Matthias Probst

dblp:249/3209 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
9since 2021 · last 2026
0000-0001-5747-0730ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 6 · 1 first-author · 6 since 2021Security and privacy · 4 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Influence of Parallelism in Vector-Multiplication Units on Correlation Power Analysis
abstract
The use of Neural Networks (NNs) in edge devices is increasing, introducing new security challenges related to the confidentiality of NNs. As edge devices often offer physical access, attacks targeting the hardware, such as Side-Channel Analysis (SCA), must be considered. To enhance the performance of NN inference, hardware accelerators are commonly employed. This work investigates the influence of parallel processing within such accelerators on correlation-based side-channel attacks that exploit power consumption. The focus is on neurons that are part of the same fully-connected layer, which run parallel and simultaneously process the same input value. The theoretical impact of concurrent Multiply-and-Accumulate (MAC) operations on overall power consumption is evaluated, as well as the success rate of Correlation Power Analysis (CPA). Based on the observed behavior, equations are derived that describe how the correlation decreases with increasing levels of parallelism. The applicability of these equations is validated using a vector-multiplication unit implemented on a Field Programmable Gate Array (FPGA). The theoretical boundary for successful CPA is found to be 15 parallel Processing Elements (PEs), while practical results show this limit is reduced to 8 PEs due to noise and Signal-to-Noise Ratio (SNR) reduction.
Manuel Brosch, Matthias Probst, Stefan Koegler, Georg Sigl
ACM Trans. Embed. Comput. Syst.2
2025 Special Session - Hardware-Software Co-Design for Machine Learning Systems Made Open-Source
abstract
Chip technologies are crucial for the digital transformation of industry and society. Machine Learning (ML) and Artificial Intelligence (AI) are increasingly shaping both daily life and industrial applications, with AI hardware playing a vital role in enabling efficient and scalable ML deployment. However, significant challenges remain in bridging the gap between ML algorithm development and hardware implementation, particularly for edge ML applications where efficiency, power constraints, and adaptability are critical. In such resource-constrained environments, hardware-software co-design becomes essential to achieve the necessary trade-offs between performance, energy efficiency, and system responsiveness. One of the key bottlenecks in ML hardware development is the lack of seamless integration between ML toolchains and electronic design automation (EDA) tools for hardware synthesis and mapping. Current solutions often require extensive manual optimization and costly proprietary software, limiting accessibility and innovation. Open-source tools can play a transformative role in democratizing ML hardware design, fostering collaboration, and addressing the growing shortage of skilled professionals. This paper covers key aspects of hardware-software co-design for ML systems, such as ML algorithms, hardware design, compiler technologies and system security, with a focus on open-source solutions. We highlight the critical need for open-source toolchains that connect ML model development with hardware synthesis and optimization and present solutions for custom hardware, as well as FPGA accelerators.
Mehdi Baradaran Tahoori, Vincent Meyers, Mahboobe Sadeghipourrudsari, Huashuangyang Xu, Jürgen Becker 0001, Tanja Harbaum, Felix Frombach, Julian Höfer, Georgios Sotiropoulos, Jörg Henkel, Zeynep Demirdag, Heba Khdr, Hassan Nassar, Ulf Schlichtmann, Johannes Geier, Philipp van Kempen, Georg Sigl, Stefan Koegler, Matthias Probst, Jürgen Teich, Frank Hannig, Muhammad Sabih, Batuhan Sesli, Norbert Wehn, Lukas Steiner, Wolfgang Kunz, Mohamed Shelkamy Ali
CODES+ISSS19
2025 Fault Detection in the Control- and Data-Path of Neural Networks
abstract
Machine learning and neural networks experience growing usage in resource-constrained devices. However, moving neural networks to small devices also brings new requirements regarding the reliability and security of the networks and their hardware. In many areas, such as autonomous driving, the device must detect possible errors during execution to ensure safe functionality. Moreover, an adversary can gain physical access to the device, opening the door for hardware attacks like fault injections that target misclassification or parameter retrieval. This work proposes a fault detection mechanism for software implementations of neural networks running on a microcontroller to increase the reliability and security of the neural network. Our technique uses AN-codes, a type of error-detecting code, to detect errors in calculations within the neural network without any implications on the accuracy of protected networks. In addition, signature checking ensures the integrity of the control flow. Simulations and real-world testing show that our mechanism successfully detects faults in all possible locations in the neural network’s program code. Despite the robustness of our fault detection mechanism, it has an overhead in code size of only about 10%, independent of the implemented network. The memory usage increases by at most 232 bytes independently of the neural network size, ensuring that the mechanism is not overly burdensome for the memory.
Matthias Probst, Manuel Brosch, Augustin Ewald, Michael Gruber, Georg Sigl
FDTC1
2025 Side-Channel Analysis of Integrate-and-Fire Neurons Within Spiking Neural Networks
abstract
Spiking neural networks gain increasing attention in constraint edge devices due to event-based low-power operation and little resource usage. Such edge devices often allow physical access, opening the door for Side-Channel Analysis. In this work, we introduce a novel robust attack strategy on the neuron level to retrieve the trained parameters of an implemented spiking neural network. Utilizing horizontal correlation power analysis, we demonstrate how to recover the weights and thresholds of a feed-forward spiking neural network implementation. We verify our methodology with real-world measurements of localized electromagnetic emanations of an FPGA design. Additionally, we propose countermeasures against the introduced novel attack approach. We evaluate shuffling and masking as countermeasures to protect the implementation against our proposed attack and demonstrate their effectiveness and limitations.
Matthias Probst, Manuel Brosch, Georg Sigl
IEEE Trans. Circuits Syst. I Regul. Pap.1
2024 EMDRIVE Architecture: Embedded Distributed Computing and Diagnostics from Sensor to Edge
abstract
Future automotive architectures are expected to transition from a network-centric to a domain-centered architecture featuring central compute units. Powerful domain controllers or smart sensors alleviate the load on these central units and communication systems. These controllers execute tasks with varying criticalities on heterogeneous multicore processors, and are ideally capable of dynamically balancing the computing load between the central unit and sensors. Here, Artificial Intelligence (AI) capabilities playa crucial role, as it is in high demand for such an automotive architecture. However, AI still requires specialized accelerators to improve their computation performance. Task-oriented distributed computing with criticalities up to ASIL-D necessitates the development and utilization of specialized methodologies, such as safety, through the isolation and abstraction of low-level hardware concepts. Meanwhile, online monitoring and diagnostics become vital features to detect errors during operation. The EMDRIVE architecture includes methods, components, and strategies to enhance the performance, safety, and security of such distributed computing platforms. The nationally funded EMDRIVE project connects its twelve partners from academia and industry and is currently in its intermediate stage.
Patrick Schmidt 0003, Iuliia Topko, Matthias Stammler, Tanja Harbaum, Jürgen Becker 0001, Rico Berner, Omar Ahmed, Jakub Jagielski, Thomas Seidler, Markus Abel, Marius Kreutzer, Maximilian Kirschner, Victor Pazmino Betancourt, Robin Sehm, Lukas Groth, Andrija Neskovic, Rolf Meyer, Saleh Mulhem, Mladen Berekovic, Matthias Probst, Manuel Brosch, Georg Sigl, Thomas Wild, Matthias Ernst, Andreas Herkersdorf, Florian Aigner, Stefan Hommes, Sebastian Lauer, Maximilian Seidler, Thomas Raste, Gasper Skvarc Bozic, Ibai Irigoyen Ceberio, Albrecht Mayer
DATE20
2024 Switch-Glitch : Location of Fault Injection Sweet Spots by Electro-Magnetic Emanation
abstract
While several approaches exist to locate spatial coordinates on a chip that are susceptible to Side-Channel Analysis (SCA), e.g., Test Vector Leakage Assessment (TVLA), so far, an equivalent for localized Electro-Magnetic (EM) based Fault Injection Analysis (FIA) is missing. This work analyzes the spatial relationship between EM emanation and Electro-Magnetic Fault Injection (EMFI) susceptibility and effect. Our experiments are based on a two-step approach where we first capture a heatmap based on a single trace per location, which is then used to find promising spatial EMFI positions. We chose an STM32F303 microcontroller, which shows that the injection locations that result in data modification are almost entirely contained within areas of high Signal-to-Noise Ratio (SNR). An EMFI based attack can be accelerated up significantly using this relationship.
Matthias Probst, Michael Gruber, Manuel Brosch, Tim Music, Georg Sigl
FDTC1
2024 A Masked Hardware Accelerator for Feed-Forward Neural Networks With Fixed-Point Arithmetic
abstract
Neural network (NN) execution on resource-constrained edge devices is increasing. Commonly, hardware accelerators are introduced in small devices to support the execution of NNs. However, an attacker can often gain physical access to edge devices. Therefore, side-channel attacks are a potential threat to obtain valuable information about the NN. In order to keep the network secret and protect it from extraction, countermeasures are required. In this article, we propose a masked hardware accelerator for feed-forward NNs that utilizes fixed-point arithmetic and is protected against side-channel analysis (SCA). We use an existing arithmetic masking scheme and improve it to prevent incorrect results. Moreover, we transfer the scheme to the hardware layer by utilizing the glitch-extended probing model and demonstrate the security of the individual modules. To exhibit the effectiveness of the masked design, we implement it on an FPGA and measure the power consumption. The results show that with two million measurements, no secret information is leaked by means of a$t$-test. In addition, we compare our accelerator with the masked software implementation and other hardware designs. The comparison indicates that our accelerator is up to 38 times faster than software and improves the throughput by a factor of about 4.1 compared to other masked hardware accelerators.
Manuel Brosch, Matthias Probst, Matthias Glaser, Georg Sigl
IEEE Trans. Very Large Scale Integr. Syst.2
2022 Counteract Side-Channel Analysis of Neural Networks by Shuffling
abstract
Machine learning is becoming an essential part in almost every electronic device. Implementations of neural networks are mostly targeted towards computational performance or memory footprint. Nevertheless, security is also an important part in order to keep the network secret and protect the intellectual property associated to the network. Especially, since neural network implementations are demonstrated to be vulnerable to side-channel analysis, powerful and computational cheap countermeasures are in demand. In this work, we apply a shuffling countermeasure to a microcontroller implementation of a neural network to prevent side-channel analysis. The countermeasure is effective while the computational overhead is low. We investigate the extensions necessary for our countermeasure, and how shuffling increases the effort for an attack in theory. In addition, we demonstrate the increase in effort for an attacker through experiments on real side-channel measurements. Based on the mechanism of shuffling and our experimental results, we conclude that an attack on a commonly used neural network with shuffling is no longer feasible in a reasonable amount of time.
Manuel Brosch, Matthias Probst, Georg Sigl
DATE2
2021 DOMREP-An Orthogonal Countermeasure for Arbitrary Order Side-Channel and Fault Attack Protection
abstract
Protection against physical attacks is a major requirement for cryptographic implementations on devices which can be accessed by attackers. Side-channel and fault injection attacks are the most common types of physical attacks. In this work we present a novel generic solution for simultaneous protection against side-channel and fault attacks with arbitrary order. We combine domain oriented masking and repetition codes in an orthogonal way and call this approach DOMREP. The resistance against side-channel attacks and fault attacks can be scaled independently of each other, for the protection against higher-order side-channel analysis and the injection of multiple faults including SIFA. We develop the generic concept of orthogonal protection, and implement the DOMREP concept on GIMLI, a round two NIST LWC competition candidate, on a Xilinx Artix-7 FPGA. Our implementation of GIMLI is verified to be resistant against univariate first-order side-channel attacks by TVLA. The resistance against SIFA is verified by means of fault emulation of single as well as multiple bit faults. Our implementation of GIMLI achieves the expected security level according to these measurements. We also provide numbers for the area overhead for our protected implementation of GIMLI.
Michael Gruber, Matthias Probst, Patrick Karl, Thomas Schamberger, Lars Tebelmann, Michael Tempelmeier, Georg Sigl
IEEE Trans. Inf. Forensics Secur.2
2019 Persistent Fault Analysis of OCB, DEOXYS and COLM
abstract
Persistent Fault Analysis (PFA) was introduced as a new approach to attack block ciphers at CHES 2018. Since then, it has been proven to be a powerful attack with an easy to achieve fault model which relies on the persistent alternation of constants e.g. S-Boxes. One of the main benefits, when working with PFA, comes from the perspective of an attacker: there is no need to conduct fault injections at runtime. As authenticated encryption is gaining more and more attraction from the research community e.g. the CAESAR competition, we opted to apply the principals of PFA to authenticated encryption schemes. Therefore, we decided to attack a subset of the AES based CAESAR finalists. In this work, we present a PFA of Deoxys-II, OCB and COLM. We show how to extend the original PFA to fit the needs of authenticated encryption schemes and what makes them vulnerable to PFA. Finally, we demonstrate the efficiency of the attacks by means of simulation.
Michael Gruber, Matthias Probst, Michael Tempelmeier
FDTC2