EDBT 2026 Demo / reviewers in the wild / expert
Jonas Krautter
dblp:228/7701
· DBLP profile ↗
20ranked-venue papers
5as first author
17since 2021 · last 2024
0000-0002-7492-5319ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 20 · 5 first-author · 17 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | In-Field Detection of Small Delay Defects and Runtime Degradation Using On-Chip SensorsabstractThe increasing safety requirements for modern complex systems mandate Silicon Lifecycle Management (SLM) using various sensors for in-field test. In this work, we evaluate so-called Path Transient Monitors (PTMs), which are based on delay lines, to detect path delay increase caused by manufacturing defects or runtime degradation. These sensors are integrated into a RISC-V SoC on an FPGA, allowing software-controlled measurements and calibration. Additionally, we introduce means to emulate delay defects and degradations by injecting additional delay elements into a custom add instruction. Furthermore, by using power wasters, we provoke runtime voltage variations. Our evaluation in different temperatures shows the dependencies between different sources of delay variations and how the sensors can help in better detection of delay defects. Seyedeh Maryam Ghasemi, Sergej Meschkov, Jonas Krautter, Dennis Gnad, Mehdi Baradaran Tahoori |
DATE | 3 |
| 2024 | OTFGEncoder - HDC: Hardware-efficient Encoding Techniques for Hyperdimensional ComputingabstractHyper-Dimensional Computing (HDC), a brain-inspired computing paradigm for cognitive tasks, is especially suited for resource-constrained edge devices due to its hardware-efficient and fault-resistant inference. However, existing HDC approaches require large amounts of memory, resulting in high power consumption, limiting their use in edge devices. We offer a hardware-aware encoding where computation parameters in hardware implementations can be reproduced on-the-fly through low-overhead cyclic digital circuits, significantly reducing memory utilization and subsequently power consumption. Mahboobe Sadeghipourrudsari, Jonas Krautter, Mehdi Baradaran Tahoori |
DATE | 2 |
| 2024 | Degradation Monitoring Through Software-controlled On-chip Sensors for RISC-VabstractComplex systems are subject to various hardware and software defects and faults through the entire design and deployment lifecycle. Many of such defects originate at the electrical or circuit levels, but manifest as functional failures in the field. In this study, we present a methodology for embedding and employing software-controlled runtime variation and degradation sensors on a RISC-V SoC to enable system-level and functional testing in the field. We demonstrate the effectiveness of the entire platform through an FPGA implementation. Delay defects and path degradations are emulated by injecting artificial delay elements into the critical path of a specific instruction. We also emulate the effect of workload-induced runtime stress with tunable software-controlled power wasters. Combining various sensors, we show that transient fluctuations, which are caused by temperature or workload, can be effectively separated from persistent delay increase, which is caused by latent manufacturing defects or aging. Seyedeh Maryam Ghasemi, Jonas Krautter, Tara Gheshlaghi, Sergej Meschkov, Dennis Gnad, Mehdi Baradaran Tahoori |
ETS | 2 |
| 2024 | Reliability and Security of AI HardwareabstractIn recent years, Artificial Intelligence (AI) systems have achieved revolutionary capabilities, providing intelligent solutions that surpass human skills in many cases. However, such capabilities come with power-hungry computation workloads. Therefore, the implementation of hardware acceleration becomes as fundamental as the software design to improve energy efficiency, silicon area, and latency of AI systems. Thus, innovative hardware platforms, architectures, and compiler-level approaches have been used to accelerate AI workloads. Crucially, innovative AI acceleration platforms are being adopted in application domains for which dependability must be paramount, such as autonomous driving, healthcare, banking, space exploration, and industry 4.0. Unfortunately, the complexity of both AI software and hardware makes the dependability evaluation and improvement extremely challenging. Studies have been conducted on both the security and reliability of AI systems, such as vulnerability assessments and countermeasures to random faults and analysis for side-channel attacks. This paper describes and discusses various reliability and security threats in AI systems, and presents representative case studies along with corresponding efficient countermeasures. Dennis Gnad, Martin Gotthard, Jonas Krautter, Angeliki Kritikakou, Vincent Meyers, Paolo Rech, Josie E. Rodriguez Condia, Annachiara Ruospo, Ernesto Sánchez 0001, Fernando Santos 0001, Olivier Sentieys, Mehdi Baradaran Tahoori, Russell Tessier, Marcello Traiola |
ETS | 3 |
| 2024 | E3HDC: Energy Efficient Encoding for Hyper-Dimensional Computing on Edge DevicesabstractHyper-Dimensional Computing (HDC) as a brain-inspired computational model for cognitive tasks is suitable for edge devices due to its hardware-friendly and fault-resistant computations. Despite this potential, HDC has a large memory footprint, resulting high power consumption. In this work, we propose a hardware-aware encoding where parameters are generated on-the-fly without any large memory block requirements. Moreover, the hardware mapping of the trained HDC model is optimized to make it suitable for resource-constraint edge devices. In this work we propose an end-to-end flow from HDC training to FPGA mapping. We demonstrate the efficiency of this method compared to other state-of-the-art HDC implementations in terms of hardware usage and power consumption. Mahboobe Sadeghipourrudsari, Jonas Krautter, Vincent Meyers, Mehdi Baradaran Tahoori |
FPL | 2 |
| 2024 | Fuzz Wars: The Voltage Awakens - Voltage-Guided Blackbox Fuzzing on FPGAsabstractThe growing complexity and size of hardware designs necessitates novel, scalable approaches to verification, as latent bugs and security flaws have devastating impact. This is especially critical since bugs in hardware designs cannot be patched after manufacturing. Currently, dynamic verification is the predominant methodology for detecting hardware design flaws, where detection efficiency is primarily determined by the choice of (random) inputs to the design under test. More elaborate recent methods adapt principles from greybox software fuzzing to achieve high coverage in short time. However, these existing greybox methods rely on heavy instrumentation or software conversion, which requires access to the design source code. Fuzing of blackbox hardware designs has only been possible with random, undirected input generation up until now, which requires a long time to cover the majority of possible hardware states. In this work, we propose FUZZ-E, a novel scalable method for coverage-guided hardware design fuzzing, where coverage is indirectly estimated through on-chip voltage measurements on FPGAs. The side-channel-based FUZZ-E approach enables testing blackbox hardware designs without requiring access to any internal signals. We provide an extensive analysis of the correlation between hardware design coverage and voltage fluctuations, and show how FUZZ-E significantly reduces the verification time required to achieve desirable design coverage. Mark Giraud, Anne Borcherding, Jonas Krautter, Philipp Nenninger, Mehdi Baradaran Tahoori |
VTS | 4 |
| 2024 | Meta-Scanner: Detecting Fault Attacks via Scanning FPGA Designs MetadataabstractWith the rise of the big data, processing in the cloud has become more significant. One method of accelerating applications in the cloud is to use field programmable gate arrays (FPGAs) to provide the needed acceleration for the user-specific applications. Multitenant FPGAs are a solution to increase efficiency. In this case, multiple cloud users upload their accelerator designs to the same FPGA fabric to use them in the cloud. However, multitenant FPGAs are vulnerable to low-level denial-of-service attacks that induce excessive voltage drops using the legitimate configurations. Through such attacks, the availability of the cloud resources to the nonmalicious tenants can be hugely impacted, leading to downtime and thus financial losses to the cloud service provider. In this article, we propose a tool for the offline classification to identify which FPGA designs can be malicious during operation by analysing the metadata of the bitstream generation step. We generate and test 475 FPGA designs that include 38% malicious designs. We identify and extract five relevant features out of the metadata provided from the bitstream generation step. Using ten-fold cross-validation to train a random forest classifier, we achieve an average accuracy of 97.9%. This significantly surpasses the conservative comparison with the state-of-the-art approaches, which stands at 84.0%, as our approach detects stealthy attacks undetectable by the existing methods. Hassan Nassar, Jonas Krautter, Lars Bauer, Dennis Gnad, Mehdi Baradaran Tahoori, Jörg Henkel |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2023 | FPGANeedle: Precise Remote Fault Attacks from FPGA to CPUabstractFPGA as general-purpose accelerators can greatly improve system efficiency and performance in cloud and edge devices alike. However, they have recently become the focus of remote attacks, such as fault and side-channel attacks from one to another user of a part of the FPGA fabric. In this work, we consider system-on-chip platforms, where an FPGA and an embedded processor core are located on the same die. We show that the embedded processor core is vulnerable to voltage drops generated by the FPGA logic. Our experiments demonstrate the possibility of compromising the data transfer from external DDR memory to the processor cache hierarchy. Furthermore, we were also able to fault and skip instructions executed on an ARM Cortex-A9 core. The FPGA based fault injection is shown precise enough to recover the secret key of an AES T-tables implementation found in the mbedTLS library. Mathieu Gross, Jonas Krautter, Dennis Gnad, Michael Gruber, Georg Sigl, Mehdi Baradaran Tahoori |
ASP-DAC | 2 |
| 2023 | Power Side-Channel Attacks and Countermeasures on Computation-in-Memory Architectures and TechnologiesabstractTo overcome the bottleneck of the classical processor-centric architectures, Computation-in-Memory (CiM) is a promising paradigm where operations are performed directly in memory. Recent works propose the use of CiM to accelerate neural networks or hyperdimensional computing, but also for memory encryption solutions. As CiM facilitates the computation in the analog domain and the output is driven through current sensing, CiM could potentially be highly vulnerable to power side-channel attacks. In this work, we analyze the vulnerability for power side-channel attacks in various CiM implementations based on Static Random Access Memory (SRAM) and emerging nonvolatile memristive technologies. Our results show that a side-channel attacker can recover secret data used in an XOR operation with only a few hundred measurements, where CiM architectures based on emerging memristive technologies are more vulnerable than SRAM-based CiM. Therefore, we propose two different types of countermeasures based on hiding and masking, which are tailored to CiM architectures. The efficiency of our proposed countermeasures is shown by both attacks and leakage assessment methodologies using one million measurement traces. Brojo Gopal Sapui, Jonas Krautter, Mahta Mayahinia, Atousa Jafari, Dennis Gnad, Sergej Meschkov, Mehdi Baradaran Tahoori |
ETS | 2 |
| 2023 | Power2Picture: Using Generative CNNs for Input Recovery of Neural Network Accelerators through Power Side-Channels on FPGAsabstractArtificial neural networks pervade almost all areas of today's life, being used for both simple image classification tasks as well as highly complex decision making in mission-critical tasks. This makes artificial neural networks an attractive target for attackers to recover the model architecture or user inputs and outputs through either classical software vulnerabilities or hardware side-channel and fault attacks. With increasing complexity of the models, smaller companies now often opt for pre-trained public models, which are then used with potentially sensitive inputs, for instance, in medical applications. In this work, we present a novel remote side-channel attack methodology to steal neural network inputs using generative convolutional neural networks. After measuring voltage fluctuations using on-chip sensors, we are able to recover the original inputs to image classifiers on different FPGA platforms. Our results prove the effectiveness of our attack, as we are able to recover inputs from networks running on different devices, with different datasets, and under different operating conditions. Lukas Huegle, Martin Gotthard, Vincent Meyers, Jonas Krautter, Dennis Gnad, Mehdi Baradaran Tahoori |
FCCM | 4 |
| 2023 | Stress-Resiliency of AI Implementations on FPGAsabstractFPGAs have become a popular choice for machine learning acceleration for both cloud and edge devices. While traditional neural networks show impressive performance in classification tasks, Hyperdimensional Computing (HDC) is rapidly emerging as a promising novel machine learning approach for its hardware-friendly inference. In HDC, classes are embedded into high-dimensional vectors during training, and inputs can be classified by computing similarity metrics between class-vectors during inference. HDC inference is especially promoted in terms of its resiliency against errors, attributed to the large inherent redundancy. In this work, we perform a thorough experimental investigation of the fault resiliency of various FPGA-based machine learning implementations under different aspects of stress, comparing HDC with classical neural network approaches. We explore both the amount of faulty classifications as well as system crashes while subjecting the designs to timing stress using overclocking, voltage stress with excessive switching activity, and thermal stress. Jonas Krautter, Paul R. Genssler, Gloria Sepanta, Hussam Amrouch, Mehdi Baradaran Tahoori |
FPL | 1 |
| 2023 | SLM ISA and Hardware Extensions for RISC-V ProcessorsabstractNowadays, RISC-V processors have attracted much attention due to their extendability, for targeting high performance applications with strict demands on functional safety. Silicon Lifecycle Management (SLM) is a new emerging concept aiming at functional safety among other features such as availability, maintainability, and lifetime extension. This concept helps to monitor the system health during its lifecycle, in the various timespans, to ensure that safety margins while running critical applications are not exceeded. Hence, enabling both the collection of chip parametrics as well as in-field testing will provide the means to fulfill this concept. In this work, we propose instruction set extensions for enabling SLM in a RISC-V based system. For this purpose, we introduce Path Transient Monitors (PTM) and Voltage Fluctuations Monitors (VFM) for monitoring path delay and voltage fluctuations. Using power wasters as a mean to inject voltage fluctuations in the FPGA system, we evaluate the abilities of this system to monitor chip degradation in early stages before system failure. Seyedeh Maryam Ghasemi, Sergej Meschkov, Jonas Krautter, Dennis Gnad, Mehdi Baradaran Tahoori |
IOLTS | 3 |
| 2023 | Enabling In-Field Parametric Testing for RISC-V CoresabstractRecently, RISC-V processors have been proposed in domains with high demand on both performance as well as functional safety, such as autonomous driving or medical devices. Therefore, enabling in-field test and measurement methods to ensure correct functionality over the entire chip lifecycle has become a necessity. In this paper, we propose an instruction set extension for RISC-V cores to enable on-chip telemetry for software-controlled in-field parametric testing. To that end, we introduce a so-called Path Transient Monitor (PTM) sensor, which is connected to the critical path of the core. Through custom instructions, the PTM is able to measure output transients with a timing resolution 1000 times (∼11.5 ps) higher than the rated clock period (few ns) of the RISC-V core, allowing thorough assessment of the device health state during in-field operation. As a case study, we implement our proposed setup as an FPGA-based hardware prototype and investigate the impact of process and design variation, temperature, and input data, to evaluate the usefulness of the collected sensor data. Seyedeh Maryam Ghasemi, Sergej Meschkov, Jonas Krautter, Dennis Gnad, Mehdi Baradaran Tahoori |
ITC | 3 |
| 2023 | New Approaches of Side-Channel Attacks Based on Chip Testing MethodsabstractThe state-of-the-art test infrastructure security is based on the assumption of preventing access to the sensitive information and the (publicly) accessible outputs or test infrastructure subset are supposed to not leak any secret information. In addition, for achieving functional safety requirements, the on-chip test infrastructure is reused in-field and cannot be completely disabled after the manufacturing test phase. Therefore, the access to the scan chains or similar test access ports which can lead to sensitive information needs to be restricted or encrypted to guarantee the security of the test infrastructure. However, in this work we show that having access to (small delay) test results on insensitive (public) outputs can in fact reveal secret data. Using real hardware, we have performed template attacks using the results of delay testing on the output of cryptographic circuits and were able to retrieve the key with very few test inputs. This template attack requires only a few random patterns on the victim device, which could be different from the device used for template building. In addition, the attack is also resilient against runtime variation and noise, as well as inaccuracies and down sampling of delay testing measurements. Sergej Meschkov, Dennis Gnad, Jonas Krautter, Mehdi Baradaran Tahoori |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2022 | Data Leakage through Self-Terminated Write Schemes in Memristive CachesabstractMemory cells in emerging non-volatile resistive memories often have asymmetric switching properties, where reliable write operations are achieved by setting the write period to a fixed value. To improve their performance and energy efficiency, self-terminating write schemes have been proposed, in which the write signal is stopped after the required state change has been observed. In this work, we show how this data-dependent write latency can be exploited as a side-channel in multiple ways to unveil restricted memory content. Moreover, we discuss and evaluate potential approaches to address the issue. Jonas Krautter, Mahta Mayahinia, Dennis Gnad, Mehdi Baradaran Tahoori |
ASP-DAC | 1 |
| 2021 | Remote and Stealthy Fault Attacks on Virtualized FPGAsabstractThe increasing amount of resources per FPGA chip makes virtualization and multi-tenancy a promising direction to improve utilization and efficiency of these flexible accelerators in the cloud. However, the freedom given to untrusted parties on a multi-tenant FPGA can result in severe security issues. Side-channel, fault, and Denial-of-Service attacks are possible through malicious use of FPGA logic resources. In this work, we perform a detailed analysis of fault attacks between logically isolated designs on a single FPGA. Attacks were often based on mapping a massive amount of Ring Oscillators into FPGA logic, which naturally induce a high current and subsequent voltage drop. However, they are easy to detect as combinational loops and can be prevented by a hypervisor. Here, we demonstrate how even elaborate fault attacks to recover a secret key of an AES encryption module can be deployed using seemingly benign benchmark circuits or even AES modules themselves to generate critical voltage fluctuations. Jonas Krautter, Dennis Gnad, Mehdi Baradaran Tahoori |
DATE | 1 |
| 2021 | Is your secure test infrastructure secure enough? : Attacks based on delay test patterns using transient behavior analysisabstractThe existing work on securing test infrastructure is based on the assumption of restricting or encrypting access to the sensitive information, which otherwise can be accessed by the scan chains or similar test access ports. Hence, the (publicly) accessible outputs or test infrastructure subset supposedly do not leak secret information. Since the on-chip test infrastructure is reused in-field for achieving functional safety requirements, disabling them completely after manufacturing test phase is not an option. In this work we invalidate this assumption by showing that having access to (small delay) test results on insensitive (public) outputs can in fact reveal secret data. Using real hardware, we have performed template attacks using the results of delay testing on the output of cryptographic circuits and were able to retrieve the key with very few test inputs. This template attack requires only few random patterns on the victim device, which could be different from the device used for template building. Sergej Meschkov, Dennis Gnad, Jonas Krautter, Mehdi Baradaran Tahoori |
ITC | 3 |
| 2019 | Active Fences against Voltage-based Side Channels in Multi-Tenant FPGAsabstractDynamic and partial reconfiguration together with hardware parallelism make FPGAs attractive as virtualized accelerators. However, recently it has been shown that multi-tenant FPGAs are vulnerable to remote side-channel attacks (SCA) from malicious users, allowing them to extract secret keys without a logical connection to the victim core. Typical mitigations against such attacks are hiding and masking schemes, to increase attackers' efforts in terms of side-channel measurements. However, they require significant efforts and tailoring for a specific algorithm, hardware implementation and mapping. In this paper, we show a hiding countermeasure against voltage-based SCA that can be integrated into any implementation, without requiring modifications or tailoring to the protected module. We place a properly mapped Active Fence of ring oscillators between victim and attacker circuit, enabled as a feedback of an FPGA-based sensor, leading to reduced side-channel leakage. Our experimental results based on a Lattice ECP5 FPGA and an AES-128 module show that two orders of magnitude more traces are needed for a successful key recovery, while no modifications to the underlying cryptographic module are necessary. Jonas Krautter, Dennis Gnad, Falk Schellenberg, Amir Moradi 0001, Mehdi Baradaran Tahoori |
ICCAD | 1 |
| 2019 | Mitigating Electrical-level Attacks towards Secure Multi-Tenant FPGAs in the CloudabstractA rising trend is the use of multi-tenant FPGAs, particularly in cloud environments, where partial access to the hardware is given to multiple third parties. This leads to new types of attacks in FPGAs, which operate not only on the logic level, but also on the electrical level through the common power delivery network. Since FPGAs are configured from the software-side, attackers are enabled to launch hardware attacks from software, impacting the security of an entire system. In this article, we show the first attempt of a countermeasure against attacks on the electrical level, which is based on a bitstream checking methodology. Bitstreams are translated back into flat technology mapped netlists, which are then checked for properties that indicate potential malicious runtime behavior of FPGA logic. Our approach can provide a metric of potential risk of the FPGA bitstream being used in active fault or passive side-channel attacks against other users of the FPGA fabric or the entire SoC platform. Jonas Krautter, Dennis Gnad, Mehdi Baradaran Tahoori |
ACM Trans. Reconfigurable Technol. Syst. | 1 |
| 2018 | Checking for Electrical Level Security Threats in Bitstreams for Multi-tenant FPGAsabstractMulti-tenant FPGAs, in which 3rd parties have partial access to the FPGA fabric, are a rising usage trend in cloud and reconfigurable SoCs. This gives rise to new types of attacks in FPGAs, as shown in recent studies. These attacks can operate on the electrical level through the common power delivery network, making them very hard to isolate. Thus, software-controlled FPGA configuration can be exploited to insert hardware trojans, impacting the security of the entire system. The attacks can be separated into fault and side-channel attacks to either actively manipulate a system or quietly extract secret information. In this paper, we show the first attempt of countermeasures against these voltage fluctuation based attacks, by analyzing FPGA bitstreams for malicious logic, basically implementing an FPGA antivirus. We provide a way to check bitstreams for potentially malicious structures, by extending a combination of commercial and open-source tools. Dennis Gnad, Sascha Rapp, Jonas Krautter, Mehdi Baradaran Tahoori |
FPT | 3 |