[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83773-en":3,"doc-seo-83773-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83773,137441390410,"Hazel","https://ap-avatar.wpscdn.com/avatar/2000252f4ab5702993?_k=1776741390130283984",8,"Research & Report","Securing Deep Learning Hardware: A Survey of Side-Channel Vulnerabilities and Countermeasures","Deep learning models deployed in healthcare, finance, and security require protection against emerging threats, especially side-channel attacks that recover sensitive information without direct model access. Attackers exploit physical and micro-architectural behaviors of CPUs, GPUs, FPGAs, and accelerators to infer architectures, parameters, and even user inputs. This survey classifies leakage sources and attacker objectives, reviews representative practical exploit studies, and evaluates existing defenses while highlighting key open research challenges and future directions.","arXiv :2607 .04055v 1 [ cs .CR] 4 Jul 2026  \n\n| The ISC Int'l Journal of Information Security\u003Cbr>ISeCure\u003Cbr> | Manuscript template of ISeCure Journal (pp. 1–17)\u003Cbr>[http://www.isecure-journal.org](http://www.isecure-journal.org) |\n| --- | --- |\n| Securing Deep Learning Hardware: A Survey of Side-Channel Vulnerabilities and Countermeasures\u003Cbr>Zahra Mohammadi 1 , Mona Hashemi 1 , and Siamak Mohammadi 1 , ∗\u003Cbr>1 School of Electrical and Computer Engineering, University of Tehran, Tehran, Iran |  |\n\nA R T I C L E I N F O.  \nKeywords:  \nSide-Channel Attacks, Deep Learning Models, Model Reverse Engineering, Intellectual Property, Side-Channel Protection, Model Security  \nAbstract  \nAs deep learning models are increasingly deployed in critical sectors such as healthcare, finance, and security, ensuring their protection against emerging threats has become crucial. Among these threats, side-channel attacks (SCAs) represent a particular challenge since they can extract sensitive information such as model architectures, parameters, and even user inputs without requiring direct access to the model. By leveraging the physical and micro-architectural properties of the hardware, attackers can compromise systems. This survey begins by classifying leakage sources and attacker objectives, then analyzes representative studies that demonstrate practical side-channel exploits against deep-learning hardware. It also reviews existing defenses aimed at mitigating these vulnerabilities and concludes by outlining key open research challengesand potential future directions.  \n© 2025 ISC. All rights reserved.  \n1 Introduction  \nDeep learning models have become fundamental toa wide array of modern applications, including cloud computing, mobile platforms, Internet of Things (IoT) devices, and critical infrastructure. Their exceptional accuracy and performance have led to widespread deployment across both data centers and resourceconstrained edge devices. However, the underlying hardware used to run these models such as Central Processing Units (CPUs), Graphics Processing Units (GPUs), Field-Programmable Gate Arrays (FPGAs), and custom accelerators can unintentionally expose sensitive information through physical and microarchitectural side channels.  \nSide-channel leakages, such as power consumption, memory access patterns, timing differences, and elec-  \n∗ Corresponding author.  \nEmail addresses: [zahramohammmadi@ut.ac.ir](zahramohammmadi@ut.ac.ir), [Hashemi.mona@ut.ac.ir](Hashemi.mona@ut.ac.ir), [smohamadi@ut.ac.ir](smohamadi@ut.ac.ir)[ ](smohamadi@ut.ac.ir)[ISSN: 2008-2045](ISSN: 2008-2045) © 2025 ISC. All rights reserved.  \ntromagnetic (EM) emissions, can be exploited by adversaries to extract critical model information. These include architecture details, model parameters, or even private user inputs [1–3] . Such attacks do not rely on software vulnerabilities but instead observe and analyze low-level physical behaviors of hardware during model execution.  \nThis survey provides a comprehensive overview of the landscape of hardware side-channel vulnerabilities in deep learning models. We present a structured taxonomy of SCAs, analyze representative attack techniques, and review defensive strategies developed to mitigate these threats. By categorizing attacks based on leakage sources, attacker capabilities, and objectives, this paper aims to shed light on the emerging security challenges and motivate the development of more resilient machine learning hardware systems.  \n ISeCure  \n2  \n1.1 Deep Learning Model as Intellectual Property (IP)  \nModern deep learning models represent far more than simple lines of code—they are valuable forms of IP, developed through extended efforts involving expert engineering, costly training procedures, and often the use of proprietary datasets. Constructing a competitive model typically requires large-scale data collection and annotation, careful design of neural network architectures, and thorough hyperparameter tuning. ","cbCaihmR55SCS3Zw","https://ap.wps.com/l/cbCaihmR55SCS3Zw","pdf",5118618,4,1,17,"English","en",105,"# Introduction\n## Deep Learning Model as Intellectual Property (IP)\n## Threat Landscape for Deep Learning Hardware","[{\"question\":\"Why are side-channel attacks a serious threat to deep learning hardware?\",\"answer\":\"Side-channel attacks can extract sensitive information such as model architectures, parameters, and user inputs by observing physical and micro-architectural behaviors of the hardware during inference or execution.\"},{\"question\":\"What leakage signals are commonly targeted in hardware side-channel attacks?\",\"answer\":\"Attackers may exploit power consumption, memory access patterns, timing differences, and electromagnetic (EM) emissions to infer critical model information.\"},{\"question\":\"How does the survey organize its coverage of side-channel vulnerabilities and defenses?\",\"answer\":\"The survey classifies leakage sources and attacker objectives, analyzes representative studies demonstrating practical exploits, reviews existing defensive strategies, and closes by outlining open research challenges and future directions.\"}]",1784190327,43,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"securing-deep-learning-hardware-a-survey-of-side-channel-vulnerabilities-and-countermeasures","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/securing-deep-learning-hardware-a-survey-of-side-channel-vulnerabilities-and-countermeasures/83773/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-26","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why are side-channel attacks a serious threat to deep learning hardware?","Question",{"text":75,"@type":76},"Side-channel attacks can extract sensitive information such as model architectures, parameters, and user inputs by observing physical and micro-architectural behaviors of the hardware during inference or execution.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What leakage signals are commonly targeted in hardware side-channel attacks?",{"text":80,"@type":76},"Attackers may exploit power consumption, memory access patterns, timing differences, and electromagnetic (EM) emissions to infer critical model information.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the survey organize its coverage of side-channel vulnerabilities and defenses?",{"text":84,"@type":76},"The survey classifies leakage sources and attacker objectives, analyzes representative studies demonstrating practical exploits, reviews existing defensive strategies, and closes by outlining open research challenges and future directions.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]