Localization of Data Compromised by Hardware Attacks in Machine Learning Enabled Cyber-Physical Edge Devices

Pravineeth Edara, Sanmitra Banerjee, Biresh Kumar Joardar · ACM Transactions on Cyber-Physical Systems · 2025

Hardware attacks present a new and easy way for malicious actors to compromise model parameters in machine learning (ML) enabled cyber-physical systems (CPS). This can have severe consequences for many safety-critical cyber-physical applications such as power systems, self-driving cars, healthcare, security, and so on. Prior works have proposed several pre-emptive mitigation approaches for hardware attacks that can be adopted. However, adversarial attacks can bypass existing pre-emptive attack detection methods. Existing defense setups offer no further protection once the detection is bypassed. The attacker can then cause damage without getting noticed easily. In this work, we propose a new diagnosis method to search for compromised weights in real-time even when detection is bypassed considering fault-injection attacks. The proposed methodology provides an additional level of protection, which can rapidly identify and localize more than 99% of affected weights in ML models, even when thousands of model parameters are affected simultaneously, with low power, performance, and area (PPA) overheads. In addition, we also propose a method to ensure that the CPS remains functional, even when undergoing attack diagnosis.

Read the paper · More papers on PaperTik