BEGIN:VCALENDAR
VERSION:2.0
PRODID:Linklings LLC
BEGIN:VTIMEZONE
TZID:America/Los_Angeles
X-LIC-LOCATION:America/Los_Angeles
BEGIN:DAYLIGHT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
TZNAME:PDT
DTSTART:19700308T020000
RRULE:FREQ=YEARLY;BYMONTH=3;BYDAY=2SU
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
TZNAME:PST
DTSTART:19701101T020000
RRULE:FREQ=YEARLY;BYMONTH=11;BYDAY=1SU
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTAMP:20260730T152640Z
LOCATION:Exhibit Hall
DTSTART;TZID=America/Los_Angeles:20260728T174900
DTEND;TZID=America/Los_Angeles:20260728T174900
UID:dac_DAC 2026_sess306_WIP3275@linklings.com
SUMMARY:The Last Line of Defense in DNN inference: ArgMax Security under C
 ombined Power Side-Channel and Fault Injection Attack
DESCRIPTION:Le Wu and Liji Wu (School of Integrated Circuits, Beijing Nati
 onal Research Center for Information Science and Technology, Tsinghua Univ
 ersity, Beijing, China); Yuyang Pan (Beijing Unionpay Card Technology Co.,
 Ltd); and Xiangmin Zhang (School of Integrated Circuits, Beijing National 
 Research Center for Information Science and Technology, Tsinghua Universit
 y, Beijing, China)\n\nDeep Neural Network (DNN) edge devices are increasin
 gly vulnerable to severe hardware security threats, particularly side-chan
 nel attacks (SCA) and fault injection attacks (FIA). This paper, for the f
 irst time, presents a combined side-channel and fault injection attack fra
 mework targeting the ArgMax unit—the hardware component responsible for co
 nverting output probabilities into the final class prediction and serving 
 as the decision logic in DNN inference. An adversary can recover intermedi
 ate prediction values through SCA and subsequently manipulate the ArgMax d
 ecision via FIA to induce targeted misclassification. On an unprotected Ar
 gMax, our attack achieved a 56.92% targeted misclassification success rate
  with full controllability across all classes, demonstrating its practical
  feasibility and high threat potential. To counter these threats, we intro
 duce Shuffled-ArgMax, a lightweight defense scheme designed to resist comb
 ined SCA–FIA attacks. Using the power side-channel and voltage fault injec
 tion capabilities of the hardware security evaluation platform, CrackNuts,
  we evaluate a convolutional neural network deployed on an STM32F407 micro
 controller. Experimental results demonstrate that Shuffled-ArgMax signific
 antly suppresses side-channel leakage and enhances robustness against prac
 tical fault injection attacks.\n\nTrack: Student\n\n
END:VEVENT
END:VCALENDAR
