Template attack recovers float32 neural-network weights bit-exactly from ChipWhisperer-Lite power traces, reaching 99% success with 171 traces
Related research and updatesSynopsis
The work presents a profiled template attack targeting the floating-point multiplication between a known input and a first-layer weight, learning multivariate Gaussian templates from Hamming-weight classes of the multiplication result under randomized network configurations and using a hierarchical coarse-to-fine-to-exact search over the 32-bit candidate space; on a ChipWhisperer-Lite with an Arm Cortex-M4, the attack recovered the target weight's float32 representation bit-exactly (0x3FB70A3D), reaching about 99% success with 171 traces and 100% from 263 traces onward.
Figure 1: Pearson correlation between the profiling traces and the Hamming weight of the full 32 32 -bit product v = float32 ( w x ) v=\mathrm{float32}(wx) for every sample of the analysis window. The red markers are the five selected POIs.
arXivInterpretation
A profiled template attack is presented that recovers an IEEE-754 single-precision neural-network weight bit-exactly from power measurements, targeting the floating-point multiplication between a known input and a first-layer weight. Prior side-channel attacks on floating-point neural-network parameters often assumed reduced numerical precision or used non-profiled correlation-based techniques; according to the authors, a profiled template attack specifically targeting bit-exact 32-bit floating-point weight recovery had not previously been investigated. An end-to-end experiment on a ChipWhisperer-Lite with an STM32F303 (Arm Cortex-M4) recovered a value matching the true float32 representation 0x3FB70A3D bit for bit.
Leakage templates are constructed across randomized network configurations, with the remaining network parameters acting as nuisance variables, so the templates characterize Hamming-weight classes of the floating-point multiplication result rather than individual weight values. The templates do not depend on one fixed network configuration and do not require the attack-phase target weight during template construction, so the same profiling model can be evaluated against candidate weights of an independently configured target network. The profiling dataset spans multiple randomized configurations, non-target weights vary during profiling and are not included in the leakage model, and the attack still recovers the weight in the fixed target network.
A hierarchical coarse-to-fine-to-exact search progressively increases both numerical and leakage-model resolution, making bit-exact recovery over the 32-bit floating-point candidate space practical. It avoids exhaustive search over the complete IEEE-754 single-precision space: the coarse stage uses fewer bits to locate promising regions over the full weight interval, the fine stage increases leakage resolution, and the exact stage uses the complete 32-bit model to distinguish neighboring float32 values and power-of-two look-alikes. The coarse stage retains six separated peaks, the fine stage refines the finalist near the true weight to a value a few ULPs below it, and the exact stage returns the bit-exact float32 value.
A success-rate analysis quantifies attack efficiency: in the evaluated setting, about 99% bit-exact success is reached with 171 traces and 100% from 263 traces onward. It provides an empirical relation between the number of traces and recovery probability, indicating that reliable recovery needs only a few hundred measurements rather than the full attack trace set. The experiment repeats the attack for logarithmically spaced trace counts, drawing attack traces in random order and running the complete hierarchical attack on nested subsets, counting success only when the recovered value equals the true float32 weight bit for bit.
Perspective
The result applies to a profiled adversary who knows the network architecture and the position of the targeted multiplication, can choose the network input, can measure the target device's power consumption, and has a programmable device of the same type for profiling; in the experiments, profiling and attack traces were acquired on the same physical board, which is re-programmed between the two phases. The method targets the first weight of the first layer because one operand of its multiplication is directly selected by the attacker, whereas input activations for later-layer weights depend on previous weighted sums and nonlinear functions. The templates characterize Hamming-weight classes of the floating-point multiplication result, so the same profiling model can be evaluated against candidate weights of an independently configured target network. The hierarchical search locates candidates over the full weight interval, refines nearby numerical candidates, and uses the complete 32-bit model to distinguish neighboring float32 values and power-of-two look-alikes, reducing search cost while preserving bit-exact recovery.
The authors scope the study to the first weight of the first layer on a single target platform and note that extending to multiple network configurations and deeper layers, investigating template portability across devices and measurement sessions, and studying the effect of larger or more balanced profiling datasets on sparsely populated Hamming-weight classes remain open. Some Hamming-weight classes are sparsely represented in profiling, and their class means are obtained by linear extrapolation from sufficiently populated classes, so the accuracy of likelihood estimates for those classes is worth watching. The noise standard deviation is two to three times larger than the difference between neighboring class means, so a single trace carries little information and evidence from many traces must be combined. In addition, several specific numbers in the original text (such as trace counts, sampling rate, class proportions, correlation ranges, and ULP counts) are absent from the provided text, so this summary does not report them.
