VLDB 2026 Research / reviewers in the wild / expert
Ihsen Alouani
dblp:123/2393
· DBLP profile ↗
46ranked-venue papers
5as first author
33since 2021 · last 2026
0000-0001-5102-8087ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 19 · 3 first-author · 14 since 2021Artificial intelligence and machine learning · 14 · 13 since 2021Software engineering, systems software and programming languages · 9 · 2 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8 · 6 since 2021Security and privacy · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Computer networks · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GUARDIAN: A Decoupled GNN Framework for Type-aware Hardware Trojan DetectionabstractWith increased outsourcing of intellectual property (IP) cores to third-party vendors, system-on-chip designs face heightened security risks from hardware trojans (HTs) that can compromise integrity and functionality. Prior HT detection works typically train separate deep-learning models on combinational (TRTC-TC) and sequential (TRTC-TS) trojan benchmarks from the LEDA-based Trust-Hub dataset, treating them independently and framing detection as binary classification, which fails when both trojan types coexist in a single netlist. In contrast, our proposed method employs a unified Graph Neural Network (GNN)-based model trained on a mixed dataset comprising benchmarks from both TRTC-TC and TRTC-TS, enabling multi-class classification to distinguish between benign, combinational, and sequential trojans. The approach addresses key GNN constraints and attains strong detection performance on the mixed dataset: TPR of 99.3% and 100%, TNR of 99.99% and 99.9%, and PPV of 97.9% and 97% for combinational and sequential trojans, respectively. Zain Shabbir, Shichao Yu, Ihsen Alouani, Máire O'Neill |
ISCAS | 3 |
| 2025 | Mind the Gap: Detecting Black-box Adversarial Attacks in the Making through Query Update AnalysisabstractAdversarial attacks remain a significant threat that can jeopardize the integrity of Machine Learning (ML) models. In particular, query-based black-box attacks can generate malicious noise without having access to the victim model’s architecture, making them practical in real-world contexts. The community has proposed several defenses against adversarial attacks, only to be broken by more advanced and adaptive attack strategies. In this paper, we propose a framework that detects if an adversarial noise instance is being generated. Unlike existing stateful defenses that detect adversarial noise generation by monitoring the input space, our approach learns adversarial patterns in the input update similarity space. In fact, we propose to observe a new metric called Delta Similarity ($\mathcal{D}\mathcal{S}$), which we show it captures more efficiently the adversarial behavior. We evaluate our approach against 8 state-of-the-art attacks, including adaptive attacks, where the adversary is aware of the defense and tries to evade detection. We find that our approach is significantly more robust than existing defenses both in terms of specificity and sensitivity.1 Jeonghwan Park 0002, Niall McLaughlin, Ihsen Alouani |
CVPR | 3 |
| 2025 | Data Oblivious CPU: Microarchitectural Side-channel Leakage-Resilient ProcessorabstractMitigating microarchitectural side channels remains a central challenge in hardware security. Despite substantial research efforts, current defenses are often narrowly tailored to specific vulnerabilities, leaving systems exposed to a broader spectrum of microarchitectural side-channel attacks. In this paper, we propose a generic approach to mitigate side-channel attacks with minimal architectural changes. Unlike traditional approaches that focus on mitigating specific side channels, we propose a dynamic strategy that alters the decoding of the instructions into secure (side-channel resilient) or performance versions of the instructions, based on the data it is processing. Specifically, to minimize performance overhead, decoding to a secure version is selectively applied only when sensitive data are being processed, ensuring optimal performance for instructions operating on non-sensitive data.To evaluate our approach, we implement it on the RISC-V out-of-order BOOM processor. Our results demonstrate that the mechanism increases the utilization of FPGA resources by only 2% compared to the original design. Furthermore, it imposes 0% performance overhead for unprotected applications, while maintaining overhead between up to 25% for security-critical workloads. This work represents a scalable and efficient solution for defending against micro-architectural side-channel attacks without compromising system performance. Behnam Omidi, Ihsen Alouani, Khaled N. Khasawneh |
DAC | 2 |
| 2025 | Attention Eclipse: Manipulating Attention to Bypass LLM Safety-AlignmentabstractRecent research has shown that carefully crafted jailbreak inputs can induce large language models to produce harmful outputs, despite safety measures such as alignment.It is important to anticipate the range of potential Jailbreak attacks to guide effective defenses and accurate assessment of model safety.In this paper, we present a new approach for generating highly effective Jailbreak attacks that manipulate the attention of the model to selectively strengthen or weaken attention among different parts of the prompt.By harnessing attention loss, we develop more effective jailbreak attacks, that are also transferrable.The attacks amplify the success rate of existing Jailbreak algorithms, including GCG, AutoDAN, and ReNeLLM, while lowering their generation cost (for example, the amplified GCG attack achieves 91.2% ASR, vs. 67.9%for the original attack on Llama2-7B-chat/AdvBench, using less than a third of the generation time).Warning: This paper contains potentially harmful LLM-generated content. Pedram Zaree, Md Abdullah Al Mamun, Quazi Mishkatul Alam, Yue Dong 0002, Ihsen Alouani, Nael B. Abu-Ghazaleh |
EMNLP | 5 |
| 2025 | On the Trustworthiness of Spiking Neural Networks and Neuromorphic SystemsabstractInternational audience Theofilos Spyrou, Haralampos-G. D. Stratigopoulos, Ihsen Alouani, Said Hamdioui, Anteneh Gebregiorgis |
ETS | 3 |
| 2025 | On Jailbreaking Quantized Language Models Through Fault Injection AttacksabstractThe safety alignment of Language Models (LMs) is a critical concern, yet their integrity can be challenged by direct parameter manipulation attacks, such as those potentially induced by fault injection. As LMs are increasingly deployed using low-precision quantization for efficiency, this paper investigates the efficacy of such attacks for jailbreaking aligned LMs across different quantization schemes. We propose gradient-guided attacks, including a tailored progressive bit-level search algorithm introduced herein and a comparative word-level (single weight update) attack. Our evaluation on Llama-3.2-3B, Phi-4-mini, and Llama-3-8B across FP16 (baseline), and weight-only quantization (FP8, INT8, INT4) reveals that quantization significantly influences attack success. While attacks readily achieve high success (>80% Attack Success Rate, ASR) on FP16 models, within an attack budget of 25 perturbations, FP8 and INT8 models exhibit ASRs below 20% and 50%, respectively. Increasing the perturbation budget up to 150 bit-flips, FP8 models maintained ASR below 65%, demonstrating some resilience compared to INT8 and INT4 models that have high ASR. In addition, analysis of perturbation locations revealed differing architectural targets across quantization schemes, with (FP16, INT4) and (INT8, FP8) showing similar characteristics. Besides, jailbreaks induced in FP16 models were highly transferable to subsequent FP8/INT8 quantization (<5% ASR difference), though INT4 significantly reduced transferred ASR (avg. 35% drop). These findings highlight that while common quantization schemes, particularly FP8, increase the difficulty of direct parameter manipulation jailbreaks, vulnerabilities can still persist, especially through post-attack quantization. Noureldin Zahran, Ahmad Tahmasivand, Ihsen Alouani, Khaled N. Khasawneh, Mohamed E. Fouda |
ACM Great Lakes Symposium on VLSI | 3 |
| 2025 | Adversarial Attention Deficit: Fooling Deformable Vision Transformers with Collaborative Adversarial PatchesabstractDeformable vision transformers reduce the expensive quadratic time-complexity of attention modeling by using sparse attention structures, making it possible to use transformers in large-scale vision applications, such as multiview vision systems. We show that existing adversarial attacks against conventional vision transformers do not transfer to deformable transformers, primarily due to the data-dependent, dynamic nature of sparse attention. In this work, we present for the first time, adversarial attacks against deformable vision transformers by getting control of their attention-inferring module. We develop a novel collaborative attack where a source patch manipulates attention to point to a target patch containing the adversarial noise, which fools the model. We observe that our attack alters less than 1% of the patched area in the input field, completely disrupting object detection and resulting in 0% AP in single-view object detection using MS COCO, and 0% MODA in multi-view object detection using Wildtrack. Quazi Mishkatul Alam, Bilel Tarchoun, Ihsen Alouani, Nael B. Abu-Ghazaleh |
WACV | 3 |
| 2025 | Are Neuromorphic Architectures Inherently Privacy-preserving? An Exploratory StudyabstractWhile machine learning (ML) models are becoming mainstream, including in critical application domains, concerns have been raised about the increasing risk of sensitive data leakage. Various privacy attacks, such as membership inference attacks (MIAs), have been developed to extract data from trained ML models, posing significant risks to data confidentiality. While the predominant work in the ML community considers traditional Artificial Neural Networks (ANNs) as the default neural model, neuromorphic architectures, such as Spiking Neural Networks (SNNs), have recently emerged as an attractive alternative mainly due to their significantly low power consumption. These architectures process information through discrete events, i.e., spikes, to mimic the functioning of biological neurons in the brain. While the privacy issues have been extensively investigated in the context of traditional ANNs, they remain largely unexplored in neuromorphic architectures, and little work has been dedicated to investigating their privacy-preserving properties. In this paper, we investigate the question of whether SNNs have inherent privacy-preserving advantages. Specifically, we investigate SNNs’ privacy properties through the lens of MIAs across diverse datasets, in comparison with ANNs. We explore the impact of different learning algorithms (surrogate gradient and evolutionary learning), programming frameworks (snnTorch, TENNLab, and LAVA), and various parameters on the resilience of SNNs against MIA. Our experiments reveal that SNNs demonstrate consistently superior privacy preservation compared to ANNs, with evolutionary algorithms further enhancing their resilience. For example, on the CIFAR-10 dataset, SNNs achieve an AUC as low as 0.59 compared to 0.82 for ANNs, and on CIFAR-100, SNNs maintain a low AUC of 0.58, whereas ANNs reach 0.88. Furthermore, we investigate the privacy-utility trade-off through Differentially Private Stochastic Gradient Descent (DPSGD), observing that SNNs incur a notably lower accuracy drop than ANNs under equivalent privacy constraints. Ayana Moshruba, Ihsen Alouani, Maryam Parsa |
Proc. Priv. Enhancing Technol. | 2 |
| 2025 | DART: Distribution-Aware Hardware Trojan DetectionabstractMachine Learning (ML) has proven effective in Integrated Circuits (IC) security, particularly in Hardware Trojan (HT) detection. However, a model’s generalization potential depends on its ability to address distribution shifts (DS) in unseen data. Mitigating DS enhances a model’s adaptability to novel variations and threats within the dynamic realm of IC designs and HTs. We formulate HT detection as a DS problem, introducingDART, a novelDistribution-AwareHT detection framework, to enhance model generalization. ApplyingDARTon state-of-the-art Graph Neural Network architecture yields up to 22.96% and 17.37% F1-score improvements for unseen IC designs diverging significantly from the training data. Youssef Gamal, Yanda Li, Shih-Yuan Yu, Ihsen Alouani, Mohammad Abdullah Al Faruque |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | A Deep CNN-BiGRU Network for Multi-stream Hand Gesture Recognition FrameworkabstractHand Gesture Recognition (HGR) achieved significant progress through diverse fields due to recent advancements in machine learning and sensor technologies. While Leap Motion Controller sensors offer convenient hand tracking and multi-modal data (skeletal and depth), the heterogeneous nature of these data modalities poses several challenges for HGR systems. In order to exploit the complementary information offered by skeleton and depth data, fusion algorithms are widely used. This paper proposes a novel Deep CNN-BiGRU model incorporating both intermediate and late fusion strategies. For each modality, we use a separate model for feature extraction step. Then, we apply fusion techniques for the decision step. Our proposed model demonstrates superior performance compared with models employed separately on skeletal or depth data, highlighting its effectiveness in exploiting the combined information for robust and accurate HGR. Nahla Majdoub Bhiri, Safa Ameur, Imen Jegham, Ihsen Alouani, Anouar Ben Khalifa |
CoDIT | 4 |
| 2024 | DAP: A Dynamic Adversarial Patch for Evading Person DetectorsabstractPatch-based adversarial attacks were proven to compromise the robustness and reliability of computer vision systems. However, their conspicuous and easily detectable nature challenge their practicality in real-world setting. To address this, recent work has proposed using Generative Adversarial Networks (GANs) to generate naturalistic patches that may not attract human attention. However, such approaches suffer from a limited latent space making it challenging to produce a patch that is efficient, stealthy, and robust to multiple real-world transformations. This paper introduces a novel approach that produces a Dynamic Adversarial Patch (DAP) designed to overcome these limitations. DAP maintains a naturalistic appearance while optimizing attack efficiency and robustness to real-world transformations. The approach involves redefining the optimization problem and introducing a novel objective function that incorporates a similarity metric to guide the patch's creation. Unlike GAN-based techniques, the DAP directly modifies pixel values within the patch, providing increased flexibility and adaptability to multiple transformations. Furthermore, most clothing-based physical attacks assume static objects and ignore the possible transformations caused by non-rigid deformation due to changes in a person's pose. To address this limitation, a ‘Creases Transformation’ (CT) block is introduced, enhancing the patch's resilience to a variety of real-world distortions. Experimental results demonstrate that the proposed approach outperforms state-of-the-art attacks, achieving a success rate of up to 82.28% in the digital world when targeting the YOLOv7 detector and 65% in the physical world when targeting YOLOv3tiny detector deployed in edge-based smart cameras. Amira Guesmi, Ruitian Ding, Muhammad Abdullah Hanif, Ihsen Alouani, Muhammad Shafique 0001 |
CVPR | 4 |
| 2024 | Harnessing ML Privacy by Design Through Crossbar Array Non-IdealitiesabstractDeep Neural Networks (DNNs), handling compute- and data-intensive tasks, often utilize accelerators like Resistive- switching Random-access Memory (RRAM) crossbar for energy- efficient in-memory computation. Despite RRAM's inherent non- idealities causing deviations in DNN output, this study transforms the weakness into strength. By leveraging RRAM non-idealities, the research enhances privacy protection against Membership Inference Attacks (MIAs), which reveal private information from training data. RRAM non-idealities disrupt MIA features, increasing model robustness and revealing a privacy-accuracy tradeoff. Empirical results with four MIAs and DNNs trained on different datasets demonstrate significant privacy leakage reduction with a minor accuracy drop (e.g., up to 2.8% for ResNet-18 with CIFAR-100). Sankha Baran Dutta, Andrés Márquez 0001, Ihsen Alouani, Khaled N. Khasawneh |
DATE | 4 |
| 2024 | AdvART: Adversarial Art for Camouflaged Object Detection AttacksabstractPhysical adversarial attacks pose a significant practical threat as it deceives deep learning systems operating in the real world by producing prominent and maliciously designed physical perturbations. Emphasizing the evaluation of naturalness is crucial in such attacks, as humans can easily detect unnatural manipulations. To address this, recent work has proposed leveraging generative adversarial networks (GANs) to generate naturalistic patches, which may seem visually suspicious and evade human’s attention. However, these approaches suffer from a limited latent space which leads to an inevitable trade-off between naturalness and attack efficiency. In this paper, we propose a novel approach to generate naturalistic and inconspicuous adversarial patches. Specifically, we redefine the optimization problem by introducing an additional loss term to the total loss. This term works as a semantic constraint to ensure that the generated camouflage pattern holds semantic meaning rather than arbitrary patterns. It leverages similarity metrics-based loss that we optimize within the global adversarial objective function. Our technique is based on directly manipulating the pixel values in the patch, which gives higher flexibility and larger space compared to the GAN-based techniques that are based on indirectly optimizing the patch by modifying the latent vector. Our attack achieves superior success rate of up to $91.19 \%$ and $72 \%$, respectively, in the digital world and when deployed in smart cameras at the edge compared to the GAN-based approach. Amira Guesmi, Ioan Marius Bilasco, Muhammad Shafique 0001, Ihsen Alouani |
ICIP | 4 |
| 2024 | BrainLeaks: On the Privacy-Preserving Properties of Neuromorphic Architectures against Model Inversion AttacksabstractWith the mainstream integration of machine learning into security-sensitive domains such as healthcare and finance, con-cerns about data privacy have intensified. Conventional artificial neural networks (ANNs) have been found vulnerable to several attacks that can leak sensitive data. Particularly, model inversion (MI) attacks enable the reconstruction of data samples that have been used to train the model. Neuromorphic architectures have emerged as a paradigm shift in neural computing, enabling asynchronous and energy-efficient computation. However, little to no existing work has investigated the privacy of neuromorphic architectures against model inversion. Our study is motivated by the intuition that the non-differentiable aspect of spiking neural networks (SNNs) might result in inherent privacy-preserving properties, especially against gradient-based attacks. To investigate this hypothesis, we propose a thorough exploration of SNNs' privacy-preserving capabilities. Specifically, we develop novel inversion attack strategies that are comprehensively designed to target SNNs, offering a comparative analysis with their conventional ANN counterparts. Our experiments, conducted on diverse event-based and static datasets, demonstrate the effectiveness of the proposed attack strategies and therefore questions the assumption of inherent privacy-preserving in neuromorphic architectures. Hamed Poursiami, Ihsen Alouani, Maryam Parsa |
ICMLA | 2 |
| 2024 | SSAP: A Shape-Sensitive Adversarial Patch for Comprehensive Disruption of Monocular Depth Estimation in Autonomous Navigation ApplicationsabstractMonocular depth estimation (MDE) has advanced significantly, primarily through the integration of convolutional neural networks (CNNs) and more recently, Transformers. However, concerns about their susceptibility to adversarial attacks have emerged, especially in safety-critical domains like autonomous driving and robotic navigation. Existing approaches for assessing CNN-based depth prediction methods have fallen short in inducing comprehensive disruptions to the vision system, often limited to specific local areas. In this paper, we introduce SSAP (Shape-Sensitive Adversarial Patch), a novel approach designed to comprehensively disrupt monocular depth estimation (MDE) in autonomous navigation applications. Our patch is crafted to selectively undermine MDE in two distinct ways: by distorting estimated distances or by creating the illusion of an object disappearing from the system’s perspective. Notably, our patch is shape-sensitive, meaning it considers the specific shape and scale of the target object, thereby extending its influence beyond immediate proximity. Furthermore, our patch is trained to effectively address different scales and distances from the camera. Experimental results demonstrate that our approach induces a mean depth estimation error surpassing 0.5, impacting up to 99% of the targeted region for CNN-based MDE models. Additionally, we investigate the vulnerability of Transformer-based MDE models to patch-based attacks, revealing that SSAP yields a significant error of 0.59 and exerts substantial influence over 99% of the target region on these models. Amira Guesmi, Muhammad Abdullah Hanif, Ihsen Alouani, Bassem Ouni, Muhammad Shafique 0001 |
IROS | 3 |
| 2024 | An information-theoretic perspective of physical adversarial patches
Bilel Tarchoun, Anouar Ben Khalifa, Mohamed Ali Mahjoub, Nael B. Abu-Ghazaleh, Ihsen Alouani |
Neural Networks | 5 |
| 2023 | Jedi: Entropy-Based Localization and Removal of Adversarial PatchesabstractReal-world adversarial physical patches were shown to be successful in compromising state-of-the-art models in a variety of computer vision applications. Existing defenses that are based on either input gradient or features analysis have been compromised by recent GAN-based attacks that generate naturalistic patches. In this paper, we propose Jedi, a new defense against adversarial patches that is resilient to realistic patch attacks. Jedi tackles the patch localization problem from an information theory perspective; leverages two new ideas: (1) it improves the identification of potential patch regions using entropy analysis: we show that the entropy of adversarial patches is high, even in naturalistic patches; and (2) it improves the localization of adversarial patches, using an autoencoder that is able to complete patch regions from high entropy kernels. Jedi achieves high-precision adversarial patch localization, which we show is critical to successfully repair the images. Since Jedi relies on an input entropy analysis, it is model-agnostic, and can be applied on pre-trained off-the-shelf models without changes to the training or inference of the protected models. Jedi detects on average 90% of adversarial patches across different benchmarks and recovers up to 94% of successful patch attacks (Compared to 75% and 65% for LGS and Jujutsu, respectively). Bilel Tarchoun, Anouar Ben Khalifa, Mohamed Ali Mahjoub, Nael B. Abu-Ghazaleh, Ihsen Alouani |
CVPR | 5 |
| 2023 | Stochastic-HMDs: Adversarial-Resilient Hardware Malware Detectors via UndervoltingabstractMachine learning-based hardware malware detectors (HMDs) offer a potential game changing advantage in defending systems against malware. However, HMDs suffer from adversarial attacks, can be effectively reverse-engineered and subsequently be evaded, allowing malware to hide from detection. We address this issue by proposing novel HMDs (Stochastic-HMDs), which leverage approximate computing (AC) to harden HMDs against adversarial evasion attacks. Stochastic-HMDs introduce stochastic noise into the computations within the model to build an efficient and low-cost moving-target defense. Specifically, we use controlled undervolting, i.e., scaling the supply voltage below nominal level, to deliberately induce stochastic timing violations in the HMDs’ computations during inference (detection). We show that such technique makes HMDs more resilient to adversarial attacks, especially to reverse-engineering and transferability. Our thorough empirical results substantiate that Stochastic-HMDs offer effective defense against adversarial attacks along with by-product power savings, without requiring any changes to the hardware/software nor to the HMDs’ model, i.e., no retraining or fine tuning is needed. In particular, Stochastic-HMDs can detect more than 94% of the evasive malware with a negligible (i.e., < 2%) accuracy loss, along with ~15% power savings. Ihsen Alouani, Khaled N. Khasawneh |
DAC | 2 |
| 2023 | A Brain-inspired Approach for Malware Detection using Sub-semantic Hardware FeaturesabstractDespite significant efforts to enhance the resilience of computer systems against malware attacks, the abundance of exploitable vulnerabilities remains a significant challenge. While preventing compromises is difficult, traditional signature-based static analysis techniques are susceptible to bypassing through metamorphic/polymorphic malware or zero-day exploits. Dynamic detection techniques, particularly those utilizing machine learning (ML), have the potential to identify previously unseen signatures by monitoring program behavior. However, classical ML models are power and resource intensive and may not be suitable for devices with limited budgets. This constraint creates a challenging tradeoff between security and resource utilization, which cannot be fully addressed through model compression and pruning. In contrast, neuromorphic architectures offer a promising solution for low-power brain-inspired systems. In this work, we explore the novel use of neuromorphic architectures for malware detection. We accomplish this by encoding sub-semantic micro-architecture level features in the spiking domain and proposing a Spiking Neural Network (SNN) architecture for hardware-aware malware detection. Our results demonstrate promising malware detection performance with an 89% F1-score. Ultimately, this work advocates that neuromorphic architectures, due to their low power consumption, represent a promising candidate for malware detection, especially for energy-constraint processors in IoT and Edge devices. Maryam Parsa, Khaled N. Khasawneh, Ihsen Alouani |
ACM Great Lakes Symposium on VLSI | 3 |
| 2023 | Exploring Machine Learning Privacy/Utility Trade-Off from a Hyperparameters LensabstractMachine Learning (ML) architectures have been applied to several applications that involve sensitive data, where a guarantee of users' data privacy is required. Differentially Private Stochastic Gradient Descent (DPSGD) is the state-of-the-art method to train privacy-preserving models. However, DPSGD comes at a considerable accuracy loss leading to sub-optimal privacy/utility trade-offs. Towards investigating new ground for better privacy-utility trade-off, this work questions; (i) if models' hyperparameters have any inherent impact on ML models' privacy-preserving properties, and (ii) if models' hyperparameters have any impact on the privacy/utility trade-off of differentially private models. We propose a comprehensive design space exploration of different hyperparameters such as the choice of activation functions, the learning rate and the use of batch normalization. Interestingly, we found that utility can be improved by using Bounded RELU as activation functions with the same privacy-preserving characteristics. With a drop-in replacement of the activation function, we achieve new state-of-the-art accuracy on MNIST (96.02%), FashionMnist (84.76%), and CIFAR-10 (44.42%) without any modification of the learning procedure fundamentals of DPSGD. Ayoub Arous, Amira Guesmi, Muhammad Abdullah Hanif, Ihsen Alouani, Muhammad Shafique 0001 |
IJCNN | 4 |
| 2023 | BM-Seg: A new bone metastases segmentation dataset and ensemble of CNN-based segmentation approach
Marwa Afnouch, Olfa Gaddour, Yosr Hentati, Fares Bougourzi, Mohamed Abid, Ihsen Alouani, Abdelmalik Taleb-Ahmed |
Expert Syst. Appl. | 6 |
| 2023 | Hand gesture recognition with focus on leap motion: An overview, real world challenges and future directions
Nahla Majdoub Bhiri, Safa Ameur, Ihsen Alouani, Mohamed Ali Mahjoub, Anouar Ben Khalifa |
Expert Syst. Appl. | 3 |
| 2023 | Deep learning-based hard spatial attention for driver in-vehicle action monitoring
Imen Jegham, Ihsen Alouani, Anouar Ben Khalifa, Mohamed Ali Mahjoub |
Expert Syst. Appl. | 2 |
| 2023 | SecureVolt: Enhancing Deep Neural Networks Security via UndervoltingabstractDeep neural networks (DNNs) are shown to be vulnerable to adversarial attacks; carefully crafted additive noise that undermines DNNs integrity. Previously proposed defenses against these attacks require substantial overheads, making it challenging to deploy these solutions in power and computational resource-constrained devices, such as embedded systems and the Edge. In this article, we explore the use of voltage over-scaling (VOS) as a lightweight and efficient defense against adversarial attacks. Specifically, we exploit the stochastic timing violations of VOS within computing elements to implement a moving-target defense for DNNs. Our experimental results demonstrate that VOS guarantees effective defense against different attack methods, does not require any software/hardware modifications, and offers a by-product reduction in power consumption. We propose a space exploration to identify a possible tradeoff between robustness, accuracy, and power gains. Furthermore, we observe the behavior of models’ epistemic uncertainty under variable undervolting aggressiveness. Our experiments show that model uncertainty analysis is coherent with the observation in our robustness/accuracy exploration. Ihsen Alouani, Khaled N. Khasawneh |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2022 | Breaking (and Fixing) Channel-based Cryptographic Key Generation: A Machine Learning ApproachabstractSeveral systems and application domains are under-going disruptive transformations due to the recent breakthroughs in computing paradigms such us Machine Learning and commu-nication technologies such as 5G and beyond. Intelligent trans-portation systems is one of the flagship domains that witnessed drastic transformations through the development of ML-based environment perception along with Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I) communication protocols. Such connected, intelligent and collaborative transportation systems represent a promising trend towards smart roads and cities. However, the safety-critical aspect of these cyber-physical systems requires a systematic study of their security and privacy. In fact, security-sensitive information could be transmitted between vehicles, or between vehicles and the infrastructure such as security alerts, payment, etc. Since asymmetric cryptography is heavy to implement on embedded time-critical devices, in addition to the complexity of PKI-based solutions, symmetric cryptography offers confidentiality along with high performance. However, cryptographic key generation and establishment in symmetric cryptosystems is a great challenge. Recent work proposed a key generation and establishment protocol for ve-hicular communication that is based on the reciprocity and high spatial and temporal variation properties of the vehicular communication channel. This paper investigates the limitations of such channel-based key generation protocols. Based on a channel model with a machine learning approach, we show the possibility for a passive eavesdropper to compromise the secret key in a practical manner, thereby undermining the security of such key establishment technique. Moreover, we propose a defense based on adversarial machine learning to overcome this limit. Ihsen Alouani |
DSD | 1 |
| 2022 | ROOM: Adversarial Machine Learning Attacks Under Real-Time ConstraintsabstractAdvances in deep-learning have enabled a wide range of promising applications. However, these systems are vulnerable to adversarial attacks; adversarially crafted pertur-bations to their inputs could cause them to misclassify. Most state-of-the-art adversarial attack generation algorithms focus primarily on controlling the noise magnitude to make it undetectable. The execution time is a secondary consideration for these attacks and the underlying assumption is that there are no time constraints. However, just-in-time adversarial attacks where an attacker opportunistically generates adversarial examples on-the-fly represent an even more critical threat, especially against real-time applications. Therefore, this paper introduces a new problem: how to systematically generate adversarial noise under real-time constraints? Understanding this problem improves our understanding of the threat these attacks pose to real-time systems and provides security evaluation benchmarks for future defenses. Therefore, first, we conduct a run-time analysis of adversarial generation algorithms. Our analysis show that universal attacks produce a general attack offline, with no online overhead. However, their success rate is limited because of their generality. In contrast, online algorithms, which target a specific input, are computationally expensive, making them inappropriate under time constraints. Thus, we propose ROOM, a novel Real-time Online-Offline attack construction Model where an offline component warms up the online algorithm, making it possible to generate highly successful attacks under time constraints. Our results show that ROOM can achieve high attack success rates under real-time constraints with up to 90x faster adversarial attack generation than state-of-the-art methods. For example, ROOM achieves 100% adversarial attack success rate on MNIST with a throughput of up to 1250 frame per second (FPS), more than 60% success rate with 200 FPS on CIFAR-10 and 60% with 16 FPS on ImageNet. Amira Guesmi, Khaled N. Khasawneh, Nael B. Abu-Ghazaleh, Ihsen Alouani |
IJCNN | 4 |
| 2022 | Special Session: Towards an Agile Design Methodology for Efficient, Reliable, and Secure ML SystemsabstractThe real-world use cases of Machine Learning (ML) have exploded over the past few years. However, the current computing infrastructure is insufficient to support all real-world applications and scenarios. Apart from high efficiency requirements, modern ML systems are expected to be highly reliable against hardware failures as well as secure against adversarial and IP stealing attacks. Privacy concerns are also becoming a first-order issue. This article summarizes the main challenges in agile development of efficient, reliable and secure ML systems, and then presents an outline of an agile design methodology to generate efficient, reliable and secure ML systems based on user-defined constraints and objectives. Shail Dave, Alberto Marchisio, Muhammad Abdullah Hanif, Amira Guesmi, Aviral Shrivastava, Ihsen Alouani, Muhammad Shafique 0001 |
VTS | 6 |
| 2022 | On the Error Rate Performance of Full-Duplex Cooperative NOMA in Wireless NetworksabstractError rate analyses of cooperative non-orthogonal multiple access (CNOMA) systems are of paramount importance to investigate the communication reliability for each user and facilitate the development of enhancement algorithms. Although CNOMA has recently attracted great attention, its error performance, particularly that of full-duplex cooperative NOMA (FD-CNOMA), is still underexplored in the literature. In this paper, we investigated the error performance of FD-CNOMA systems under imperfect successive interference cancellation (SIC) and residual self-interference (RSI), where new closed-form expressions of the exact bit error rates (BER) are derived for both users. Through the derived BER expressions, high-SNR analyses are conducted to show that FD-CNOMA has an error floor. Based on the derived expressions, we proposed a novel SINR-based selective FD-relaying, which minimizes the end-to-end (e2e) BER and improves the overall system performance. The analyses are extended to cover pulse-amplitude modulation (PAM) and quadrature-amplitude modulation (QAM) with arbitrary modulation orders. Monte Carlo simulations and numerical results are presented to corroborate the derived analytical expressions and give valuable insights into the error performance of FD-CNOMA systems. Anis Amazigh Hamza, Iyad Dayoub, Ihsen Alouani, Abderrahmane Amrouche |
IEEE Trans. Commun. | 3 |
| 2021 | Defensive approximation: securing CNNs using approximate computingabstractIn the past few years, an increasing number of machine-learning and deep learning structures, such as Convolutional Neural Networks (CNNs), have been applied to solving a wide range of real-life problems. However, these architectures are vulnerable to adversarial attacks: inputs crafted carefully to force the system output to a wrong label. Since machine-learning is being deployed in safety-critical and security-sensitive domains, such attacks may have catastrophic security and safety consequences. In this paper, we propose for the first time to use hardware-supported approximate computing to improve the robustness of machine learning classifiers. We show that our approximate computing implementation achieves robustness across a wide range of attack scenarios. Specifically, we show that successful adversarial attacks against the exact classifier have poor transferability to the approximate implementation. The transferability is even poorer for the black-box attack scenarios, where adversarial attacks are generated using a proxy model. Surprisingly, the robustness advantages also apply to white-box attacks where the attacker has unrestricted access to the approximate classifier implementation: in this case, we show that substantially higher levels of adversarial noise are needed to produce adversarial examples. Furthermore, our approximate computing model maintains the same level in terms of classification accuracy, does not require retraining, and reduces resource utilization and energy consumption of the CNN. We conducted extensive experiments on a set of strong adversarial attacks; We empirically show that the proposed implementation increases the robustness of a LeNet-5 and an Alexnet CNNs by up to 99% and 87%, respectively for strong transferability-based attacks along with up to 50% saving in energy consumption due to the simpler nature of the approximate logic. We also show that a white-box attack requires a remarkably higher noise budget to fool the approximate classifier, causing an average of 4 dB degradation of the PSNR of the input image relative to the images that succeed in fooling the exact classifier. Amira Guesmi, Ihsen Alouani, Khaled N. Khasawneh, Mouna Baklouti, Tarek Frikha, Mohamed Abid, Nael B. Abu-Ghazaleh |
ASPLOS | 2 |
| 2021 | Adversarial Attacks in a Multi-view Setting: An Empirical Study of the Adversarial Patches Inter-view TransferabilityabstractWhile machine learning applications are getting mainstream owing to a demonstrated efficiency in solving complex problems, they suffer from inherent vulnerability to adversarial attacks. Adversarial attacks consist of additive noise to an input which can fool a detector. Recently, successful real-world printable adversarial “patches” were proven efficient against state-of-the-art neural networks. In the transition from digital noise based attacks to real-world physical attacks, the myriad of factors affecting object detection will also affect adversarial patches. Among these factors, view angle is one of the most influential, yet under-explored. In this paper, we study the effect of view angle on the effectiveness of an adversarial patch. To this aim, we propose the first approach that considers a multi-view context by combining existing adversarial patches with a perspective geometric transformation in order to simulate the effect of view angle changes. Our approach has been evaluated on two datasets: the first dataset which contains most real world constraints of a multi-view context, and the second dataset which empirically isolates the effect of view angle. The experiments show that view angle significantly affects the performance of adversarial patches, where in some cases the patch loses most of its effectiveness. We believe that these results motivate taking into account the effect of view angles in future adversarial attacks, and open up new opportunities for adversarial defenses. Bilel Tarchoun, Ihsen Alouani, Anouar Ben Khalifa, Mohamed Ali Mahjoub |
CW | 2 |
| 2021 | Securing Deep Spiking Neural Networks against Adversarial Attacks through Inherent Structural ParametersabstractDeep Learning (DL) algorithms have gained popularity owing to their practical problem-solving capacity. However, they suffer from a serious integrity threat, i.e., their vulnerability to adversarial attacks. In the quest for DL trustworthiness, recent works claimed the inherent robustness of Spiking Neural Networks (SNNs) to these attacks, without considering the variability in their structural spiking parameters. This paper explores the security enhancement of SNNs through internal structural parameters. Specifically, we investigate the SNNs robustness to adversarial attacks with different values of the neuron's firing voltage thresholds and time window boundaries. We thoroughly study SNNs security under different adversarial attacks in the strong white-box setting, with different noise budgets and under variable spiking parameters. Our results show a significant impact of the structural parameters on the SNNs' security, and promising sweet spots can be reached to design trustworthy SNNs with 85% higher robustness than a traditional non-spiking DL system. To the best of our knowledge, this is the first work that investigates the impact of structural parameters on SNNs robustness to adversarial attacks. The proposed contributions and the experimental framework is available online11https://github.com/rda-ela/SNN-Adversarial-Attacks to the community for reproducible research. Rida El-Allami, Alberto Marchisio, Muhammad Shafique 0001, Ihsen Alouani |
DATE | 4 |
| 2021 | LSTM-based System for Multiple Obstacle Detection using Ultra-wide Band RadarabstractAutonomous vehicles present a promising opportunity in the future of transportation systems by providing road safety. As significant progress has been made in the automatic environment perception, the detection of road obstacles remains a major challenge. Thus, to achieve reliable obstacle detection, several sensors have been employed. For short ranges, the Ultra-Wide Band (UWB) radar is utilized in order to detect objects in the near field. However, the main challenge appears in distinguishing the real target’s signature from noise in the received UWB signals. In this paper, we propose a novel framework that exploits Recurrent Neural Networks (RNNs) with UWB signals for multiple road obstacle detection. Features are extracted from the time-frequency domain using the discrete wavelet transform and are forwarded to the Long short-term memory (LSTM) network. We evaluate our approach on the OLIMP dataset which includes various driving situations with complex environment and targets from several classes. The obtained results show that the LSTM-based system outperforms the other implemented related techniques in terms of obstacle detection. Amira Mimouna, Anouar Ben Khalifa, Ihsen Alouani, Abdelmalik Taleb-Ahmed, Atika Rivenq, Najoua Essoukri Ben Amara |
ICAART (2) | 3 |
| 2021 | Lower Voltage for Higher Security: Using Voltage Overscaling to Secure Deep Neural NetworksabstractDeep neural networks (DNNs) are shown to be vulnerable to adversarial attacks—carefully crafted additive noise that undermines DNNs integrity. Previously proposed defenses against these attacks require substantial overheads, making it challenging to deploy these solutions in power and computational resource-constrained devices, such as embedded systems and the Edge. In this paper, we explore the use of voltage over-scaling (VOS) as a lightweight defense against adversarial attacks. Specifically, we exploit the stochastic timing violations of VOS to implement a moving-target defense for DNNs. Our experimental results demonstrate that VOS guarantees effective defense against different attack methods, does not require any software/hardware modifications, and offers a by-product reduction in power consumption. Ihsen Alouani, Khaled N. Khasawneh |
ICCAD | 2 |
| 2020 | NeuroAttack: Undermining Spiking Neural Networks Security through Externally Triggered Bit-FlipsabstractDue to their proven efficiency, machine-learning systems are deployed in a wide range of complex real-life problems. More specifically, Spiking Neural Networks (SNNs) emerged as a promising solution to the accuracy, resource-utilization, and energy-efficiency challenges in machine-learning systems. While these systems are going mainstream, they have inherent security and reliability issues. In this paper, we propose NeuroAttack, a cross-layer attack that threatens the SNNs integrity by exploiting low-level reliability issues through a high-level attack. Particularly, we trigger a fault-injection based sneaky hardware backdoor through a carefully crafted adversarial input noise. Our results on Deep Neural Networks (DNNs) and SNNs show a serious integrity threat to state-of-the art machine-learning techniques. Valerio Venceslai, Alberto Marchisio, Ihsen Alouani, Maurizio Martina, Muhammad Shafique 0001 |
IJCNN | 3 |
| 2020 | A novel multi-view pedestrian detection database for collaborative Intelligent Transportation Systems
Anouar Ben Khalifa, Ihsen Alouani, Mohamed Ali Mahjoub, Atika Rivenq |
Future Gener. Comput. Syst. | 2 |
| 2020 | A novel public dataset for multimodal multiview and multispectral driver distraction analysis: 3MDAD
Imen Jegham, Anouar Ben Khalifa, Ihsen Alouani, Mohamed Ali Mahjoub |
Signal Process. Image Commun. | 3 |
| 2019 | MDAD: A Multimodal and Multiview in-Vehicle Driver Action Dataset
Imen Jegham, Anouar Ben Khalifa, Ihsen Alouani, Mohamed Ali Mahjoub |
CAIP (1) | 3 |
| 2019 | A new memory reliability technique for multiple bit upsets mitigationabstractTechnological advances make it possible to produce increasingly complex electronic components. Nevertheless, these advances are convoyed by an increasing sensitivity to operating conditions and an accelerated aging process. In safety critical applications, it is vital to provide solutions to avoid these limitations and to guarantee a high level of reliability. In most of the existing methods in the literature only Single Event Upsets (SEU) are assumed. The next generations of embedded systems must on one side support Multiple-Bit Upsets (MBU) and avoid to induce a significant memory and processing overheads on the other side. This paper proposes a new method to increase the reliability of SRAM, without dramatically increasing costs in memory space and processing time. Our method, named DPSR for Double Parity Single Redundancy, offers a high level of reliability and takes into fault patterns occurring in real conditions. Alexandre Chabot, Ihsen Alouani, Smaïl Niar, Réda Nouacer |
CF | 2 |
| 2019 | Facial Expression Recognition Based on DWT Feature for Deep CNNabstractFacial expressions recognition have become one of the most important fields of research in pattern recognition, in this paper, we propose a method to identify the facial expressions of the people through their emotions, this method combining Viola-Jones face detection algorithm, Facial image enhancement using histogram equalization, discrete wavelet transform (DWT) and deep convolution neural network. Extraction results of facial features using DWT are the input of CNN, which are used directly to train the CNN network. Our experimental were performed on CK+ database and JAFFE face database, the obtained results based on this network is 96.46% and 98.43% respectively. Ridha Ilyas Bendjillali, Mohammed Beladgham, Khaled Merit, Abdelmalik Taleb-Ahmed, Ihsen Alouani |
CoDIT | 5 |
| 2019 | HEAP: A Heterogeneous Approximate Floating-Point Multiplier for Error Tolerant ApplicationsabstractFloating point arithmetic is one of the most commonly used units in nowadays computing systems and is deployed for a wide range of domains and applications. While floating point operators offer high precision calculations, a plethora of applications such as multimedia processing and machine learning tolerate errors and computation imprecision. In a context of limited power budget embedded systems, saving resources and energy with an acceptable precision loss is a challenging design task. Approximate computing is an emerging systems design paradigm that offers promising balance between accuracy on the one hand and power consumption and resource utilization on the other hand. While state of the art approximate techniques offer a wide design space at the operator level, few are the works that consider exploring different techniques to build a heterogeneous comprehensive approximate design. In this paper, we propose HEAP: a heterogeneous approximate floating point multiplier. Based on a design space exploration process, we present an approximation at the transistor level that reduces energy consumption of up to 68%. Experimental study on a set of machine learning applications shows promising results with comparable accuracy to exact multiplier based systems. Amira Guesmi, Ihsen Alouani, Mouna Baklouti, Tarek Frikha, Mohamed Abid, Atika Rivenq |
RSP | 2 |
| 2018 | A Reliability Study on CNNs for Critical Embedded SystemsabstractDeep learning systems such as Convolutional Neural Networks (CNNs) have shown remarkable efficiency in dealing with a variety of complex real life problems. To accelerate the execution of these heavy algorithms, a plethora of software implementations and hardware accelerators have been proposed. In a context of shrinking devices dimensions, reliability issues of CNN-hosting systems are under-explored. In this paper, we experimentally evaluate the inherent fault tolerance of CNNs by injecting errors within network modules, namely processing elements and memories. Our experiments demonstrate a non uniform sensitivity between different parts of the system. While CNNs are relatively resilient to errors occurring in processing elements, transient faults hitting memories lead to catastrophic degradation of accuracy. Mohamed A. Neggaz, Ihsen Alouani, Pablo R. Lorenzo, Smaïl Niar |
ICCD | 2 |
| 2018 | A Comprehensive Fault Injection Strategy for Embedded Systems Reliability AssessmentabstractThe embedded systems industry is moving towards the integration of higher performance, yet less reliable electronic components into new product generations. Technology and voltage scaling increased dramatically the susceptibility of new devices not only to Single Bit Upsets (SBU), but also to Multiple Bit Upsets (MBU). However, the system reliability assessment at the design phase of fault-tolerant computer systems is a complex and critical task. In this context, it is mandatory to enhance reliability analysis and evaluation techniques at early-stage of the system development. In this paper, we present a technique for reliability evaluation of embedded systems at early-stage by taking into account the application behavior and SBU/MBU phenomena. Instead of using the random fault injection, our approach models the architecture behavior under real working conditions. Our results demonstrate the efficiency of the proposed fault injection simulation platform for early-stage reliability studies. Alexandre Chabot, Ihsen Alouani, Smaïl Niar, Réda Nouacer |
RSP | 2 |
| 2017 | Adaptive Reliability for Fault Tolerant Multicore SystemsabstractIn an era of continuously shrinking technology and escalating power density, Multiprocessor System on Chips (MPSoCs) suffer from a growing prominence of device defects and increase of dependability-related issues. This paper tackles the dependability challenge by suggesting an adaptive reliability enhancement strategy for multicore systems. We dynamically adapt the reliability enhancement to the actual tasks requirements as well as cores runtime operating conditions. As reliability improvement may adversely affect the parameters of embedded systems, we suggest a runtime recovery method. In fact, we implement a 3-mode mapping technique to limit redundancy overheads through judicious task migrating and dropping. Our experiments show promising results in terms of error mitigation with controllable power and thermal overheads. Ihsen Alouani, Thomas Wild, Andreas Herkersdorf, Smaïl Niar |
DSD | 1 |
| 2016 | NS-SRAM: Neighborhood Solidarity SRAM for Reliability Enhancement of SRAM MemoriesabstractTechnology shift and voltage scaling increased the susceptibility of Static Random Access Memories (SRAMs) to errors dramatically. In this paper, we present NS-SRAM, for Neighborhood Solidarity SRAM, a new technique to enhance error resilience of SRAMs by exploiting the adjacent memory bit data. Bit cells of a memory line are paired together in circuit level to mutually increase the static noise margin and critical charge of a cell. Unlike existing techniques, NS-SRAM aims to enhance both Bit Error Rate (BER) and Soft Error rate (SER) at the same time. Due to auto-adaptive joiners, each of the adjacent cells' nodes is connected to its counterpart in the neighbor bit. NS-SRAM enhances read-stability by increasing critical Read Static Noise Margin (RSNM), thereby decreasing faults when circuit operates under voltage scaling. It also increases hold-stability and critical charge to mitigate soft-errors. By the proposed technique, reliability of SRAM based structures such as cache memories and register files can drastically be improved with comparable area overhead to existing hardening techniques. Moreover it does not require any extra-memory, does not impact the memory effective size, and has no negative impact on performance. Ihsen Alouani, Hamzeh Ahangari, Ozcan Ozturk 0001, Smaïl Niar |
DSD | 1 |
| 2015 | A multi-objective approach for software/hardware partitioning in a multi-target tracking systemabstractHeterogeneous Multiprocessor System-on-Chips (MPSoCs) are getting increasingly used to cope with new embedded applications performance requirements. In such systems, the promising cohabitation of processing elements (PEs) having different aspects allows designers to better exploit the synergy of hardware and software cores. Software/Hardware partitioning investigates the design of MPSOCs to take advantage of software flexibility and hardware high performance with the lowest possible costs. Signal-processing-oriented systems handle huge amounts of data and consequently demand highly performant architecture. In this paper, we propose a Software/Hardware partitioning approach for high speed reconfigurable DSP-oriented embedded systems. We present two multi-objective techniques aiming at exploring the partitioning configurations that minimize execution time, resource utilization and time to market of the MPSoC. Ihsen Alouani, Braham Lotfi Mediouni, Smaïl Niar |
RSP | 1 |
| 2012 | Parity-based mono-Copy Cache for low power consumption and high reliabilityabstractThe power consumption is one of the most important preoccupations of the chip designers. However, reducing power consumption has its negative impact on the circuit. For example, reducing the supply voltage of a microprocessor implies an increase in the probability of process-variation-induced failures. Fault tolerant architectures propose a trade-off by boosting the reliability while reducing power consumption. Since a large part of the microprocessor power is consumed by the cache memory, we propose in this paper the Parity-based mono-Copy Cache (PmC2) that maintains cache reliability under aggressive voltage scaling. PmC2results in reducing energy consumption considerably with very low performance penalty. PmC2uses a parity check mechanism in error detection and only one cache block redundancy for error correction. Our experimental results demonstrate that reducing the supply voltage with roughly 25% of nominal Vdd achieves more than 62% reduction in cache power consumption with a negligible IPC loss that does not exceed 0.15%. Ihsen Alouani, Smaïl Niar, Fadi J. Kurdahi, Mohamed Abid |
RSP | 1 |