Neural Network Operation Obfuscation Against Side-Channel Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Neural networks are vulnerable to adversarial attacks that reveal their weights, biases, and architecture through side-channel analysis, compromising their security and privacy.

Innovation Solution

Obfuscate neural network operations by expanding weights and biases with dummy values, masking activation functions, and introducing dummy operations and layers to obscure the actual computations and data flows, making it difficult for attackers to discern the true network parameters and structure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If neural network operations are performed using standard weights and biases, then computational efficiency is maintained, but the network becomes vulnerable to adversarial attacks that can reveal weights, biases, and architecture through side-channel analysis

Engineering Contradiction:
Improvesecurity against adversarial attacksVSAvoidcomplexity of protecting operations
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-obfuscating weights and biases before they are used in neural network operations. Dummy weights and biases are generated and integrated into the network architecture in advance, creating a protective layer that prevents attackers from directly observing the true parameters during side-channel analysis. This proactive obfuscation ensures that even if attackers monitor computational processes, they only capture obfuscated data rather than actual network parameters.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses dummy weights and biases as intermediaries between the true network parameters and the external environment. These dummy elements act as mediators that absorb and mask the information flow, preventing direct observation of actual weights and biases. The dummy parameters serve as a protective buffer that maintains network functionality while concealing sensitive information from potential attackers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dummy operations and layers are introduced to obfuscate the network architecture, then security against architecture revelation attacks is improved, but the complexity of the network increases

Engineering Contradiction:
Improveprotection of architecture confidentialityVSAvoidcomplexity of the network structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the neural network into distinct functional segments: obfuscation layers containing dummy operations and true operational layers containing actual computations. This segmentation allows the network to maintain its core functionality while adding protective layers that confuse attackers. The dummy layers are structured as separate, identifiable components that can be systematically integrated without fundamentally altering the underlying architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes structural parameters by adding dummy layers and modifying the network topology to include obfuscation elements. These parameter changes increase the apparent complexity of the network architecture, making it difficult for attackers to distinguish between dummy and functional components. The modifications alter the network's structural parameters while preserving its computational essence through careful design of the obfuscation layers.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If weights and biases are obfuscated with dummy values, then the confidentiality of network parameters is protected, but the computational overhead increases

Engineering Contradiction:
Improveconfidentiality of weights and biasesVSAvoidcomputational energy consumption
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by obfuscating only the critical weights and biases that are most susceptible to revelation through side-channel attacks, rather than obfuscating all parameters uniformly. This selective approach reduces the overall computational overhead while still providing adequate protection for the most vulnerable parameters. The obfuscation is applied strategically to minimize energy consumption while maintaining security effectiveness.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12393679B2Protection of neural networks by obfuscation of neural network operations and architecture
Publication Date: 2025.08.19 CRYPTOGRAPHY RESEARCH INC
  • US12393679B2 patent drawing
  • US12393679B2 patent drawing
  • US12393679B2 patent drawing

AI summary

Aspects of the present disclosure involve implementations that may be used to protect neural network models against adversarial attacks by obfuscating neural network operations and architecture. Obfuscation techniques include obfuscating weights and biases of neural network nodes, obfuscating activation functions used by neural networks, as well as obfuscating neural network architecture by introducing dummy operations, dummy nodes, and dummy layers into the neural networks.