边缘智能模型的电磁侧信道泄露风险评估
网络出版日期: 2026-04-01
基金资助
国家自然科学基金(U24A20240)
版权
Evaluating electromagnetic side-channel leaks in edge intelligence models
Online published: 2026-04-01
Copyright
边缘智能设备在物联网与安防等场景中广泛应用,其深度学习模型易遭受电磁侧信道攻击。为量化评估模型在此类攻击下的信息泄露情况,构建分层次风险评估框架,从模型家族、层级结构和核心参数3个维度开展分析。结合时频域特征与随机森林算法实现模型家族识别,利用功耗迹线的时序模式与长短期记忆网络完成层级结构及核心参数的自动化推断,并建立信息泄露量化指标以衡量泄露程度。在真实边缘智能设备上,选取9类典型深度学习模型开展实验验证。结果表明,模型家族分类的平均F1分数达95.7%,层级结构恢复精度约93.8%,核心参数识别精度超过90%。研究证实,电磁侧信道可泄露模型多层次信息,且识别精度较高,足以支撑模型克隆及后续攻击行为。该研究为边缘智能设备的侧信道风险认知与防护方案设计提供了量化依据。
赵怡航 , 宋祁朋 , 刘晓剑 , 李玥 , 曹进 . 边缘智能模型的电磁侧信道泄露风险评估[J]. 网络空间安全科学学报, 2025 , 3(5) : 23 -37 . DOI: 10.20172/j.issn.2097-3136.250503
Edge intelligence devices are widely deployed in the Internet of Things (IoT) and security scenarios, but their deep learning models are vulnerable to electromagnetic side-channel attacks. To quantitatively assess the information leakage of such models under these attacks, a hierarchical risk evaluation framework is proposed, which is analyzed from three dimensions: model family, layer structure, and core parameters. Model family identification is achieved by combining time-frequency features with a random forest algorithm, while the automatic inference of layer structure and core parameters is realized by using the temporal patterns of power traces and a Long Short-Term Memory (LSTM) network. Quantitative indicators are established to measure the information leakage degree. Experiments are conducted on real edge intelligence devices with nine typical deep learning models. The results show that the average F1-score for model family classification reaches 95.7%, the reconstruction accuracy of layer structure is about 93.8%, and the identification accuracy of core parameters exceeds 90%. This study confirms that electromagnetic side channels can leak multi-level model information with high accuracy, and such information is sufficient to support model cloning and subsequent attacks. It provides a quantitative basis for understanding side-channel risks and designing protection schemes for edge intelligence devices.
表 1 本文评估框架与代表性方法研究维度对比Table 1 Comparison of evaluation framework and research dimensions for typical methods |
表 2 侧信道威胁模型能力与知识分类Table 2 Threat model capabilities and knowledge classification in side-channel analysis |
| 类型 | 编号 | 描述 | 本文具备能力 |
| 通用能力 | G1 | 物理接近硬件设备,且该设备 未实施任何防护措施 | √ |
| G2 | 收集和分析功耗和电磁迹线的能力 | √ | |
| G3 | 攻击者拥有一台与目标设备 完全相同的分析设备 | √ | |
| 特定能力 | I1 | 输入维度 | √ |
| I2 | 模型架构 | × | |
| I3 | 模型中使用的参数 | × | |
| A1 | 输入维度和数值(架构) | × | |
| P1 | 输入维度和数值(参数) | × | |
| P2 | 架构 | × | |
| P3 | 目标设备的硬件设计 | × |
表 3 数学符号释义Table 3 Glossary of mathematical symbols |
| 符号 | 说明 |
| 模型家族暴露风险 | |
| 层级结构泄露风险 | |
| 核心参数泄露风险 | |
| 预测的层类型序列与真实的层类型序列 | |
| 编辑距离,用于衡量两个序列的差异 | |
| 预测的核心参数集合与真实的核心参数集合 | |
| 高斯平滑处理后的数据点与原始序列中的邻近点 | |
| 高斯滤波器的窗口大小 | |
| 高斯函数 | |
| 标准差,决定高斯平滑的程度 | |
| 卷积层的核心参数:卷积核大小、数量、步长、填充 | |
| 分别表示池化层的核大小及全连接层的神经元数量 |
表 5 模型家族暴露风险评估结果Table 5 Results of the model family exposure risk assessment |
| 模型类型 | 精确率 | 召回率 | F1分数 |
| AlexNet | 99.1% | 98.9% | 99.00% |
| DenseNet | 99.3% | 99.1% | 99.20% |
| Inception | 98.0% | 99.5% | 98.74% |
| MobileNet | 96.2% | 96.2% | 96.20% |
| ResNet | 98.7% | 98.2% | 98.45% |
| ShuffleNet | 96.6% | 96.3% | 96.45% |
| SqueezeNet | 96.5% | 82.3% | 88.84% |
| VGGNet | 96.1% | 83.6% | 89.42% |
| YOLO | 95.2% | 93.4% | 94.29% |
| 1 |
李肯立, 刘楚波. 边缘智能: 现状和展望[J]. 大数据, 2019, 5 (3): 69- 75.
Li K L, Liu C B. Edge intelligence: state-of-the-art and expectations[J]. Big Data Research, 2019, 5 (3): 69- 75.
|
| 2 |
Zhang Y, Yasaei R, Chen H, et al. Stealing neural network structure through remote FPGA side-channel analysis[J]. IEEE Transactions on Information Forensics and Security, 2021, 16, 4377- 4388.
|
| 3 |
Méndez Real M, Salvador R. Physical side-channel attacks on embedded neural networks: a survey[J]. Applied Sciences, 2021, 11 (15): 6790.
|
| 4 |
王永娟, 樊昊鹏, 代政一, 等. 侧信道攻击与防御技术研究进展[J]. 计算机学报, 2023, 46 (1): 202- 228.
Wang Y J, Fan H P, Dai Z Y, et al. Advances in side channel attacks and countermeasures[J]. Chinese Journal of Computers, 2023, 46 (1): 202- 228.
|
| 5 |
Batina L, Bhasin S, Jap D, et al. {CSI}{NN}: Reverse engineering of neural network architectures through electromagnetic side channel[C]//28th USENIX Security Symposium (USENIX Security 19). 2019: 515-532.
|
| 6 |
Naghibijouybari H, Neupane A, Qian Z Y, et al. Rendered insecure: GPU side channel attacks are practical[C]//Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM, 2018: 2139-2153.
|
| 7 |
Yan M, Fletcher C W, Torrellas J. Cache telepathy: Leveraging shared resource attacks to learn {DNN} architectures[C]//29th USENIX Security Symposium (USENIX Security 20). 2020: 2003-2020.
|
| 8 |
Yu H G, Ma H C, Yang K C, et al. DeepEM: deep neural networks model recovery through EM side-channel information leakage[C]//Proceedings of the 2020 IEEE International Symposium on Hardware Oriented Security and Trust (HOST). Piscataway: IEEE Press, 2020: 209-218.
|
| 9 |
Joud R, Moëllic P A, Pontié S, et al. Like an open book? read neural network architecture with simple power analysis on 32-bit microcontrollers[M]. Smart Card Research and Advanced Applications. ChamSpringer Nature Switzerland. 2024: 256-276.
|
| 10 |
Cheng G Y, Luo Y K, Xu X L, et al. Side-channel-assisted reverse-engineering of encrypted DNN hardware accelerator IP and attack surface exploration[C]//Proceedings of the 2024 IEEE Symposium on Security and Privacy (SP). Piscataway: IEEE Press, 2024: 4678-4695.
|
| 11 |
Liang S S, Zhan Z H, Yao F, et al. Clairvoyance: exploiting far-field EM emanations of GPU to see your DNN models through obstacles at a distance[C]//Proceedings of the 2022 IEEE Security and Privacy Workshops (SPW). Piscataway: IEEE Press, 2022: 312-322.
|
| 12 |
Maia H T, Xiao C, Li D, et al. Can one hear the shape of a neural network: Snooping the GPU via magnetic side channel[C]//USENIX Security Symposium, 2022: 4383-4400.
|
| 13 |
Biron P V. Backpropagation: theory, architectures, and applications[J]. Journal of the American Society for Information Science, 1997, 48 (1): 88- 89.
|
| 14 |
Khater A H, Malfliet W, Callebaut D K, et al. The tanh method, a simple transformation and exact analytical solutions for nonlinear reaction–diffusion equations[J]. Chaos, Solitons & Fractals, 2002, 14(3): 513-522.
|
| 15 |
Glorot X, Bordes A, Bengio Y. Deep sparse rectifier neural networks[C]//Proceedings of the Fourteenth International Conference on Artificial Intelligence and Statistics. JMLR Workshop and Conference Proceedings, 2011: 315-323.
|
| 16 |
Hinton G E, Salakhutdinov R R. Replicated softmax: an undirected topic model[J]. Advances in Neural Information Processing Systems, 2009, 22, 1607- 1614.
|
| 17 |
Yoshida K, Kubota T, Okura S, et al. Model reverse-engineering attack using correlation power analysis against systolic array based neural network accelerator[C]//Proceedings of the 2020 IEEE International Symposium on Circuits and Systems (ISCAS). Piscataway: IEEE Press, 2020: 1-5.
|
| 18 |
Yoshida K, Shiozaki M, Okura S, et al. Model reverse-engineering attack against systolic-array-based DNN accelerator using correlation power analysis[J]. IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences, 2021, 104(1): 152-161.
|
| 19 |
Li G, Tiwari M, Orshansky M. Power-based attacks on spatial DNN accelerators[J]. ACM Journal on Emerging Technologies in Computing Systems, 2022, 18 (3): 1- 18.
|
| 20 |
Horvath P, Chmielewski L M, Weissbart L J A, et al. BarraCUDA: GPUs do leak DNN weights[J]. IEEE Symposium on Security and Privacy, 2025: 1-18.
|
| 21 |
Joud R, Moëllic P A, Pontié S, et al. A practical introduction to Side-channel extraction of Deep neural network parameters[C]//Smart Card Research and Advanced Applications. Cham: Springer, 2023: 45-65.
|
| 22 |
Maji S, Banerjee U, Chandrakasan A P. Leaky nets: Recovering embedded neural network models and inputs through simple power and timing side-channels—Attacks and defenses[J]. IEEE Internet of Things Journal, 2021, 8 (15): 12079- 12092.
|
| 23 |
Patwari K, Hafiz S M, Wang H, et al. DNN model architecture fingerprinting attack on CPU-GPU edge devices[C]//Proceedings of the 2022 IEEE 7th European Symposium on Security and Privacy (EuroS&P). Piscataway: IEEE Press, 2022: 337-355.
|
| 24 |
Hu X, Liang L, Li S C, et al. DeepSniffer: a DNN model extraction framework based on learning architectural hints[C]//Proceedings of the Twenty-Fifth International Conference on Architectural Support for Programming Languages and Operating Systems. New York: ACM, 2020: 385-399.
|
| 25 |
Horváth P, Lauret D, Liu Z, et al. SoK: neural network extraction through physical side channels[C]//USENIX Security Symposium. USENIX Association, 2024: 3215-3234.
|
| 26 |
Grecco H E, Dartiailh M C, Thalhammer-thurner G, et al. PyVISA: the Python instrumentation package[J]. Journal of Open Source Software, 2023, 8 (84): 5304.
|
| 27 |
Takatoi G, Sugawara T, Sakiyama K, et al. Simple electromagnetic analysis against activation functions of deep neural networks[C]//Applied Cryptography and Network Security Workshops. Cham: Springer, 2020: 181-197.
|
| 28 |
Edelsbrunner H, Guibas L J, Sharir M. The upper envelope of piecewise linear functions: Algorithms and applications[J]. Discrete & Computational Geometry, 1989, 4 (4): 311- 336.
|
| 29 |
Lim J S. Two-dimensional signal and image processing[M]. Upper Saddle River, N J: Prentice Hall, 1990.
|
| 30 |
Graves A, Fernández S, Gomez F, et al. Connectionist temporal classification: labelling unsegmented sequence data with recurrent neural networks[C]//Proceedings of the 23rd international conference on Machine learning. 2006: 369-376.
|
| 31 |
Graves A, Jaitly N. Towards end-to-end speech recognition with recurrent neural networks[C]//Proceedings of the 31st International Conference on International Conference on Machine Learning. New York: ACM, 2014: 1764-1772.
|
| 32 |
Ma J, Mabrouk H, Xu J, et al. NNoM: v0.4. 3[DS/OL]. Zenodo, 2021. [2025-10-11]. https://doi.org/10.5281/zenodo.1234567.
|
/
| 〈 |
|
〉 |