Benjamin Hettwer

dblp:233/4192 · DBLP profile ↗
← Back
8ranked-venue papers
5as first author
3since 2021 · last 2025
0000-0002-2164-6316ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 6 · 3 first-author · 3 since 2021Security and privacy · 2 · 2 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author
YearPublicationVenuePosition
2025 A Lightweight PUF-Based Weights Obfuscation Technique for Secure In-Memory AI Inference
abstract
In-Memory Computing (IMC) has introduced a novel computational approach that substantially improves emerging embedded AI accelerators’ latency and power consumption efficiency. Despite the numerous advantages, IMC architectures also introduce new security vulnerabilities that may compromise the confidentiality of the deployed Neural Network (NN) algorithms. In this work, following an analysis of the potential threats, we present a novel lightweight security countermeasure for IMC accelerators. This methodology can be employed to de-obfuscate the pre-trained weights of NN architectures whose bits’ significance has been reordered prior to the deployment phase onto the IMC crossbar. The proposed solution is based on the coordinated action of a Ferroelectric Field-Effect Transistor (FeFET) based Physical Unclonable Function (PUF) design and shifting registers. These components perform custom arithmetic shift operations on the values calculated by the IMC device at runtime to obtain a coherent inference computation. Furthermore, a design-space exploration method is proposed to investigate the trade-off between area overhead and the level of security provided by the implementation. The results show that with less than 3% of area overhead our design is robust against all the tested attack strategies.
Luca Parrini, Anirban Kar, Benjamin Hettwer, Taha Soliman, Yogesh Singh Chauhan, Hussam Amrouch, Norbert Wehn
IEEE Trans. Circuits Syst. I Regul. Pap.3
2024 Error Detection and Correction Codes for Safe In-Memory Computations
abstract
In-Memory Computing (IMC) introduces a new paradigm of computation that offers high efficiency in terms of latency and power consumption for AI accelerators. However, the non-idealities and defects of emerging technologies used in advanced IMC can severely degrade the accuracy of inferred Neural Networks (NN) and lead to malfunctions in safety-critical applications. In this paper, we investigate an architectural-level mitigation technique based on the coordinated action of multiple checksum codes, to detect and correct errors at run-time. This implementation demonstrates higher efficiency in recovering accuracy across different AI algorithms and technologies compared to more traditional methods such as Triple Modular Redundancy (TMR). The results show that several configurations of our implementation recover more than 91% of the original accuracy with less than half of the area required by TMR and less than 40% of latency overhead.
Luca Parrini, Taha Soliman, Benjamin Hettwer, Jan Micha Borrmann, Simranjeet Singh, Ankit Bende, Vikas Rana, Farhad Merchant, Norbert Wehn
ETS3
2023 Special Session: Mitigating Side-Channel Attacks Through Circuit to Application Layer Approaches
abstract
Side-Channel Attacks (SCAs), which are always considered a severe threat to the security of the cryptographic circuits, today can also be employed to extract IP secrets and neural network models. Hence, developing novel security solutions at different design levels is crucial. In this paper, we explore recent countermeasures at the circuit, algorithmic, and microarchitecture levels. First, we explain how Reconfigurable Field-Effect Transistor (RFET), as a beyond CMOS technology, enables us to provide both IP and data protection against SCAs at the circuit level. Second, we investigate an automated method for generating masked circuits as an algorithmic solution, and then we review machine learning-based SCA detection mechanisms at the microarchitecture level. Finally, we discuss emerging threats of SCAs from the industrial point of view.
Nima Kavand, Armin Darjani, Jens Trommer, Giulio Galderisi, Thomas Mikolajick, Nicolai Müller, Amir Moradi 0001, Chongzhou Fang, Ning Miao, Han Wang 0020, Sai Manoj Pudukotai Dinakarrao, Houman Homayoun, Benjamin Hettwer, Luca Parrini, Akash Kumar 0001
CODES+ISSS13
2020 Deep Learning Multi-Channel Fusion Attack Against Side-Channel Protected Hardware
abstract
State-of-the-art hardware masking approaches like threshold implementations and domain-oriented masking provide a guaranteed level of security even in the presence of glitches. Although provable secure in theory, recent work showed that the effective security order of a masked hardware implementation can be lowered by applying a multi-probe attack or exploiting externally amplified coupling effects. However, the proposed attacks are based on an unrealistic adversary model (i.e. knowledge of masks values during profiling) or require complex measurement setup manipulations.In this work, we propose a novel attack vector that exploits location dependent leakage from several decoupling capacitors of a modern System-on-Chip (SoC) with 16 nm fabrication technology. We combine the leakage from different sources using a deep learning-based information fusion approach. The results show a remarkable advantage regarding the number of required traces for a successful key recovery compared to state-of-the-art profiled side-channel attacks. All evaluations are performed under realistic conditions, resulting in a real-world attack scenario that is not limited to academic environments.
Benjamin Hettwer, Daniel Fennes, Sebastien Leger, Jan Richter-Brockmann, Stefan Gehrer, Tim Güneysu
DAC1
2020 Lightweight Side-Channel Protection using Dynamic Clock Randomization
abstract
Power analysis attacks have evolved rapidly over the past two decades, recently strengthened by advanced deep learning algorithms. However, the application of effective countermeasures such as masking is often challenging in practice due to restricted power and area resources of cryptographic devices. On the other hand, lightweight hiding methods like random data delays often introduce only a small amount of entropy in the execution process, and thus provide only a moderate level of protection. In this work, we propose and evaluate a generic hiding countermeasure based on dynamic clock frequency randomization. We exploit runtime reconfiguration of modern reconfigurable devices to produce a highly unstable clock signal, which yields up to 20 million different execution times for an AES encryption operation. Our design not only creates heavy misalignments in the power traces, but is also highly customizable and can be easily composed with other side-channel countermeasures. We test our approach using recently proposed evaluation methods for desynchronized power traces including sliding-window correlation analysis and deep neural networks. The results show that none of the attacks is able to recover the secret key with one million power traces. Furthermore, we could not detect any first-order leakage in five million encryptions using state-of-the-art leakage assessment.
Benjamin Hettwer, Kallyan Das, Sebastien Leger, Stefan Gehrer, Tim Güneysu
FPL1
2019 Securing Cryptographic Circuits by Exploiting Implementation Diversity and Partial Reconfiguration on FPGAs
abstract
Adaptive and reconfigurable systems such as Field Programmable Gate Arrays (FPGAs) play an integral part of many complex embedded platforms. This implies the capability to perform runtime changes to hardware circuits on demand. In this work, we make use of this feature to propose a no-vel countermeasure against physical attacks of cryptographic implementations. In particular, we leverage exploration of the implementation space on FPGAs to create various circuits with different hardware layouts from a single design of the Advanced Encryption Standard (AES), that are dynamically exchanged during device operation. We provide evidence from practical experiments based on a modern Xilinx ZYNQ UltraScale+ FPGA that our approach increases the resistance against physical attacks by at least factor two. Furthermore, the genericness of our approach allows an easy adaption to other algorithms and combination with other countermeasures.
Benjamin Hettwer, Johannes Petersen, Stefan Gehrer, Heike Neumann, Tim Güneysu
DATE1
2019 Deep Neural Network Attribution Methods for Leakage Analysis and Symmetric Key Recovery
Benjamin Hettwer, Stefan Gehrer, Tim Güneysu
SAC1
2018 Profiled Power Analysis Attacks Using Convolutional Neural Networks with Domain Knowledge
Benjamin Hettwer, Stefan Gehrer, Tim Güneysu
SAC1