VLDB 2026 Research / reviewers in the wild / expert
Brojo Gopal Sapui
dblp:185/5736 · also Brojogopal Sapui
· DBLP profile ↗
11ranked-venue papers
8as first author
11since 2021 · last 2026
0009-0003-2657-4205ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 11 · 8 first-author · 11 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HyFault: Targeted Fault Injection Attacks on Hyperdimensional Computing AcceleratorsabstractEdge AI accelerators are a critical building block of numerous AI-driven applications deployed in resource-constrained environments such as IoT, automotive systems, and wearable devices. Hyperdimensional Computing (HDC) has recently emerged as a promising lightweight AI model for these edge scenarios, offering efficiency, simplicity, and inherent robustness against random computational faults. However, despite its advantages, the security implications of deploying HDC accelerators, particularly their resilience against targeted fault injection attacks, remain insufficiently explored. Such attacks pose tangible security risks, including intentional misclassification leading to denial-of-service or reliability degradation in critical decision-making systems. In this work, we precisely attack FPGA-based HDC accelerators using profiling and advanced voltage-level fault injection methods to evaluate their vulnerability. Our experiments reveal significant susceptibility during the critical similarity computation phase of the HDC inference pipeline, achieving targeted misclassification rates of up to ≈89%. To address these security vulnerabilities, we propose XOR masking and query hypervector randomization as practical, hardware-friendly countermeasures. Extensive real hardware evaluations confirm that these defenses substantially reduce misclassification rates to ≈2%, significantly enhancing the security and reliability of edge-deployed accelerators. Brojo Gopal Sapui, Mehdi Baradaran Tahoori |
ASP-DAC | 1 |
| 2026 | When Faults Don't Vanish: Persistent Fault Injection and Key Recovery on MRAM-Backed AESabstractSpin-Transfer Torque MRAM (STT-MRAM) is gaining popularity as a leading non-volatile memory (NVM) for embedded, IoT, and automotive systems, owing to its low leakage, high endurance, and compatibility with CMOS processes. However, its magnetic nature and non-volatility feature introduce unique fault behaviors that differ fundamentally from conventional volatile memories such as SRAM and DRAM. In particular, faults injected during MRAM write operations may persist across power cycles, enabling attackers to exploit stable key corruptions. In this work, we present a persistent fault analysis (PFA) framework targeting AES implementations where the round-key schedule is stored in STT-MRAM. We demonstrate how carefully timed voltage glitches during MRAM write cycles can create reproducible, persistent bit flips that propagate through the AES key schedule. These persistent corruptions significantly reduce the ciphertext requirements for differential fault analysis (DFA) and enable statistical persistent fault analysis (SPFA) with only 12–17 faulty ciphertexts. These findings highlight that MRAM-based systems are exposed to a persistent-fault threat model different from transient faults in volatile memories, with direct implications for secure key storage and cryptographic implementations. Brojo Gopal Sapui, Priyanjana Pal, Mehdi Baradaran Tahoori |
DATE | 1 |
| 2025 | Side-channel Collision Attacks on Hyper-Dimensional Computing based on Emerging Resistive MemoriesabstractBrain-inspired architectures are increasingly favored for edge devices due to their efficient execution of cognitive tasks with limited energy and computational resources. A promising approach in this field is Hyper-Dimensional Computing (HDC), known for its robustness against noise and simple computational operations, despite being constrained by memory bandwidth. HDC is well-suited for computation in memory (CiM) using emerging resistive memory technologies. However, security concerns arise from potential attack vectors in HDC, spanning from computational algorithms to the underlying technology. Since HDC relies on unique data patterns, or class hypervectors, stored in memory, there is a risk of undetected data manipulation or poisoning. We demonstrate that power information from insensitive (public) outputs can expose secret data stored in memories. This study investigates side-channel vulnerabilities in Content Addressable Memory (CAM)-HDC implemented with resistive memory-based CiM. We develop a collision attack using side-channel information to recover predicted classes from all possible outputs accurately. Our findings highlight a security threat in HDC even with parallel computation between query and class hypervectors. To address this vulnerability, we propose an effective countermeasure based on a hiding technique for CiM implementation, mitigating the identified security risks. Brojo Gopal Sapui, Mehdi Baradaran Tahoori |
ASP-DAC | 1 |
| 2025 | Invited Paper: Side Channel Vulnerability Analysis of Flexible Neuromorphic CircuitsabstractThe rapid advancement of flexible electronics (FE) has driven significant innovation across diverse sectors, including healthcare, wearables, smart packaging, and IoT devices, owing to their adaptability, lightweight form factor, and cost-effectiveness compared to traditional silicon-based electronics. A key computing paradigm in this domain is bespoke classifiers, where model parameters are hardcoded in neuromorphic hardware to meet strict area, power, and cost constraints. By tailoring bespoke hardware to specific tasks, these circuits achieve significant accuracy under tight resource budgets but also introduce distinct security vulnerabilities. The intrinsic flexibility of substrates, unconventional manufacturing processes, and limited protective packaging make such systems particularly vulnerable to security threats, with side-channel attacks (SCAs) being a critical concern. In this work, we systematically investigate SCA vulnerabilities in bespoke TFT-based multilayer perceptron (MLP) classifiers, considering both analog (flexible analog multilayer perceptron (f-AMLP)) and digital (flexible digital multilayer perceptron (f-DMLP)) realizations. For digital classifiers, we apply correlation power analysis (CPA), leveraging well-established leakage models from silicon-based systems. For analog classifiers, where leakage is continuous, nonlinear, and strongly influenced by device-level variability, we develop a tailored convolutional neural network (CNN)-based regression attack capable of extracting inputs from noisy power traces. Experimental results across benchmark datasets show that f-DMLPs can be compromised with 70–85% cumulative attack success rate (ASR) after ≈ 4k–5k traces using CPA, while f-AMLPs, though slower to attack initially, reach up to 90–95% ASR after ≈ 8k–9k traces with CNN-based approach. Priyanjana Pal, Brojo Gopal Sapui, Mehdi Baradaran Tahoori |
ICCAD | 2 |
| 2025 | Leaks beyond Bits: Deep Learning-Assisted Side-Channel Attacks on Hyperdimensional Computing AcceleratorsabstractHyperdimensional Computing (HDC) has emerged as a promising lightweight machine learning approach suitable for edge and Internet-of-Things (IoT) applications due to its inherent energy efficiency and robustness in noisy environments. Despite these advantages, recent research has shown that FPGA-based HDC accelerators are susceptible to model inversion and physical attacks. In this paper, we propose a specialized Convolutional Neural Network (CNN)-based side-channel analysis (SCA) designed to extract stored hypervector bits from FPGA-implemented HDC models. After identifying the location of CNN-extracted leakages, we introduce an adaptive Gradient-weighted Class Activation Mapping (Grad-CAM)-guided approach to achieve much more effective attack results. This adaptive technique iteratively highlights critical leakage regions, enabling a targeted and efficient improvement of the signal-to-noise ratio (SNR), accelerating the attack by rapidly narrowing down essential leakage intervals. Using approximately one million power traces obtained from a dedicated ChipWhisperer Pro measurement setup during HDC inference, our adaptive CNN-based method achieves a bit extraction accuracy of up to 93%, reaching nearly 2× the accuracy of the non-adaptive baseline with half as many traces, and ultimately providing 1.7× higher maximum bit extraction accuracy. We further analyze the robustness of the identified leakages across multiple FPGA architectures under different noise conditions. To counteract these vulnerabilities, we introduce a dynamic masking scheme that effectively reduces CNN bit extraction accuracy to ≈ 18%, with minimal overhead on FPGA resources (around 1.6× increase in LUT usage and 1.4× increase in latency). Furthermore, we validate the effectiveness of our protection scheme through a higher order test vector leakage assessment (TVLA), confirming a significantly reduced leakage with a t-value of ≈ 2.2. Brojo Gopal Sapui, Mehdi Baradaran Tahoori |
ICCAD | 1 |
| 2025 | Collide & Conquer: Side-channel Attack on Hyper-dimensional Computing (HDC) AcceleratorsabstractHyper-dimensional computing (HDC), a brain-inspired architecture, is gaining attention for edge AI due to its noise resilience and suitability for resource-constrained environments. However, its deployment in safety-critical domains exposes HDC to critical security vulnerabilities, including data poisoning and intellectual property (IP) theft. We demonstrate a practical side-channel attack on an FPGA-based binary HDC accelerator using voltage fluctuations captured by Time-to-Digital Converters (TDC) sensors to extract its IP, such as class hypervectors. By introducing collision analysis combined with an implicit triggering mechanism, we achieve a maximum of ≈83% bit recovery of a single class hypervector using a few hundred traces, even under parallel operations. We also discuss a randomization counter-measure that effectively reduces the recovery accuracy to ≈19% without sacrificing classification performance. Brojo Gopal Sapui, Mahboobe Sadeghipourrudsari, Mehdi Baradaran Tahoori |
ITC-Asia | 1 |
| 2025 | Efficient Analog Error Correction for Printed Unary-Encoded ComputingabstractPrinted electronics (PE) is an emerging additive manufacturing technology, enabling flexible and extremely lowcost computing devices for future pervasive computing systems. Given the form factor and limited device count in this technology, Unary Encoding (UE), which encodes values as a sequence of bits (1’s or 0’s) by utilizing the proportion of 1’s in the sequence to represent the corresponding probability, shows great promise for printed technologies targeting resource-constrained applications. However, while UE offers some resilience to noise and variability, explicit error correction is still required to address intrinsic defects and variations in printing technologies to deliver reliable and stable outputs. In this work, we propose an area-efficient analog error correction (AEC) method using UE techniques to deal with sporadic bit errors and environmental noise at runtime. This approach significantly reduces transistor count and area utilization compared to conventional error correction coding (ECC) implementations. For proof of concept, we have shown the applicability of this approach for printed physical unclonable functions (p-PUFs) which have significantly lower reliability than silicon-based counterparts. Moreover, the robustness of the proposed scheme against temperature and voltage fluctuations has also been reported. By applying AEC to the p-PUFs output bitstream, its reliability can be fully restored (statistically 100%) for up to 20% bit error rate. Priyanjana Pal, Brojo Gopal Sapui, Dennis Weller, Mehdi Baradaran Tahoori |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2024 | Power Side-Channel Analysis and Mitigation for Neural Network Accelerators based on Memristive CrossbarsabstractThe modern trend of exploring Artificial Intelligence (AI) in various industries, such as big data, edge computing, automobile, and medical applications, has increased tremendously. As functionalities grow, energy-efficient hardware for AI devices becomes crucial. To address that, Computation-in-Memory (CiM) using Non-Volatile Memories (NVMs) offers a promising solution. However, security is also an important concern in this computation paradigm. In this work, we analyze the vulnerability for power side-channel attacks on Multiply-Accumulate (MAC) operations implemented in CiM architecture based on emerging NVMs. Our results show that peripheral devices such as Analog-to-Digital Converters (ADCs) leak much more sensitive information than the crossbar itself because of its significant power consumption. Therefore, we propose a circuit-level countermeasure based on hiding for the ADCs of memristive CiM architecture to mitigate the power attacks. The efficiency of our proposed countermeasure is shown by both attacks and leakage assessment methodologies using a maximum of one million measurement traces. Brojo Gopal Sapui, Mehdi Baradaran Tahoori |
ASPDAC | 1 |
| 2024 | Side-Channel Attack with Fault Analysis on Memristor-based Computation-in-MemoryabstractThe inherent limitations of traditional processor-centric architectures have led to the emergence of Computationin-Memory (CiM), offering an energy-efficient hardware solution for diverse applications such as deep learning and cryptography. However, CiM’s analog domain computations, relying on curren sensing for output, expose potential vulnerabilities to glitch-based fault injections. These are still unexplored in CiM and can prevent their widespread adoption. Our work investigates side-channel vulnerabilities in scouting logic CiM, revealing that an attacker can extract sensitive information with minimal measurements through side-channel analysis based on an effective Fault Sen sitivity Analysis (FSA). We demonstrate that with access to data-dependent delays at the transient output level, correlation analysis between fault sensitivity and transient output characteristics facilitates input data recovery. To counter these threats, we propose a power- and area-efficient circuit-level countermeasure tailored for CiM architectures, proving its effectiveness through comprehensive assessments, including correlation attacks and Test Vector Leakage Analysis (TVLA) with one million traces. Brojo Gopal Sapui, Sergej Meschkov, Mehdi Baradaran Tahoori |
IOLTS | 1 |
| 2023 | Highly-Bespoke Robust Printed Neuromorphic CircuitsabstractWith the rapid growth of the Internet of Things, smart fast-moving consumer products, and wearable devices, requirements such as flexibility, non-toxicity, and low cost are desperately required. However, these requirements are usually beyond the reach of conventional rigid silicon technologies. In this regard, printed electronics offers a promising alternative. Combined with neuromorphic computing, printed neuromorphic circuits offer not only the aforementioned properties, but also compensate for some of the weaknesses of printed electronics, such as manufacturing variations, low device count, and high latency. Generally, (printed) neuromorphic circuits express their functionality through printed resistor crossbars to emulate matrix multiplication, and nonlinear circuitry to express activation functions. The values of the former are usually learned, while the latter is designed beforehand and considered fixed in training for all tasks. The additive manufacturing feature of printed electronics allows the design of highly-bespoke designs. In the case of printed neuromorphic circuits, the circuit is optimized to a particular dataset. Moreover, we explore an approach to learn not only the values of the crossbar resistances, but also the parameterization of the nonlinear components for a bespoke implementation. While providing additional flexibility of the functionality to be expressed, this will also allow an increased robustness against printing variation. The experiments show that the accuracy and robustness of printed neuromorphic circuits can be improved by 26% and 75% respectively under 10% variation of circuit components. Haibin Zhao, Brojo Gopal Sapui, Michael Hefenbrock, Zhidong Yang, Michael Beigl, Mehdi Baradaran Tahoori |
DATE | 2 |
| 2023 | Power Side-Channel Attacks and Countermeasures on Computation-in-Memory Architectures and TechnologiesabstractTo overcome the bottleneck of the classical processor-centric architectures, Computation-in-Memory (CiM) is a promising paradigm where operations are performed directly in memory. Recent works propose the use of CiM to accelerate neural networks or hyperdimensional computing, but also for memory encryption solutions. As CiM facilitates the computation in the analog domain and the output is driven through current sensing, CiM could potentially be highly vulnerable to power side-channel attacks. In this work, we analyze the vulnerability for power side-channel attacks in various CiM implementations based on Static Random Access Memory (SRAM) and emerging nonvolatile memristive technologies. Our results show that a side-channel attacker can recover secret data used in an XOR operation with only a few hundred measurements, where CiM architectures based on emerging memristive technologies are more vulnerable than SRAM-based CiM. Therefore, we propose two different types of countermeasures based on hiding and masking, which are tailored to CiM architectures. The efficiency of our proposed countermeasures is shown by both attacks and leakage assessment methodologies using one million measurement traces. Brojo Gopal Sapui, Jonas Krautter, Mahta Mayahinia, Atousa Jafari, Dennis Gnad, Sergej Meschkov, Mehdi Baradaran Tahoori |
ETS | 1 |