Defending Side-Channel Attacks in FPGA-based Convolutional Layers and Multi-Head Attention Layers with Channel-Level Parallelization
Side-channel attacks (SCAs) pose critical security threats to neural networks (NNs) deployed on hardware platforms, particularly in cloud-based Field-Programmable Gate Array (FPGA) environments. This paper introduces a channel-level parallel structure for matrix operations to enhance NN resilience against SCAs, which mainly targets convolutional layers in Convolutional Neural Networks (CNNs) and multi-head attention layers in Transformers. Unlike kernel-level parallelism which is the common base of parallel structure for FPGA NN Accelerator, our methodology reorganizes computational sequences by associating single inputs with weights from multiple CNN channels or multiple Query/Key/Value (Q/K/V) matrices across Transformer heads. This strategy effectively thwarts Correlation Power Analysis (CPA) attacks targeting layer weight extraction. Comprehensive evaluation on PYNQ-Z2 FPGA demonstrates significant security improvements over state-of-the-art masking techniques. For CNN convolutional layers, SCA success rates drop from \(96.98\% \) to \(7.27\% \) on average. The architecture achieves either: low resource overhead ( \(87.3\% \) average reduction vs. state-of-the-art masking method) or enhanced timing performance ( \(51.37\% \) average improvement vs. baseline). Similarly, Transformer multi-head attention layers exhibit reduced SCA success rates from \(86.98\% \) to \(7.03\% \) on average, with either \(73.35\% \) resource reduction on average or \(31.94\% \) timing improvement on average. Additional analysis examines weight distribution impact across channels for precise security assessment. Results confirm the proposed structure provides robust SCA protection for secure NN hardware deployment.
Authors
- Ranxi Lin
- Pingqiang Zhou (ORCID: https://orcid.org/0000-0001-9515-9302)
- Yankun Zhu (ORCID: https://orcid.org/0009-0007-4690-9200)
Institutions
- ShanghaiTech University (CN)
Publication Details
- Journal
- ACM Transactions on Design Automation of Electronic Systems
- Published
- 2026-09-24
- DOI
- https://doi.org/10.1145/3847663
- Primary Topic
- Cryptographic Implementations and Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00