{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:WPUT7Z26737HE3ZRFRDQDCBWGD","short_pith_number":"pith:WPUT7Z26","schema_version":"1.0","canonical_sha256":"b3e93fe75efefe726f312c4701883630daf8d4add5e34abf518ef416354d14ad","source":{"kind":"arxiv","id":"2302.01474","version":2},"attestation_state":"computed","paper":{"title":"Defensive ML: Defending Architectural Side-channels with Adversarial Obfuscation","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AR","cs.LG"],"primary_cat":"cs.CR","authors_text":"Bo Li, Hyoungwook Nam, Josep Torrellas, Nam Sung Kim, Raghavendra Pradyumna Pothukuchi","submitted_at":"2023-02-03T00:41:01Z","abstract_excerpt":"Side-channel attacks that use machine learning (ML) for signal analysis have become prominent threats to computer security, as ML models easily find patterns in signals. To address this problem, this paper explores using Adversarial Machine Learning (AML) methods as a defense at the computer architecture layer to obfuscate side channels. We call this approach Defensive ML, and the generator to obfuscate signals, defender. Defensive ML is a workflow to design, implement, train, and deploy defenders for different environments. First, we design a defender architecture given the physical character"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2302.01474","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2023-02-03T00:41:01Z","cross_cats_sorted":["cs.AR","cs.LG"],"title_canon_sha256":"b8991adfa2a5acbd5eda25f0053eeceecb78c283bb5833fbbbf5ae84028c4073","abstract_canon_sha256":"c4200d2b9c32651a2a41e7152a6c94c091a64fa3dd2e668665237efd10b4dab7"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:00:43.846559Z","signature_b64":"y9QIICvj017szktl4gUt4rBnWKjYD2Mpn2hoOEEwAnMlmEpsQY4RpCkhBPmiSag3ukg09Lq1cxG4Zi8GpGpNCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b3e93fe75efefe726f312c4701883630daf8d4add5e34abf518ef416354d14ad","last_reissued_at":"2026-07-05T07:00:43.846018Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:00:43.846018Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Defensive ML: Defending Architectural Side-channels with Adversarial Obfuscation","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AR","cs.LG"],"primary_cat":"cs.CR","authors_text":"Bo Li, Hyoungwook Nam, Josep Torrellas, Nam Sung Kim, Raghavendra Pradyumna Pothukuchi","submitted_at":"2023-02-03T00:41:01Z","abstract_excerpt":"Side-channel attacks that use machine learning (ML) for signal analysis have become prominent threats to computer security, as ML models easily find patterns in signals. To address this problem, this paper explores using Adversarial Machine Learning (AML) methods as a defense at the computer architecture layer to obfuscate side channels. We call this approach Defensive ML, and the generator to obfuscate signals, defender. Defensive ML is a workflow to design, implement, train, and deploy defenders for different environments. First, we design a defender architecture given the physical character"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2302.01474","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2302.01474/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2302.01474","created_at":"2026-07-05T07:00:43.846083+00:00"},{"alias_kind":"arxiv_version","alias_value":"2302.01474v2","created_at":"2026-07-05T07:00:43.846083+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2302.01474","created_at":"2026-07-05T07:00:43.846083+00:00"},{"alias_kind":"pith_short_12","alias_value":"WPUT7Z26737H","created_at":"2026-07-05T07:00:43.846083+00:00"},{"alias_kind":"pith_short_16","alias_value":"WPUT7Z26737HE3ZR","created_at":"2026-07-05T07:00:43.846083+00:00"},{"alias_kind":"pith_short_8","alias_value":"WPUT7Z26","created_at":"2026-07-05T07:00:43.846083+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.23640","citing_title":"CachePrune: Privacy-Aware and Fine-Grained KV Cache Sharing for Efficient LLM Inference","ref_index":34,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/WPUT7Z26737HE3ZRFRDQDCBWGD","json":"https://pith.science/pith/WPUT7Z26737HE3ZRFRDQDCBWGD.json","graph_json":"https://pith.science/api/pith-number/WPUT7Z26737HE3ZRFRDQDCBWGD/graph.json","events_json":"https://pith.science/api/pith-number/WPUT7Z26737HE3ZRFRDQDCBWGD/events.json","paper":"https://pith.science/paper/WPUT7Z26"},"agent_actions":{"view_html":"https://pith.science/pith/WPUT7Z26737HE3ZRFRDQDCBWGD","download_json":"https://pith.science/pith/WPUT7Z26737HE3ZRFRDQDCBWGD.json","view_paper":"https://pith.science/paper/WPUT7Z26","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2302.01474&json=true","fetch_graph":"https://pith.science/api/pith-number/WPUT7Z26737HE3ZRFRDQDCBWGD/graph.json","fetch_events":"https://pith.science/api/pith-number/WPUT7Z26737HE3ZRFRDQDCBWGD/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/WPUT7Z26737HE3ZRFRDQDCBWGD/action/timestamp_anchor","attest_storage":"https://pith.science/pith/WPUT7Z26737HE3ZRFRDQDCBWGD/action/storage_attestation","attest_author":"https://pith.science/pith/WPUT7Z26737HE3ZRFRDQDCBWGD/action/author_attestation","sign_citation":"https://pith.science/pith/WPUT7Z26737HE3ZRFRDQDCBWGD/action/citation_signature","submit_replication":"https://pith.science/pith/WPUT7Z26737HE3ZRFRDQDCBWGD/action/replication_record"}},"created_at":"2026-07-05T07:00:43.846083+00:00","updated_at":"2026-07-05T07:00:43.846083+00:00"}