Author = Hajimohammadali, Reyhaneh

Defending CNNs Against Power Side-channel Attacks: A Residue Number System Solution

Volume 18, Issue 3, July 2026, Pages 83-92

https://doi.org/10.22042/isecure.2026.248359

Marzieh Morshedzadeh, Reyhaneh Hajimohammadali, Ali Jahanian

Abstract Neural networks are increasingly used in safety-critical domains such as autonomous driving and medical applications. Their dependence on sensitive parameters, however, makes them attractive targets for adversaries. Among the various existing threats, power side-channel attacks aimed at recovering model parameters are particularly concerning. This work presents a defence mechanism based on the Residue Number System (RNS) to strengthen neural network implementations against such attacks. Security can be improved by carefully selecting computational parameters without sacrificing accuracy. Our experimental results on FPGA hardware with LeNet-5 show up to 3× improvement in resistance to correlation power analysis (CPA) attacks before reverse conversion (RC) and 2× improvement after RC, while preserving classification accuracy. We believe this is the first systematic integration of RNS into convolutional neural network inference on FPGA hardware. While prior modular approaches protect only isolated operations, our method applies RNS arithmetic comprehensively, thereby providing stronger resilience against adversaries.