Evaluating electromagnetic side-channel leaks in edge intelligence models
Online published: 2026-04-01
Copyright
Edge intelligence devices are widely deployed in the Internet of Things (IoT) and security scenarios, but their deep learning models are vulnerable to electromagnetic side-channel attacks. To quantitatively assess the information leakage of such models under these attacks, a hierarchical risk evaluation framework is proposed, which is analyzed from three dimensions: model family, layer structure, and core parameters. Model family identification is achieved by combining time-frequency features with a random forest algorithm, while the automatic inference of layer structure and core parameters is realized by using the temporal patterns of power traces and a Long Short-Term Memory (LSTM) network. Quantitative indicators are established to measure the information leakage degree. Experiments are conducted on real edge intelligence devices with nine typical deep learning models. The results show that the average F1-score for model family classification reaches 95.7%, the reconstruction accuracy of layer structure is about 93.8%, and the identification accuracy of core parameters exceeds 90%. This study confirms that electromagnetic side channels can leak multi-level model information with high accuracy, and such information is sufficient to support model cloning and subsequent attacks. It provides a quantitative basis for understanding side-channel risks and designing protection schemes for edge intelligence devices.
Zhao Yihang , Song Qipeng , Liu Xiaojian , Li Yue , Cao Jin . Evaluating electromagnetic side-channel leaks in edge intelligence models[J]. Journal of Cybersecurity, 2025 , 3(5) : 23 -37 . DOI: 10.20172/j.issn.2097-3136.250503
表 1 本文评估框架与代表性方法研究维度对比Table 1 Comparison of evaluation framework and research dimensions for typical methods |
表 2 侧信道威胁模型能力与知识分类Table 2 Threat model capabilities and knowledge classification in side-channel analysis |
| 类型 | 编号 | 描述 | 本文具备能力 |
| 通用能力 | G1 | 物理接近硬件设备,且该设备 未实施任何防护措施 | √ |
| G2 | 收集和分析功耗和电磁迹线的能力 | √ | |
| G3 | 攻击者拥有一台与目标设备 完全相同的分析设备 | √ | |
| 特定能力 | I1 | 输入维度 | √ |
| I2 | 模型架构 | × | |
| I3 | 模型中使用的参数 | × | |
| A1 | 输入维度和数值(架构) | × | |
| P1 | 输入维度和数值(参数) | × | |
| P2 | 架构 | × | |
| P3 | 目标设备的硬件设计 | × |
表 3 数学符号释义Table 3 Glossary of mathematical symbols |
| 符号 | 说明 |
| 模型家族暴露风险 | |
| 层级结构泄露风险 | |
| 核心参数泄露风险 | |
| 预测的层类型序列与真实的层类型序列 | |
| 编辑距离,用于衡量两个序列的差异 | |
| 预测的核心参数集合与真实的核心参数集合 | |
| 高斯平滑处理后的数据点与原始序列中的邻近点 | |
| 高斯滤波器的窗口大小 | |
| 高斯函数 | |
| 标准差,决定高斯平滑的程度 | |
| 卷积层的核心参数:卷积核大小、数量、步长、填充 | |
| 分别表示池化层的核大小及全连接层的神经元数量 |
表 5 模型家族暴露风险评估结果Table 5 Results of the model family exposure risk assessment |
| 模型类型 | 精确率 | 召回率 | F1分数 |
| AlexNet | 99.1% | 98.9% | 99.00% |
| DenseNet | 99.3% | 99.1% | 99.20% |
| Inception | 98.0% | 99.5% | 98.74% |
| MobileNet | 96.2% | 96.2% | 96.20% |
| ResNet | 98.7% | 98.2% | 98.45% |
| ShuffleNet | 96.6% | 96.3% | 96.45% |
| SqueezeNet | 96.5% | 82.3% | 88.84% |
| VGGNet | 96.1% | 83.6% | 89.42% |
| YOLO | 95.2% | 93.4% | 94.29% |
| 1 |
李肯立, 刘楚波. 边缘智能: 现状和展望[J]. 大数据, 2019, 5 (3): 69- 75.
Li K L, Liu C B. Edge intelligence: state-of-the-art and expectations[J]. Big Data Research, 2019, 5 (3): 69- 75.
|
| 2 |
Zhang Y, Yasaei R, Chen H, et al. Stealing neural network structure through remote FPGA side-channel analysis[J]. IEEE Transactions on Information Forensics and Security, 2021, 16, 4377- 4388.
|
| 3 |
Méndez Real M, Salvador R. Physical side-channel attacks on embedded neural networks: a survey[J]. Applied Sciences, 2021, 11 (15): 6790.
|
| 4 |
王永娟, 樊昊鹏, 代政一, 等. 侧信道攻击与防御技术研究进展[J]. 计算机学报, 2023, 46 (1): 202- 228.
Wang Y J, Fan H P, Dai Z Y, et al. Advances in side channel attacks and countermeasures[J]. Chinese Journal of Computers, 2023, 46 (1): 202- 228.
|
| 5 |
Batina L, Bhasin S, Jap D, et al. {CSI}{NN}: Reverse engineering of neural network architectures through electromagnetic side channel[C]//28th USENIX Security Symposium (USENIX Security 19). 2019: 515-532.
|
| 6 |
Naghibijouybari H, Neupane A, Qian Z Y, et al. Rendered insecure: GPU side channel attacks are practical[C]//Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM, 2018: 2139-2153.
|
| 7 |
Yan M, Fletcher C W, Torrellas J. Cache telepathy: Leveraging shared resource attacks to learn {DNN} architectures[C]//29th USENIX Security Symposium (USENIX Security 20). 2020: 2003-2020.
|
| 8 |
Yu H G, Ma H C, Yang K C, et al. DeepEM: deep neural networks model recovery through EM side-channel information leakage[C]//Proceedings of the 2020 IEEE International Symposium on Hardware Oriented Security and Trust (HOST). Piscataway: IEEE Press, 2020: 209-218.
|
| 9 |
Joud R, Moëllic P A, Pontié S, et al. Like an open book? read neural network architecture with simple power analysis on 32-bit microcontrollers[M]. Smart Card Research and Advanced Applications. ChamSpringer Nature Switzerland. 2024: 256-276.
|
| 10 |
Cheng G Y, Luo Y K, Xu X L, et al. Side-channel-assisted reverse-engineering of encrypted DNN hardware accelerator IP and attack surface exploration[C]//Proceedings of the 2024 IEEE Symposium on Security and Privacy (SP). Piscataway: IEEE Press, 2024: 4678-4695.
|
| 11 |
Liang S S, Zhan Z H, Yao F, et al. Clairvoyance: exploiting far-field EM emanations of GPU to see your DNN models through obstacles at a distance[C]//Proceedings of the 2022 IEEE Security and Privacy Workshops (SPW). Piscataway: IEEE Press, 2022: 312-322.
|
| 12 |
Maia H T, Xiao C, Li D, et al. Can one hear the shape of a neural network: Snooping the GPU via magnetic side channel[C]//USENIX Security Symposium, 2022: 4383-4400.
|
| 13 |
Biron P V. Backpropagation: theory, architectures, and applications[J]. Journal of the American Society for Information Science, 1997, 48 (1): 88- 89.
|
| 14 |
Khater A H, Malfliet W, Callebaut D K, et al. The tanh method, a simple transformation and exact analytical solutions for nonlinear reaction–diffusion equations[J]. Chaos, Solitons & Fractals, 2002, 14(3): 513-522.
|
| 15 |
Glorot X, Bordes A, Bengio Y. Deep sparse rectifier neural networks[C]//Proceedings of the Fourteenth International Conference on Artificial Intelligence and Statistics. JMLR Workshop and Conference Proceedings, 2011: 315-323.
|
| 16 |
Hinton G E, Salakhutdinov R R. Replicated softmax: an undirected topic model[J]. Advances in Neural Information Processing Systems, 2009, 22, 1607- 1614.
|
| 17 |
Yoshida K, Kubota T, Okura S, et al. Model reverse-engineering attack using correlation power analysis against systolic array based neural network accelerator[C]//Proceedings of the 2020 IEEE International Symposium on Circuits and Systems (ISCAS). Piscataway: IEEE Press, 2020: 1-5.
|
| 18 |
Yoshida K, Shiozaki M, Okura S, et al. Model reverse-engineering attack against systolic-array-based DNN accelerator using correlation power analysis[J]. IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences, 2021, 104(1): 152-161.
|
| 19 |
Li G, Tiwari M, Orshansky M. Power-based attacks on spatial DNN accelerators[J]. ACM Journal on Emerging Technologies in Computing Systems, 2022, 18 (3): 1- 18.
|
| 20 |
Horvath P, Chmielewski L M, Weissbart L J A, et al. BarraCUDA: GPUs do leak DNN weights[J]. IEEE Symposium on Security and Privacy, 2025: 1-18.
|
| 21 |
Joud R, Moëllic P A, Pontié S, et al. A practical introduction to Side-channel extraction of Deep neural network parameters[C]//Smart Card Research and Advanced Applications. Cham: Springer, 2023: 45-65.
|
| 22 |
Maji S, Banerjee U, Chandrakasan A P. Leaky nets: Recovering embedded neural network models and inputs through simple power and timing side-channels—Attacks and defenses[J]. IEEE Internet of Things Journal, 2021, 8 (15): 12079- 12092.
|
| 23 |
Patwari K, Hafiz S M, Wang H, et al. DNN model architecture fingerprinting attack on CPU-GPU edge devices[C]//Proceedings of the 2022 IEEE 7th European Symposium on Security and Privacy (EuroS&P). Piscataway: IEEE Press, 2022: 337-355.
|
| 24 |
Hu X, Liang L, Li S C, et al. DeepSniffer: a DNN model extraction framework based on learning architectural hints[C]//Proceedings of the Twenty-Fifth International Conference on Architectural Support for Programming Languages and Operating Systems. New York: ACM, 2020: 385-399.
|
| 25 |
Horváth P, Lauret D, Liu Z, et al. SoK: neural network extraction through physical side channels[C]//USENIX Security Symposium. USENIX Association, 2024: 3215-3234.
|
| 26 |
Grecco H E, Dartiailh M C, Thalhammer-thurner G, et al. PyVISA: the Python instrumentation package[J]. Journal of Open Source Software, 2023, 8 (84): 5304.
|
| 27 |
Takatoi G, Sugawara T, Sakiyama K, et al. Simple electromagnetic analysis against activation functions of deep neural networks[C]//Applied Cryptography and Network Security Workshops. Cham: Springer, 2020: 181-197.
|
| 28 |
Edelsbrunner H, Guibas L J, Sharir M. The upper envelope of piecewise linear functions: Algorithms and applications[J]. Discrete & Computational Geometry, 1989, 4 (4): 311- 336.
|
| 29 |
Lim J S. Two-dimensional signal and image processing[M]. Upper Saddle River, N J: Prentice Hall, 1990.
|
| 30 |
Graves A, Fernández S, Gomez F, et al. Connectionist temporal classification: labelling unsegmented sequence data with recurrent neural networks[C]//Proceedings of the 23rd international conference on Machine learning. 2006: 369-376.
|
| 31 |
Graves A, Jaitly N. Towards end-to-end speech recognition with recurrent neural networks[C]//Proceedings of the 31st International Conference on International Conference on Machine Learning. New York: ACM, 2014: 1764-1772.
|
| 32 |
Ma J, Mabrouk H, Xu J, et al. NNoM: v0.4. 3[DS/OL]. Zenodo, 2021. [2025-10-11]. https://doi.org/10.5281/zenodo.1234567.
|
/
| 〈 |
|
〉 |