Researchers have developed a novel power side-channel membership inference attack (PSCMIA) that can determine if a specific data sample was used to train an embedded machine learning model. This method bypasses the need for traditional attacks that rely on model outputs like prediction probabilities or labels, instead analyzing power consumption traces during model execution. PSCMIA demonstrated effectiveness across various datasets, model architectures (FC and CNN), and embedded platforms, achieving high ROC-AUC values and outperforming label-only attacks in many configurations. AI
IMPACT This research highlights a new privacy risk for embedded ML systems, potentially requiring new defenses to protect training data.
RANK_REASON Academic paper detailing a new machine learning security vulnerability. [lever_c_demoted from research: ic=1 ai=1.0]
- Atmel AVR
- CIFAR-10
- CINIC10
- Fashion-MNIST
- MNIST database
- PSCMIA
- Sahan Sanjaya Nelundeniyalage
- STM32F3
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →