Netinfo Security ›› 2025, Vol. 25 ›› Issue (6): 977-987.doi: 10.3969/j.issn.1671-1122.2025.06.012

Previous Articles     Next Articles

A Security Protection Scheme against Memory Side-Channel Attacks on NPU

HU Wenao, YAN Fei(), ZHANG Liqiang   

  1. School of Cyber Science and Engineering, Wuhan University, Wuhan 430040, China
  • Received:2025-01-24 Online:2025-06-10 Published:2025-07-11

Abstract:

With rapid advancement of artificial intelligence technology, neural processing units(NPU) have been widely adopted in smartphones, autonomous vehicles, and edge computing. However, existing NPU architectures demonstrated vulnerabilities against memory side-channel attacks, where attackers could reverse-engineer deep neural networks(DNN) model structures and parameters by analyzing memory access patterns. To address this issue, this paper proposed NPUGuard, a security protection scheme featuring two core modules: feature map partitioning module and encrypted compression engine. The solution enhanced security through three approaches: layer boundary expansion, data address obfuscation, and data encryption protection. Experimental results show that NPUGuard effectively increases layer boundaries, expanding potential reverse-engineered network configurations from 24 to 7.86×105. The chaos mapping-based encryption algorithm achieves 60% storage reduction while encrypting sensitive data. Moreover, NPUGuard introduces only 5% performance overhead, demonstrating effective balance between security enhancement and computational efficiency.

Key words: side-channel protection, NPU security, feature map partitioner, data encryption and compression

CLC Number: