Defending Side-Channel Attacks in FPGA-based Convolutional Layers and Multi-Head Attention Layers with Channel-Level Parallelization

Side-channel attacks (SCAs) pose critical security threats to neural networks (NNs) deployed on hardware platforms, particularly in cloud-based Field-Programmable Gate Array (FPGA) environments. This paper introduces a channel-level parallel structure for matrix operations to enhance NN resilience against SCAs, which mainly targets convolutional layers in Convolutional Neural Networks (CNNs) and multi-head attention layers in Transformers. Unlike kernel-level parallelism which is the common base of parallel structure for FPGA NN Accelerator, our methodology reorganizes computational sequences by associating single inputs with weights from multiple CNN channels or multiple Query/Key/Value (Q/K/V) matrices across Transformer heads. This strategy effectively thwarts Correlation Power Analysis (CPA) attacks targeting layer weight extraction. Comprehensive evaluation on PYNQ-Z2 FPGA demonstrates significant security improvements over state-of-the-art masking techniques. For CNN convolutional layers, SCA success rates drop from \(96.98\% \) to \(7.27\% \) on average. The architecture achieves either: low resource overhead ( \(87.3\% \) average reduction vs. state-of-the-art masking method) or enhanced timing performance ( \(51.37\% \) average improvement vs. baseline). Similarly, Transformer multi-head attention layers exhibit reduced SCA success rates from \(86.98\% \) to \(7.03\% \) on average, with either \(73.35\% \) resource reduction on average or \(31.94\% \) timing improvement on average. Additional analysis examines weight distribution impact across channels for precise security assessment. Results confirm the proposed structure provides robust SCA protection for secure NN hardware deployment.

Authors

Institutions

Publication Details

Journal
ACM Transactions on Design Automation of Electronic Systems
Published
2026-09-24
DOI
https://doi.org/10.1145/3847663
Primary Topic
Cryptographic Implementations and Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Defending Side-Channel Attacks in FPGA-based Convolutional Layers and Multi-Head Attention Layers with Channel-Level Parallelization

Ranxi Lin, Pingqiang Zhou, Yankun Zhu
ACM Transactions on Design Automation of Electronic Systems
Cryptographic Implementations and Security
article

Defending Side-Channel Attacks in FPGA-based Convolutional Layers and Multi-Head Attention Layers with Channel-Level Parallelization

Ranxi Lin, Pingqiang Zhou, Yankun Zhu
article en

Abstract

Side-channel attacks (SCAs) pose critical security threats to neural networks (NNs) deployed on hardware platforms, particularly in cloud-based Field-Programmable Gate Array (FPGA) environments. This paper introduces a channel-level parallel structure for matrix operations to enhance NN resilience against SCAs, which mainly targets convolutional layers in Convolutional Neural Networks (CNNs) and multi-head attention layers in Transformers. Unlike kernel-level parallelism which is the common base of parallel structure for FPGA NN Accelerator, our methodology reorganizes computational sequences by associating single inputs with weights from multiple CNN channels or multiple Query/Key/Value (Q/K/V) matrices across Transformer heads. This strategy effectively thwarts Correlation Power Analysis (CPA) attacks targeting layer weight extraction. Comprehensive evaluation on PYNQ-Z2 FPGA demonstrates significant security improvements over state-of-the-art masking techniques. For CNN convolutional layers, SCA success rates drop from \(96.98\% \) to \(7.27\% \) on average. The architecture achieves either: low resource overhead ( \(87.3\% \) average reduction vs. state-of-the-art masking method) or enhanced timing performance ( \(51.37\% \) average improvement vs. baseline). Similarly, Transformer multi-head attention layers exhibit reduced SCA success rates from \(86.98\% \) to \(7.03\% \) on average, with either \(73.35\% \) resource reduction on average or \(31.94\% \) timing improvement on average. Additional analysis examines weight distribution impact across channels for precise security assessment. Results confirm the proposed structure provides robust SCA protection for secure NN hardware deployment.

ACM Transactions on Design Automation of Electronic Systems
ShanghaiTech University (CN)
Openalex Percentile: Top 9%
Cryptographic Implementations and Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Defending Side-Channel Attacks in FPGA-based Convolutional Layers and Multi-Head Attention Layers with Channel-Level Parallelization — Ranxi Lin, Pingqiang Zhou, et al. · ACM Transactions on Design Automation of Electronic Systems (2026) | TGRS Research Map | TGRS