KIT | KIT-Bibliothek | Impressum | Datenschutz

Collide & Conquer: Side-channel Attack on Hyper-dimensional Computing (HDC) Accelerators

Sapui, Brojogopal 1; Sadeghipourrudsari, Mahboobe 1; Tahoori, Mehdi B. 1
1 Institut für Technische Informatik (ITEC), Karlsruher Institut für Technologie (KIT)

Abstract:

Hyper-dimensional computing (HDC), a brain-inspired architecture, is gaining attention for edge AI due to its noise resilience and suitability for resource-constrained environments. However, its deployment in safety-critical domains exposes HDC to critical security vulnerabilities, including data poisoning and intellectual property (IP) theft. We demonstrate a practical side-channel attack on an FPGA-based binary HDC accelerator using voltage fluctuations captured by Time-to-Digital Converters (TDC) sensors to extract its IP, such as class hypervectors. By introducing collision analysis combined with an implicit triggering mechanism, we achieve a maximum of ≈83% bit recovery of a single class hypervector using a few hundred traces, even under parallel operations. We also discuss a randomization counter-measure that effectively reduces the recovery accuracy to ≈19% without sacrificing classification performance.


Originalveröffentlichung
DOI: 10.1109/ITC-Asia67627.2025.00019
Zugehörige Institution(en) am KIT Institut für Technische Informatik (ITEC)
Publikationstyp Proceedingsbeitrag
Publikationsdatum 16.12.2025
Sprache Englisch
Identifikator ISBN: 979-8-3315-7193-1
KITopen-ID: 1000192478
Erschienen in 2025 IEEE International Test Conference in Asia (ITC-Asia)
Veranstaltung IEEE International Test Conference in Asia (ITC-Asia 2025), Tokio, Japan, 16.12.2025 – 19.12.2025
Verlag Institute of Electrical and Electronics Engineers (IEEE)
Seiten 60 - 65
Externe Relationen Siehe auch
Schlagwörter side channel, hdc, tdc, countermeasure
Nachgewiesen in Scopus
OpenAlex
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page