🤖 AI Summary
This study addresses the privacy risks of embedded machine learning models, where restricted outputs render traditional membership inference attacks (MIAs) ineffective yet physical side channels remain vulnerable. We propose PSCMIA, a novel method that executes MIAs using solely power consumption traces without relying on model prediction probabilities or labels. This approach overcomes the dependence on logical outputs inherent in conventional attacks, exposing critical privacy vulnerabilities at the physical execution level. Experimental evaluations on fully connected and convolutional neural networks deployed on STM32F3 and XMEGA platforms demonstrate that PSCMIA achieves an ROC-AUC of 0.907 for fully connected networks. Furthermore, its performance on convolutional networks closely approximates that of probability-vector-based attacks while outperforming label-only attacks across most configurations.
📝 Abstract
Membership inference attacks (MIAs) threaten the privacy of machine learning (ML) training data by determining whether a sample was used to train a target model. Existing MIAs rely on model outputs, ranging from prediction probabilities to predicted labels, an assumption that can be restrictive for on-device ML systems with limited or inaccessible outputs. However, suppressing model outputs does not eliminate the data-dependent computations that produce them, which may remain observable through physical side channels. We present PSCMIA, a power side-channel membership inference attack against embedded ML models that can infer membership directly from power traces without requiring prediction probabilities or even the predicted labels. We evaluate PSCMIA across multiple datasets (MNIST, FMNIST, CIFAR10, CINIC10), fully connected (FC) and convolutional neural network (CNN) architectures, and two embedded platforms (STM32F3, XMEGA). PSCMIA achieves ROC-AUC values of up to 0.907 on FC models. For CNN models, the ROC-AUC gap between PSCMIA and probability vector-based shadow MIA ranges from 0.006 to 0.116. Across the FC and CNN evaluations, PSCMIA outperforms label-only MIA in 11 of 16 model-dataset-hardware configurations, demonstrating that physical execution can expose membership information even when conventional model outputs are unavailable through unintended power side-channel leakage.