Defending Side-Channel Attacks in FPGA-based Convolutional Layers and Multi-Head Attention Layers with Channel-Level Parallelization
YanKun Zhu, Ranxi Lin, Pingqiang Zhou
Side-channel attacks (SCAs) pose critical security threats to neural networks (NNs) deployed on hardware platforms, particularly in cloud-based Field-Programmable Gate Array (FPGA) environments. This paper introduces a channel-level parallel structure for matrix operations to enhance NN resilience against SCAs, which mainly targets convolutional layers in Convolutional Neural Networks (CNNs) and multi-head attention layers in Transformers. Unlike kernel-level parallelism which is the common base of parallel structure for FPGA NN Accelerator, our methodology reorganizes computational sequences by associating single inputs with weights from multiple CNN channels or multiple Query/Key/Value (Q/K/V) matrices across Transformer heads. This strategy effectively thwarts Correlation Power Analysis (CPA) attacks targeting layer weight extraction. Comprehensive evaluation on PYNQ-Z2 FPGA demonstrates significant security improvements over state-of-the-art masking techniques. For CNN convolutional layers, SCA success rates drop from