX Secu- rity Symposium (USENIX Security 23) , pp. 391–408, 2023
2023
-
[69]
Nvidia bluefield dpu
Nvidia, “Nvidia bluefield dpu.” https://www.nvidia.com/en-us/netw orking/products/data-processing-unit/
-
[70]
Practical cold boot attack on iot device-case study on raspberry pi,
Y .-S. Won, J.-Y . Park, D.-G. Han, and S. Bhasin, “Practical cold boot attack on iot device-case study on raspberry pi,” in 2020 IEEE International Symposium on the Physical and Failure Analysis of Integrated Circuits (IPFA), pp. 1–4, IEEE, 2020
2020
-
[71]
Warm-boot attack on modern drams,
Y . Jiang, S. Wang, R. Figueiredo, and Y . Jin, “Warm-boot attack on modern drams,” in 2023 Design, Automation & Test in Europe Conference & Exhibition (DATE) , pp. 1–2, IEEE, 2023
2023
-
[72]
Drama: Exploiting dram addressing for cross-cpu attacks,
P. Pessl, D. Gruss, C. Maurice, M. Schwarz, and S. Mangard, “Drama: Exploiting dram addressing for cross-cpu attacks,” in 25th USENIX security symposium (USENIX security 16) , pp. 565–581, 2016
2016
-
[73]
Dramaqueen: Revisiting side channels in dram,
V . van der Veen and B. Gras, “Dramaqueen: Revisiting side channels in dram,” 2023
2023
-
[74]
Nvleak:off-chip side-channel attacks via non-volatile mem- ory systems,
Z. Wang, M. Taram, D. Moghimi, S. Swanson, D. Tullsen, and J. Zhao, “Nvleak:off-chip side-channel attacks via non-volatile mem- ory systems,” in 32nd USENIX Security Symposium (USENIX Secu- rity 23), pp. 6771–6788, 2023
2023
-
[75]
Deephammer: Depleting the intelligence of deep neural networks through targeted chain of bit flips,
F. Yao, A. S. Rakin, and D. Fan, “Deephammer: Depleting the intelligence of deep neural networks through targeted chain of bit flips,” in 29th USENIX Security Symposium (USENIX Security 20) , pp. 1463–1480, 2020
2020
-
[76]
Yes, one-bit-flip matters! universal dnn model inference depletion with runtime code fault injection,
S. Li, X. Wang, M. Xue, H. Zhu, Z. Zhang, Y . Gao, W. Wu, and X. S. Shen, “Yes, one-bit-flip matters! universal dnn model inference depletion with runtime code fault injection,” in Proceedings of the 33th USENIX Security Symposium , 2024
2024
-
[77]
Bit-flip attack: Crushing neural net- work with progressive bit search,
A. S. Rakin, Z. He, and D. Fan, “Bit-flip attack: Crushing neural net- work with progressive bit search,” in Proceedings of the IEEE/CVF International Conference on Computer Vision, pp. 1211–1220, 2019
2019
-
[78]
Rambleed: Reading bits in memory without accessing them,
A. Kwong, D. Genkin, D. Gruss, and Y . Yarom, “Rambleed: Reading bits in memory without accessing them,” in 2020 IEEE Symposium on Security and Privacy (SP) , pp. 695–711, IEEE, 2020
2020
-
[79]
Deepsteal: Advanced model extractions leveraging efficient weight stealing in memories,
A. S. Rakin, M. H. I. Chowdhuryy, F. Yao, and D. Fan, “Deepsteal: Advanced model extractions leveraging efficient weight stealing in memories,” in 2022 IEEE symposium on security and privacy (SP) , pp. 1157–1174, IEEE, 2022
2022
-
[80]
Side- channel attack analysis on in-memory computing architectures,
Z. Wang, F.-h. Meng, Y . Park, J. K. Eshraghian, and W. D. Lu, “Side- channel attack analysis on in-memory computing architectures,” IEEE Transactions on Emerging Topics in Computing, vol. 12, no. 1, pp. 109–121, 2023
2023
-
[81]
Powergan: A machine learning approach for power side-channel attack on compute-in-memory accelerators,
Z. Wang, Y . Wu, Y . Park, S. Yoo, X. Wang, J. K. Eshraghian, and W. D. Lu, “Powergan: A machine learning approach for power side-channel attack on compute-in-memory accelerators,” Advanced Intelligent Systems, vol. 5, no. 12, p. 2300313, 2023
2023
-
[82]
Amplifying main memory-based timing covert and side channels using processing-in-memory operations,
K. Kanellopoulos, F. Bostanci, A. Olgun, A. G. Yaglikci, I. E. Yuksel, N. M. Ghiasi, Z. Bingol, M. Sadrosadati, and O. Mutlu, “Amplifying main memory-based timing covert and side channels using processing-in-memory operations,” arXiv preprint arXiv:2404.11284, 2024
2024 arXiv
-
[84]
Understanding error propagation in deep learning neural network (dnn) accelerators and applications,
G. Li, S. K. S. Hari, M. Sullivan, T. Tsai, K. Pattabiraman, J. Emer, and S. W. Keckler, “Understanding error propagation in deep learning neural network (dnn) accelerators and applications,” in Proceedings of the International Conference for High Performance Computing, Networ...
2017
-
[85]
Fault injection for tensorflow applications,
N. Narayanan, Z. Chen, B. Fang, G. Li, K. Pattabiraman, and N. Debardeleben, “Fault injection for tensorflow applications,” IEEE Transactions on Dependable and Secure Computing , vol. 20, no. 4, pp. 2677–2695, 2022
2022
-
[86]
pcileech
ufrisk, “pcileech.” https://github.com/ufrisk/pcileech, 2017
2017
-
[87]
Thunderclap: Exploring vulnerabilities in operating system iommu protection via dma from untrustworthy peripherals,
A. T. Markettos, C. Rothwell, B. F. Gutstein, A. Pearce, P. G. Neumann, S. W. Moore, and R. N. M. Watson, “Thunderclap: Exploring vulnerabilities in operating system iommu protection via dma from untrustworthy peripherals,” in Proceedings 2019 Network and Distributed System Se...
2019
-
[88]
New security challenges on machine learning inference engine: Chip cloning and model reverse engineering,
S. Huang, X. Peng, H. Jiang, Y . Luo, and S. Yu, “New security challenges on machine learning inference engine: Chip cloning and model reverse engineering,” arXiv preprint arXiv:2003.09739, 2020
2003 arXiv
-
[89]
Reverse engineering convo- lutional neural networks through side-channel information leaks,
W. Hua, Z. Zhang, and G. E. Suh, “Reverse engineering convo- lutional neural networks through side-channel information leaks,” in Proceedings of the 55th Annual Design Automation Conference , pp. 1–6, 2018
2018
-
[90]
Bandwidth utilization side-channel on ml inference accelerators,
S. Banerjee, S. Wei, P. Ramrakhyani, and M. Tiwari, “Bandwidth utilization side-channel on ml inference accelerators,” arXiv preprint arXiv:2110.07157, 2021
2021 arXiv
-
[91]
Chen, “Hmtt.” https://asg.ict.ac.cn/hmtt/, 2019
M. Chen, “Hmtt.” https://asg.ict.ac.cn/hmtt/, 2019
2019
-
[92]
Hermes attack: Steal dnn models with lossless inference accuracy,
Y . Zhu, Y . Cheng, H. Zhou, and Y . Lu, “Hermes attack: Steal dnn models with lossless inference accuracy,” in 30th USENIX Security Symposium (USENIX Security 21) , 2021
2021
-
[93]
Deepsniffer: A dnn model extraction framework based on learning architectural hints,
X. Hu, L. Liang, S. Li, L. Deng, P. Zuo, Y . Ji, X. Xie, Y . Ding, C. Liu, T. Sherwood, et al. , “Deepsniffer: A dnn model extraction framework based on learning architectural hints,” in Proceedings of the Twenty-Fifth International Conference on Architectural Support for Prog...
2020
-
[94]
Rendered insecure: Gpu side channel attacks are practical,
H. Naghibijouybari, A. Neupane, Z. Qian, and N. Abu-Ghazaleh, “Rendered insecure: Gpu side channel attacks are practical,” in Proceedings of the 2018 ACM SIGSAC conference on computer and communications security, pp. 2139–2153, 2018
2018
-
[95]
Leaky dnn: Stealing deep-learning model secret with gpu context-switching side-channel,
J. Wei, Y . Zhang, Z. Zhou, Z. Li, and M. A. Al Faruque, “Leaky dnn: Stealing deep-learning model secret with gpu context-switching side-channel,” in 2020 50th Annual IEEE/IFIP International Con- ference on Dependable Systems and Networks (DSN) , pp. 125–137, IEEE, 2020
2020
-
[96]
Huffduff: Stealing pruned dnns from sparse accelerators,
D. Yang, P. J. Nair, and M. Lis, “Huffduff: Stealing pruned dnns from sparse accelerators,” in Proceedings of the 28th ACM In- ternational Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2 , pp. 385–399, 2023
2023
-
[97]
Sparsity turns adver- sarial: Energy and latency attacks on deep neural networks,
S. Krithivasan, S. Sen, and A. Raghunathan, “Sparsity turns adver- sarial: Energy and latency attacks on deep neural networks,” IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, vol. 39, no. 11, pp. 4129–4141, 2020
2020
-
[98]
Beyond the bridge: Contention-based covert and side channel attacks on multi-gpu interconnect,
Y . Zhang, R. Nazaraliyev, S. B. Dutta, N. Abu-Ghazaleh, A. Mar- quez, and K. Barker, “Beyond the bridge: Contention-based covert and side channel attacks on multi-gpu interconnect,” arXiv preprint arXiv:2404.03877, 2024
2024 arXiv
-
[99]
Invisible probe: Timing attacks with pcie congestion side-channel,
M. Tan, J. Wan, Z. Zhou, and Z. Li, “Invisible probe: Timing attacks with pcie congestion side-channel,” in 2021 IEEE Symposium on Security and Privacy (SP) , pp. 322–338, IEEE, 2021
2021
-
[100]
Steal- ing neural networks via timing side channels,
V . Duddu, D. Samanta, D. V . Rao, and V . E. Balas, “Steal- ing neural networks via timing side channels,” arXiv preprint arXiv:1812.11720, 2018
2018 arXiv
-
[101]
Layer sequence extraction of optimized dnns using side-channel information leaks,
Y . Sun, G. Jiang, X. Liu, P. He, and S.-K. Lam, “Layer sequence extraction of optimized dnns using side-channel information leaks,” IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, 2024
2024
-
[102]
Practical attacks on deep neural networks by memory trojaning,
X. Hu, Y . Zhao, L. Deng, L. Liang, P. Zuo, J. Ye, Y . Lin, and Y . Xie, “Practical attacks on deep neural networks by memory trojaning,” IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, vol. 40, no. 6, pp. 1230–1243, 2020
2020
-
[103]
Remote power attacks on the versatile tensor accelerator in multi-tenant fpgas,
S. Tian, S. Moini, A. Wolnikowski, D. Holcomb, R. Tessier, and J. Szefer, “Remote power attacks on the versatile tensor accelerator in multi-tenant fpgas,” in 2021 IEEE 29th Annual International Symposium on Field-Programmable Custom Computing Machines (FCCM), pp. 242–246, IEEE, 2021
2021
-
[104]
V oltage noise-based adversarial attacks on machine learning inference in multi-tenant fpga accelera- tors,
S. Majumdar and R. Teodorescu, “V oltage noise-based adversarial attacks on machine learning inference in multi-tenant fpga accelera- tors,” in 2024 IEEE International Symposium on Hardware Oriented Security and Trust (HOST) , pp. 80–85, IEEE, 2024
2024
-
[105]
Mind control attack: Undermining deep learning with gpu memory exploitation,
S.-O. Park, O. Kwon, Y . Kim, S. K. Cha, and H. Yoon, “Mind control attack: Undermining deep learning with gpu memory exploitation,” Computers & Security , vol. 102, p. 102115, 2021
2021
-
[106]
Security analysis of deep neural networks operating in the presence of cache side-channel attacks,
S. Hong, M. Davinroy, Y . Kaya, S. N. Locke, I. Rackow, K. Kulda, D. Dachman-Soled, and T. Dumitras ¸, “Security analysis of deep neural networks operating in the presence of cache side-channel attacks,” arXiv preprint arXiv:1810.03487 , 2018
-
[107]
Ganred: Gan-based reverse engineer- ing of dnns via cache side-channel,
Y . Liu and A. Srivastava, “Ganred: Gan-based reverse engineer- ing of dnns via cache side-channel,” in Proceedings of the 2020 ACM SIGSAC Conference on Cloud Computing Security Workshop , pp. 41–52, 2020
2020
-
[108]
Spy in the gpu-box: Covert and side channel attacks on multi-gpu systems,
S. B. Dutta, H. Naghibijouybari, A. Gupta, N. Abu-Ghazaleh, A. Marquez, and K. Barker, “Spy in the gpu-box: Covert and side channel attacks on multi-gpu systems,” in Proceedings of the 50th Annual International Symposium on Computer Architecture , pp. 1– 13, 2023
2023
-
[109]
Csinn: Reverse engi- neering of neural network architectures through electromagnetic side channel,
L. Batina, S. Bhasin, D. Jap, and S. Picek, “Csinn: Reverse engi- neering of neural network architectures through electromagnetic side channel,” in 28th USENIX Security Symposium (USENIX Security 19), pp. 515–532, 2019
2019
-
[110]
Simple electro- magnetic analysis against activation functions of deep neural net- works,
G. Takatoi, T. Sugawara, K. Sakiyama, and Y . Li, “Simple electro- magnetic analysis against activation functions of deep neural net- works,” in Applied Cryptography and Network Security Workshops: ACNS 2020 Satellite Workshops, AIBlock, AIHWS, AIoTS, Cloud S&P , SCI, SecMT, a...
2020
-
[111]
Barracuda: Bringing electromagnetic side channel into play to steal the weights of neural networks from nvidia gpus,
P. Horvath, L. Chmielewski, L. Weissbart, L. Batina, and Y . Yarom, “Barracuda: Bringing electromagnetic side channel into play to steal the weights of neural networks from nvidia gpus,” arXiv preprint arXiv:2312.07783, 2023
2023 arXiv
-
[112]
Floating-point multiplication timing attack on deep neural network,
G. Dong, P. Wang, P. Chen, R. Gu, and H. Hu, “Floating-point multiplication timing attack on deep neural network,” in 2019 IEEE International Conference on Smart Internet of Things (SmartIoT) , pp. 155–161, IEEE, 2019
2019
-
[113]
Int-monitor: a model triggered hardware trojan in deep learning accelerators,
P. Li and R. Hou, “Int-monitor: a model triggered hardware trojan in deep learning accelerators,” The Journal of Supercomputing, vol. 79, no. 3, pp. 3095–3111, 2023
2023
-
[114]
Open dnn box by power side- channel attack,
Y . Xiang, Z. Chen, Z. Chen, Z. Fang, H. Hao, J. Chen, Y . Liu, Z. Wu, Q. Xuan, and X. Yang, “Open dnn box by power side- channel attack,” IEEE Transactions on Circuits and Systems II: Express Briefs, vol. 67, no. 11, pp. 2717–2721, 2020
2020
-
[115]
Physical side-channel attacks on embedded neural networks: A survey,
M. M ´endez Real and R. Salvador, “Physical side-channel attacks on embedded neural networks: A survey,” Applied Sciences , vol. 11, no. 15, p. 6790, 2021
2021
-
[116]
Fault injection attack on deep neural network,
Y . Liu, L. Wei, B. Luo, and Q. Xu, “Fault injection attack on deep neural network,” in 2017 IEEE/ACM International Conference on Computer-Aided Design (ICCAD) , pp. 131–138, IEEE, 2017
2017
-
[117]
Rowpress: Amplifying read disturbance in modern dram chips,
H. Luo, A. Olgun, A. G. Ya ˘glıkc ¸ı, Y . C. Tu˘grul, S. Rhyner, M. B. Cavlak, J. Lindegger, M. Sadrosadati, and O. Mutlu, “Rowpress: Amplifying read disturbance in modern dram chips,” in Proceedings of the 50th Annual International Symposium on Computer Architec- ture, pp. 1–18, 2023
2023
-
[118]
Aqua: Scalable rowhammer mitigation by quarantining aggressor rows at runtime,
A. Saxena, G. Saileshwar, P. J. Nair, and M. Qureshi, “Aqua: Scalable rowhammer mitigation by quarantining aggressor rows at runtime,” in 2022 55th IEEE/ACM International Symposium on Microarchitecture (MICRO), pp. 108–123, IEEE, 2022
2022
-
[119]
Intel trust domain extensions
TDX, “Intel trust domain extensions.” https://www.intel.com/conten t/www/us/en/developer/tools/trust-domain-extensions/overview.htm l, 2021
2021
-
[120]
Amd secure encrypted virtualizations
AMD-SEV , “Amd secure encrypted virtualizations.” https://www. amd.com/en/developer/sev.html, 2018
2018
-
[121]
Data integrity checking for iscsi with dm-verity,
R. Zhou, Z. Ai, J. Hu, Q. Liu, Q. Zhou, X. Wang, H. Jiang, and K.-C. Li, “Data integrity checking for iscsi with dm-verity,” in Advanced Technologies, Embedded and Multimedia for Human-centric Com- puting: HumanCom and EMC 2013 , pp. 691–697, Springer, 2014
2013
-
[122]
Intel sgx explained,
V . Costan, “Intel sgx explained,” IACR Cryptol, EPrint Arch , 2016
2016
-
[123]
Memory encryption for general-purpose processors,
S. Gueron, “Memory encryption for general-purpose processors,” IEEE Security & Privacy , vol. 14, no. 6, pp. 54–62, 2016
2016
-
[124]
Morphable counters: Enabling compact integrity trees for low-overhead secure memories,
G. Saileshwar, P. J. Nair, P. Ramrakhyani, W. Elsasser, J. A. Joao, and M. K. Qureshi, “Morphable counters: Enabling compact integrity trees for low-overhead secure memories,” in 2018 51st Annual IEEE/ACM International Symposium on Microarchitecture (MICRO), pp. 416–427, IEEE, 2018
2018
-
[125]
Mgx: Near-zero overhead memory protection for data-intensive accelerators,
W. Hua, M. Umar, Z. Zhang, and G. E. Suh, “Mgx: Near-zero overhead memory protection for data-intensive accelerators,” in Pro- ceedings of the 49th Annual International Symposium on Computer Architecture, pp. 726–741, 2022
2022
-
[126]
Aegis: Mitigating targeted bit-flip attacks against deep neural networks,
J. Wang, Z. Zhang, M. Wang, H. Qiu, T. Zhang, Q. Li, Z. Li, T. Wei, and C. Zhang, “Aegis: Mitigating targeted bit-flip attacks against deep neural networks,” in 32nd USENIX Security Symposium (USENIX Security 23) , pp. 2329–2346, 2023
2023
-
[127]
Hydra: En- abling low-overhead mitigation of row-hammer at ultra-low thresh- olds via hybrid tracking,
M. Qureshi, A. Rohan, G. Saileshwar, and P. J. Nair, “Hydra: En- abling low-overhead mitigation of row-hammer at ultra-low thresh- olds via hybrid tracking,” in Proceedings of the 49th Annual Inter- national Symposium on Computer Architecture , pp. 699–710, 2022
2022
-
[128]
Scalable and secure row- swap: Efficient and safe row hammer mitigation in memory sys- tems,
J. Woo, G. Saileshwar, and P. J. Nair, “Scalable and secure row- swap: Efficient and safe row hammer mitigation in memory sys- tems,” in 2023 IEEE International Symposium on High-Performance Computer Architecture (HPCA), pp. 374–389, IEEE, 2023
2023
-
[129]
Timing channel protection for a shared memory controller,
Y . Wang, A. Ferraiuolo, and G. E. Suh, “Timing channel protection for a shared memory controller,” in 2014 IEEE 20th International Symposium on High Performance Computer Architecture (HPCA) , pp. 225–236, IEEE, 2014
2014
-
[130]
Lattice priority scheduling: Low-overhead timing-channel protec- tion for a shared memory controller,
A. Ferraiuolo, Y . Wang, D. Zhang, A. C. Myers, and G. E. Suh, “Lattice priority scheduling: Low-overhead timing-channel protec- tion for a shared memory controller,” in 2016 IEEE International Symposium on High Performance Computer Architecture (HPCA) , pp. 382–393, IEEE, 2016
2016
-
[131]
Secndp: Secure near-data processing with untrusted memory,
W. Xiong, L. Ke, D. Jankov, M. Kounavis, X. Wang, E. Northup, J. A. Yang, B. Acun, C.-J. Wu, P. T. P. Tang,et al., “Secndp: Secure near-data processing with untrusted memory,” in 2022 IEEE Inter- national Symposium on High-Performance Computer Architecture (HPCA), pp. 244–258,...
2022
-
[132]
Avoiding information leakage in the memory controller with fixed service policies,
A. Shafiee, A. Gundu, M. Shevgoor, R. Balasubramonian, and M. Tiwari, “Avoiding information leakage in the memory controller with fixed service policies,” in Proceedings of the 48th International Symposium on Microarchitecture, pp. 89–101, 2015
2015
-
[133]
Power side-channel attacks and countermeasures on computation-in-memory architectures and technologies,
B. Sapui, J. Krautter, M. Mayahinia, A. Jafari, D. Gnad, S. Meschkov, and M. B. Tahoori, “Power side-channel attacks and countermeasures on computation-in-memory architectures and technologies,” in 2023 IEEE European Test Symposium (ETS), pp. 1– 6, IEEE, 2023
2023
-
[134]
{RL-Watchdog}: A fast and predictable {SSD} liveness watchdog on storage systems,
J. Y . Ha, S. Lee, H. Y . Yeom, and Y . Son, “ {RL-Watchdog}: A fast and predictable {SSD} liveness watchdog on storage systems,” in 2024 USENIX Annual Technical Conference (USENIX ATC 24) , pp. 1083–1100, 2024
2024
-
[135]
Security of nvme offloaded data in large-scale machine learning,
T. Krauß, R. G ¨otz, and A. Dmitrienko, “Security of nvme offloaded data in large-scale machine learning,” in European Symposium on Research in Computer Security , pp. 143–163, Springer, 2023
2023
-
[136]
Onion oram: A constant bandwidth blowup oblivious ram,
S. Devadas, M. van Dijk, C. W. Fletcher, L. Ren, E. Shi, and D. Wichs, “Onion oram: A constant bandwidth blowup oblivious ram,” in Theory of Cryptography: 13th International Conference, TCC 2016-A, Tel Aviv, Israel, January 10-13, 2016, Proceedings, Part II 13, pp. 145–174, Sp...
2016
-
[137]
Guardnn: secure accelerator architecture for privacy-preserving deep learning,
W. Hua, M. Umar, Z. Zhang, and G. E. Suh, “Guardnn: secure accelerator architecture for privacy-preserving deep learning,” in Proceedings of the 59th ACM/IEEE Design Automation Conference , pp. 349–354, 2022
2022
-
[138]
Intel iommu
IOMMU, “Intel iommu.” https://www.intel.com/content/dam/develo p/external/us/en/documents/intel-whitepaper-using-iommu-for-dma -protection-in-uefi-820238.pdf, 2014
2014
-
[139]
{sRDMA}– efficient {NIC-based} authentication and encryption for remote di- rect memory access,
K. Taranov, B. Rothenberger, A. Perrig, and T. Hoefler, “{sRDMA}– efficient {NIC-based} authentication and encryption for remote di- rect memory access,” in 2020 USENIX Annual Technical Conference (USENIX ATC 20) , pp. 691–704, 2020
2020
-
[140]
Nvidia trusted computing solutions
T. Computing, “Nvidia trusted computing solutions.” https://docs.n vidia.com/nvtrust/index.html, 2021
2021
-
[141]
Arm trustzone
ARM, “Arm trustzone.” https://www.arm.com/technologies/trustzo ne-for-cortex-a, 2014
2014
-
[142]
Structured sparsity in the nvidia ampere architecture
Nvidia, “Structured sparsity in the nvidia ampere architecture.” https: //developer.nvidia.com/blog/structured-sparsity-in-the-nvidia-amper e-architecture-and-applications-in-search-engines/, 2023
2023
-
[143]
Camouflage: Mem- ory traffic shaping to mitigate timing attacks,
Y . Zhou, S. Wagh, P. Mittal, and D. Wentzlaff, “Camouflage: Mem- ory traffic shaping to mitigate timing attacks,” in 2017 IEEE Inter- national Symposium on High Performance Computer Architecture (HPCA), pp. 337–348, IEEE, 2017
2017
-
[144]
Dagguise: mitigating memory timing side channels,
P. W. Deutsch, Y . Yang, T. Bourgeat, J. Drean, J. S. Emer, and M. Yan, “Dagguise: mitigating memory timing side channels,” in Proceedings of the 27th ACM International Conference on Architec- tural Support for Programming Languages and Operating Systems , pp. 329–343, 2022
2022
-
[145]
Obsidian: Cooperative state-space exploration for performant inference on secure ml accelerators,
S. Banerjee, S. Wei, P. Ramrakhyani, and M. Tiwari, “Obsidian: Cooperative state-space exploration for performant inference on secure ml accelerators,” arXiv preprint arXiv:2409.02817 , 2024
2024 arXiv
-
[146]
Halak, Hardware supply chain security: Threat modelling, emerg- ing attacks and countermeasures
B. Halak, Hardware supply chain security: Threat modelling, emerg- ing attacks and countermeasures . Springer Nature, 2021
2021
-
[147]
{ScatterCache}: thwarting cache attacks via cache set randomization,
M. Werner, T. Unterluggauer, L. Giner, M. Schwarz, D. Gruss, and S. Mangard, “ {ScatterCache}: thwarting cache attacks via cache set randomization,” in 28th USENIX Security Symposium (USENIX Security 19), pp. 675–692, 2019
2019
-
[148]
Phantomcache: Obfuscating cache conflicts with localized randomization.,
Q. Tan, Z. Zeng, K. Bu, and K. Ren, “Phantomcache: Obfuscating cache conflicts with localized randomization.,” in NDSS, 2020
2020
-
[149]
New attacks and defense for encrypted-address cache,
M. K. Qureshi, “New attacks and defense for encrypted-address cache,” in Proceedings of the 46th International Symposium on Computer Architecture, pp. 360–371, 2019
2019
-
[150]
Dawg: A defense against cache timing attacks in speculative exe- cution processors,
V . Kiriansky, I. Lebedev, S. Amarasinghe, S. Devadas, and J. Emer, “Dawg: A defense against cache timing attacks in speculative exe- cution processors,” in 2018 51st Annual IEEE/ACM International Symposium on Microarchitecture (MICRO) , pp. 974–987, IEEE, 2018
2018
-
[151]
Composable cachelets: Protecting enclaves from cache side-channel attacks,
D. Townley, K. Arıkan, Y . D. Liu, D. Ponomarev, and O. Ergin, “Composable cachelets: Protecting enclaves from cache side-channel attacks,” in 31st USENIX Security Symposium (USENIX Security 22), pp. 2839–2856, 2022
2022
-
[152]
Vantage: Scalable and efficient fine-grain cache partitioning,
D. Sanchez and C. Kozyrakis, “Vantage: Scalable and efficient fine-grain cache partitioning,” in Proceedings of the 38th annual international symposium on Computer architecture, pp. 57–68, 2011
2011
-
[153]
Maskednet: The first hardware inference engine aiming power side-channel protection,
A. Dubey, R. Cammarota, and A. Aysu, “Maskednet: The first hardware inference engine aiming power side-channel protection,” in 2020 IEEE International Symposium on Hardware Oriented Security and Trust (HOST) , pp. 197–208, IEEE, 2020
2020
-
[154]
Bomanet: Boolean masking of an entire neural network,
A. Dubey, R. Cammarota, and A. Aysu, “Bomanet: Boolean masking of an entire neural network,” inProceedings of the 39th International Conference on Computer-Aided Design , pp. 1–9, 2020
2020
-
[155]
A quantitative defense framework against power attacks on multi-tenant fpga,
Y . Luo and X. Xu, “A quantitative defense framework against power attacks on multi-tenant fpga,” in Proceedings of the 39th international conference on computer-aided design , pp. 1–9, 2020
2020
-
[156]
Jamming and eavesdropping defense scheme based on deep reinforcement learning in autonomous vehicle networks,
Y . Yao, J. Zhao, Z. Li, X. Cheng, and L. Wu, “Jamming and eavesdropping defense scheme based on deep reinforcement learning in autonomous vehicle networks,”IEEE Transactions on Information Forensics and Security, vol. 18, pp. 1211–1224, 2023
2023
-
[157]
Deepem: Deep neural networks model recovery through em side-channel information leak- age,
H. Yu, H. Ma, K. Yang, Y . Zhao, and Y . Jin, “Deepem: Deep neural networks model recovery through em side-channel information leak- age,” in 2020 IEEE International Symposium on Hardware Oriented Security and Trust (HOST) , pp. 209–218, IEEE, 2020
2020
-
[158]
Eliminating fine grained timers in xen,
B. C. Vattikonda, S. Das, and H. Shacham, “Eliminating fine grained timers in xen,” in Proceedings of the 3rd ACM workshop on Cloud computing security workshop , pp. 41–46, 2011
2011
-
[159]
Timewarp: Rethink- ing timekeeping and performance monitoring mechanisms to mit- igate side-channel attacks,
R. Martin, J. Demme, and S. Sethumadhavan, “Timewarp: Rethink- ing timekeeping and performance monitoring mechanisms to mit- igate side-channel attacks,” ACM SIGARCH computer architecture news, vol. 40, no. 3, pp. 118–129, 2012
2012
-
[160]
Iodine: Verifying constant-time execution of hardware,
K. v. Gleissenthall, R. G. Kıcı, D. Stefan, and R. Jhala, “Iodine: Verifying constant-time execution of hardware,” in 28th USENIX Security Symposium (USENIX Security 19) , pp. 1411–1428, 2019
2019
-
[161]
Small-footprint alu for public-key processors for per- vasive security,
K. Sakiyama, L. Batina, N. Mentens, B. Preneel, and I. Ver- bauwhede, “Small-footprint alu for public-key processors for per- vasive security,” in Workshop on RFID Security , vol. 12, 2006
2006
-
[162]
Aegis: Architecture for tamper-evident and tamper-resistant pro- cessing,
G. E. Suh, D. Clarke, B. Gassend, M. Van Dijk, and S. Devadas, “Aegis: Architecture for tamper-evident and tamper-resistant pro- cessing,” in ACM International Conference on Supercomputing 25th Anniversary Volume, pp. 357–368, 2003
2003
-
[163]
Data operand independent timing isa guidance
“Data operand independent timing isa guidance.” https://www.intel. com/content/www/us/en/developer/articles/technical/software-secur ity-guidance/best-practices/data-operand-independent-timing-isa-g uidance.html
-
[164]
Arm architecture registers for future architecture technologies
“Arm architecture registers for future architecture technologies.” ht tps://developer.arm.com/documentation/ddi0601/2020-12/AArch6 4-Registers/DIT--Data-Independent-Timing
2020
-
[165]
Teesec: Pre-silicon vulnerability discovery for trusted execution environments,
M. Ghaniyoun, K. Barber, Y . Xiao, Y . Zhang, and R. Teodorescu, “Teesec: Pre-silicon vulnerability discovery for trusted execution environments,” in Proceedings of the 50th Annual International Symposium on Computer Architecture , pp. 1–15, 2023
2023
-
[166]
Zipchannel: Cache side-channel vulner- abilities in compression algorithms,
M. Minkin and B. Kasikci, “Zipchannel: Cache side-channel vulner- abilities in compression algorithms,” in2024 54th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN), pp. 223–237, IEEE, 2024
2024
-
[167]
Secureloop: Design space exploration of secure dnn accelerators,
K. Lee, M. Yan, J. Emer, and A. Chandrakasan, “Secureloop: Design space exploration of secure dnn accelerators,” in Proceedings of the 56th Annual IEEE/ACM International Symposium on Microarchitec- ture, pp. 194–208, 2023
2023
-
[168]
Confidential computing deployment guide
C. Computing, “Confidential computing deployment guide.” https: //docs.nvidia.com/cc-deployment-guide-tdx.pdf, 2024
2024
-
[169]
Proflip: Targeted trojan attack with progressive bit flips,
H. Chen, C. Fu, J. Zhao, and F. Koushanfar, “Proflip: Targeted trojan attack with progressive bit flips,” in Proceedings of the IEEE/CVF International Conference on Computer Vision, pp. 7718–7727, 2021
2021
-
[170]
Tbt: Targeted neural network attack with bit trojan,
A. S. Rakin, Z. He, and D. Fan, “Tbt: Targeted neural network attack with bit trojan,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , pp. 13198–13207, 2020
2020
-
[171]
Cve-2023-36189
Mitre, “Cve-2023-36189.” https://cve.mitre.org/cgi-bin/cvename.cgi ?name=CVE-2023-36189, 2023
2023
-
[172]
Timing black-box attacks: Crafting adversarial examples through timing leaks against dnns on embedded devices,
T. Nakai, D. Suzuki, and T. Fujino, “Timing black-box attacks: Crafting adversarial examples through timing leaks against dnns on embedded devices,” IACR Transactions on Cryptographic Hardware and Embedded Systems , pp. 149–175, 2021
2021
-
[173]
Cve-2024-7297
Mitre, “Cve-2024-7297.” https://cve.mitre.org/cgi-bin/cvename.cgi ?name=CVE-2024-7297, 2024
2024
-
[174]
Cve-2024-28224
Mitre, “Cve-2024-28224.” https://cve.mitre.org/cgi-bin/cvename.cgi ?name=CVE-2024-28224, 2024
2024
-
[175]
Understanding contention-based channels and using them for defense,
C. Hunger, M. Kazdagli, A. Rawat, A. Dimakis, S. Vishwanath, and M. Tiwari, “Understanding contention-based channels and using them for defense,” in 2015 IEEE 21st International Symposium on High Performance Computer Architecture (HPCA) , pp. 639–650, IEEE, 2015
2015
-
[176]
Casa: End-to-end quantitative security analysis of randomly mapped caches,
T. Bourgeat, J. Drean, Y . Yang, L. Tsai, J. Emer, and M. Yan, “Casa: End-to-end quantitative security analysis of randomly mapped caches,” in 2020 53rd Annual IEEE/ACM International Symposium on Microarchitecture (MICRO), pp. 1110–1123, IEEE, 2020
2020
-
[177]
Cwe - cwe/capec wgs & sigs
“Cwe - cwe/capec wgs & sigs.” https://cwe.mitre.org/community/ working groups.html#ai wg
-
[178]
Differential privacy,
C. Dwork, “Differential privacy,” in International colloquium on automata, languages, and programming , pp. 1–12, Springer, 2006
2006
-
[179]
Have it your way: Individualized privacy assignment for dp-sgd,
F. Boenisch, C. M ¨uhl, A. Dziedzic, R. Rinberg, and N. Papernot, “Have it your way: Individualized privacy assignment for dp-sgd,” Advances in Neural Information Processing Systems , vol. 36, 2024
2024
-
[180]
Information flow control in machine learning through modular model architecture,
T. Tiwari, S. Gururangan, C. Guo, W. Hua, S. Kariyappa, U. Gupta, W. Xiong, K. Maeng, H.-H. S. Lee, and G. E. Suh, “Information flow control in machine learning through modular model architecture,” in 33rd USENIX Security Symposium (USENIX Security 24), pp. 6921– 6938, 2024
2024
-
[181]
Hyperflow: A processor architecture for nonmalleable, timing-safe information flow security,
A. Ferraiuolo, M. Zhao, A. C. Myers, and G. E. Suh, “Hyperflow: A processor architecture for nonmalleable, timing-safe information flow security,” in Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security , pp. 1583–1600, 2018
2018
-
[182]
Crafting a usable microkernel, processor, and i/o system with strict and provable information flow security,
M. Tiwari, J. K. Oberg, X. Li, J. Valamehr, T. Levin, B. Hardekopf, R. Kastner, F. T. Chong, and T. Sherwood, “Crafting a usable microkernel, processor, and i/o system with strict and provable information flow security,” ACM SIGARCH Computer Architecture News, vol. 39, no. 3, ...
2011
-
[183]
In- tegration verification across software and hardware for a simple embedded system,
A. Erbsen, S. Gruetter, J. Choi, C. Wood, and A. Chlipala, “In- tegration verification across software and hardware for a simple embedded system,” in Proceedings of the 42nd ACM SIGPLAN International Conference on Programming Language Design and Implementation, pp. 604–619, 2021
2021
-
[184]
Private cloud compute: A new frontier for ai privacy in the cloud
Apple, “Private cloud compute: A new frontier for ai privacy in the cloud.” https://security.apple.com/blog/private-cloud-compute/
-
[185]
The confidential genai service
Edgeless, “The confidential genai service.” https://www.edgeless.s ystems/products/continuum
Reviewed August 12, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.