DRACO Design of Resilient Architectures for Computing

Aegis

Primary Research Question: How much of a deployed edge model can an attacker recover from side channels alone, and what closes the gap?
Sponsored by

A model deployed to the edge is a model in the adversary’s hands. The weights may be encrypted at rest and the inference API may be locked down, but the accelerator still draws power and still radiates, and both are functions of what it is computing. Aegis measures how much that gives away.

The work runs in two directions, and the second is the point of the first:

Extraction. We establish what is actually recoverable from power and electromagnetic measurement of edge ML hardware — architecture and layer structure, then parameters, then inputs. Each of those is a different attack with a different cost, and the literature is uneven about which have been demonstrated versus which are assumed to follow. We are interested in the boundary: what an attacker gets with physical access and a modest budget, stated concretely enough to plan against.

Protection. Once the leak is characterized, the question is what closes it and what that costs. Masking, shuffling, and noise injection all have well-understood analogues in cryptographic side-channel defense; whether they transfer to ML inference at acceptable latency and accuracy is not settled. Countermeasures that are unaffordable get deployed by nobody, so cost is part of the result, not a footnote to it.

Aegis is supported by Leidos.

Open questions

Next project
CHIRP