Shuffling Countermeasure against Power Side-Channel Attack for MLP with Software Implementation
Yusuke Nozaki, Masaya Yoshikawa · 2021
In recent years, several attack methods for artificial intelligence (AI) have been reported. Therefore, the study of countermeasure against illegal attacks for AI is very important. This study proposes a new countermeasure method against power side-channel based model extraction attacks for AI. The proposed method improves the resistance against power side-channel based model extraction attacks by randomizing the calculation order with shuffling method. Experiments using an actual device indicated that the proposed countermeasure could improve the resistance against power side-channel based model extraction attacks.