Defending CNNs Against Power Side-channel Attacks: A Residue Number System Solution

Document Type : Research Article

Authors

Faculty of Computer Science and Engineering, Shahid Beheshti University, Tehran, Iran

10.22042/isecure.2026.248359
Abstract
Neural networks are increasingly used in safety-critical domains such as autonomous driving and medical applications. Their dependence on sensitive parameters, however, makes them attractive targets for adversaries. Among the various existing threats, power side-channel attacks aimed at recovering model parameters are particularly concerning. This work presents a defence mechanism based on the Residue Number System (RNS) to strengthen neural network implementations against such attacks. Security can be improved by carefully selecting computational parameters without sacrificing accuracy. Our experimental results on FPGA hardware with LeNet-5 show up to 3× improvement in resistance to correlation power analysis (CPA) attacks before reverse conversion (RC) and 2× improvement after RC, while preserving classification accuracy. We believe this is the first systematic integration of RNS into convolutional neural network inference on FPGA hardware. While prior modular approaches protect only isolated operations, our method applies RNS arithmetic comprehensively, thereby providing stronger resilience against adversaries.

Keywords


[1] V. Sze, Y.-H. Chen, T.-J. Yang, and J. S. Emer, Efficient processing of deep neural networks: a tutorial and survey, Proc. IEEE, vol. 105, no. 12, pp. 2295–2329, 2017.
[2] W. Samek, G. Montavon, S. Lapuschkin, C. J. Anders, and K. R. Müller, Explaining deep neural networks and beyond: a review of methods and applications, Proc. IEEE, vol. 109, no. 3, pp. 247–278, 2021.
[3] M. Isakov, V. Gadepally, K. M. Gettings, and M. A. Kinsy, Survey of attacks and defenses on edge-deployed neural networks, in Proc. IEEE HPEC, 2019, pp. 1–8.
[4] A. Michel, S. K. Gha, and R. Ewetz, A survey on the vulnerability of deep neural networks against adversarial attacks, Prog. Artif. Intell., 2022, pp. 1–11.
[5] S. Almutairi and A. Barnawi, Securing DNN for smart vehicles: an overview of adversarial attacks, defenses, and frameworks, J. Eng. Appl. Sci., vol. 70, pp. 1–29, 2023.
[6] A. Demontis, M. Melis, M. Pintor, M. Jagielski, B. Biggio, A. Oprea, C. Nita-Rotaru, and F. Roli, Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks, in Proc. USENIX Security Symp., 2019.
[7] F. Tramer, F. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart, Stealing machine learning models via prediction APIs, in Proc. USENIX Security Symp., 2016.
[8] G. Apruzzese, A. S. Anderson, S. Dambra, D. Freeman, F. Pierazzi, and K. Roundy, Real attackers don’t compute gradients: bridging the gap between adversarial ML research and practice, in Proc. IEEE SATML, 2023, pp. 339–364.
[9] S. Mendez Real, Physical side-channel attacks on embedded neural networks: a survey, Appl. Sci., 2021, pp. 310–316.
[10] H. Chabanne, J.-L. Danger, L. Guiga, and U. Kuhne, Side-channel attacks for architecture extraction of neural networks, CAAI Trans. Intell. Technol., vol. 6, no. 1, pp. 3–16, 2021.
[11] A. Dubey, R. Cammarota, V. Suresh, and A. Aysu, Guarding machine learning hardware against physical side-channel attacks, CoRR, vol. abs/2109.00187, 2021.
[12] K. Ganesan, M. Fishkin, O. Lin, and N. E. Jerger, Blackjack: secure machine learning on IoT devices through hardware-based shuffling, arXiv preprint, arXiv:2310.17804, 2023.
[13] X. Liu, L. Xie, Y. Wang, J. Zou, J. Xiong, Z. Ying, and A. V. Vasilakos, Privacy and security issues in deep learning: a survey, IEEE Access, vol. 9, pp. 4566–4593, 2021.
[14] J. Krautter and M. B. Tahoori, Neural networks asaside-channel counter measure: challenges and opportunities, in Proc. IEEE ISVLSI, 2021, pp. 272–277.
[15] M. Brosch, M. Probst, and G. Sigl, Counteract side-channel analysis of neural networks by shuffling, in Proc. DATE, 2022.
[16] T. D. Cnudde, M. Ender, and A. Moradi, Hardware masking revisited, TCHES, 2018.
[17] M. M. Ahmadi, L. Alrahis, O. Sinanoglu, and M. Shafique, DNN-alias: deep neural network protection against side-channel attacks via layer balancing, arXiv preprint, arXiv:2303.06746, 2023.
[18] J. Li, Z. He, A. S. Rakin, D. Fan, and C. Chakrabarti, Neurobfuscator: a full-stack obfuscation tool to mitigate neural architecture stealing, in Proc. IEEE HOST, 2021.
[19] R. P. Mcevoy, C. C. Murphy, et al., Isolated WDDL: a hiding countermeasure for differential power analysis on FPGAs, TRETS, 2009.
[20] Z. He, A. S. Rakin, and D. Fan, Parametric noise injection: trainable randomness to improve deep neural network robustness against adversarial attack, in Proc. CVPR, 2019, pp. 588–597.
[21] T. Schneider, A. Moradi, and T. Guneysu, Arithmetic addition over boolean masking towards first- and second-order resistance in hardware, Horst Gortz Institute for IT Security, Germany, 2015.
[22] R. Selvamand, A. Tyagi, Residue number system (RNS) and power distribution network topology based mitigation of power side-channel attacks, Cryptography, vol. 8, no. 1, p. 1, 2023.
[23] A. T.-S. R. Selvam, An evaluation of power sidechannel resistance for RNS secure logic, Sensors, vol. 22, no. 1, 2022.
[24] A. Dubey, A. Ahmad, M. A. Pasha, R. Cammarota, and A. Aysu, Modulonet: neural networks meet modular arithmetic for efficient hardware masking, IACR TCHES, 2022, pp. 506–556.
[25] A. Dubey, R. Cammarota, and A. Aysu, MaskedNet: the first hardware inference engine aiming power side-channel protection, in Proc. IEEE HOST, 2020.
[26] P. C. Kocher, J. Jaffe, and B. Jun, Differential power analysis: leaking secrets, in Proc. Crypto, 1999, pp. 388–397.
[27] M. Randolph and W. Diehl, Power side-channel attack analysis: a review of 20 years of study for the layman, Cryptography, vol. 4, no. 2, p. 15, 2020.
[28] K. Gandolfi, C. Mourtel, and F. Olivier, Electromagnetic analysis: concrete results, in Proc. CHES, Springer, 2001, pp. 251–261.
[29] S. Mangard, E. Oswald, and T. Popp, Power analysis attacks: revealing the secrets of smart cards, Springer, 2008.
[30] J. Mishra and S. K. Sahay, Modern hardware security: a review of attacks and countermeasures, arXiv preprint, arXiv:2501.04394, 2025.
[31] S. Potluriand, F. Koushanfar, SoK: model reverse engineering threats for neural network hardware, Cryptology ePrint Archive, Paper 2024/913.
[32] A. Yuan, G. Bai, L. Jiao, and Y. Liu, Offline handwritten English character recognition based on convolutional neural network, in Proc. IEEE DAS, 2012, pp. 125–129.
[33] Y. Xiang, Z. Chen, Z. Fang, H. Hao, J. Chen, Y. Liu, Z. Wu, Q. Xuan, and X. Yang, Open DNN box by power side-channel attack, IEEE Trans. Circuits Syst. II, 2020.
[34] A. A. Oke, B. A. Nathaniel, B. F. Bukola, and O. A. Ayopo, Residue number system based applications: a literature review, 2021.
[35] J. Peng, Y. Alkabani, S. Sun, V. J. Sorger, and T. El-Ghazawi, DNNARA: a deep neural network accelerator using residue arithmetic and integrated photonics, in Proc. ICPP, 2020.
[36] A. Babatunde, B. F. Balogun, A. O. Lawal, et al., Application of residue number system in information security: a systematic review, SLU J. Sci. Technol., vol. 11, pp. 195–219, 2025.
[37] Q. Xu, M. T. Arafin, and G. Qu, Security of neural networks from hardware perspective: a survey and beyond, in Proc. IEEE ASP-DAC, 2021, pp. 449–454.
[38] N. Singh, An overview of residue number system,inProc.Nat.SeminarDevices,Circuitsand Communication, Nov. 2008.