EDBT 2026 Demo / reviewers in the wild / expert
Vincent Meyers
dblp:294/5088
· DBLP profile ↗
16ranked-venue papers
6as first author
16since 2021 · last 2026
0000-0001-9775-5861ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 16 · 6 first-author · 16 since 2021Software engineering, systems software and programming languages · 5 · 2 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Concurrent Fault Detection for Binary Neural Network Accelerators via On-Chip Voltage MonitoringabstractAs Neural Networks (NNs) are increasingly deployed in safety-critical edge and datacenter systems, ensuring reliable execution becomes essential. Runtime faults such as memory bit flips and faults in logic components can silently corrupt computations without triggering system-level alarms. Conventional detection methods often miss logic faults or incur significant overhead. We propose a lightweight, concurrent error detection method that monitors voltage fluctuation traces captured by on-chip sensors. Our hypothesis is that faults alter neuron activations and change the switching activity and thus the instantaneous voltage fluctuation profile during inference. These traces are classified using a threshold-based model, requiring no modifications to the NN hardware or inference pipeline. As our approach operates purely through side-channel observation, it functions as a non-intrusive wrapper applicable to a wide range of AI accelerators. We evaluate the method on two different FPGAs, demonstrating consistent efficiency across platforms and portability to cloud scenarios. It detects faults in under a second, making it suitable for real-time applications such as vision tasks running at 30–60 FPS. By repurposing voltage sensors as diagnostic tools, this work opens a new direction for functional safety in AI hardware. Vincent Meyers, Mahboobe Sadeghipourrudsari, Mehdi Baradaran Tahoori |
DATE | 1 |
| 2026 | Multi-Partner Project: A Holistic and Open-Source Approach to Efficient, Secure and Reliable AI Hardware Deployment in DI-EDAIabstractArtificial Intelligence (AI) has demonstrated strong capabilities across various domains over the past decade. Edge and specifically mission-critical applications, such as automotive and aerospace, require both high performance and efficiency without compromises in security and reliability. This stems from tightly constrained power consumption, failures that can have catastrophic consequences and devices that may be physically accessible to malicious actors. AI algorithm deployment to hardware also presents significant barriers, requiring specialized knowledge and expensive development tools. The DI-EDAI project aims to offer a holistic approach for connecting high-level AI algorithms with hardware implementations while tackling the aforementioned issues. Unlike other approaches that address individual aspects of the AI deployment flow, we investigate solutions across multiple layers of the design stack. Through our work we develop efficient hardware, map AI algorithms to hardware while simultaneously ensuring security and reliability. Furthermore, we leverage AI-techniques to assist with Electronic Design Automation (EDA) workflows for design optimization, verification and implementation. Our open source approach aims to reduce entry barriers, promote transparency and education, and spark innovation. This paper presents the current state of the DI-EDAI project at midterm, highlighting our latest contributions, identifying limitations in existing state-of-the-art approaches, and outlining ongoing work to address these gaps. Georgios Sotiropoulos, Felix Frombach, Julian Höfer, Tanja Harbaum, Jürgen Becker 0001, Henrik Iver Thorøe, Vincent Meyers, Mehdi Baradaran Tahoori, Zeynep Demirdag, Mohammed Bakr Sikal, Hassan Nassar, Heba Khdr, Jörg Henkel, Christopher Wolters, Philipp van Kempen, Johannes Geier, Ulf Schlichtmann, Batuhan Sesli, Muhammad Sabih, Jakob Wittmann, Frank Hannig, Jürgen Teich, Lukas Steiner, Norbert Wehn, Mohamed Shelkamy Ali, Philipp Schmitz, Wolfgang Kunz, Stefan Koegler, Georg Sigl |
DATE | 7 |
| 2025 | Towards Functional Safety of Neural Network Hardware Accelerators: Concurrent Out-of-Distribution Detection in Hardware Using Power Side-Channel AnalysisabstractFor AI hardware, functional safety is crucial, especially for neural network (NN) accelerators used in safety-critical systems. A key requirement for maintaining this safety is the precise detection of out-of-distribution (OOD) instances, which are inputs significantly distinct from the training data. Neglecting to integrate robust OOD detection may result in possible safety hazards, diminished performance, and inaccurate decision-making within NN applications. Existing methods for OOD detection have been explored for full-precision models. However, the evaluation of methods on quantized neural network (QNN), which are often deployed on hardware accelerators such as FPGAs, and on-device hardware realization of concurrent OOD detection (COD) is missing in literature. In this paper, we provide a novel approach to OOD detection for NN FPGA accelerators using power measurements. Utilizing the power side-channel through digital voltage sensors allows on-device OOD detection in a non-intrusive and concurrent manner, without relying on explicit labels or modifications to the underlying NN. Furthermore, our method allows OOD detection before the inference finishes. Additionally to the evaluation, we provide an efficient hardware implementation of COD on an actual FPGA. Vincent Meyers, Michael Hefenbrock, Mahboobe Sadeghipourrudsari, Dennis Gnad, Mehdi Baradaran Tahoori |
ASP-DAC | 1 |
| 2025 | Special Session - Hardware-Software Co-Design for Machine Learning Systems Made Open-SourceabstractChip technologies are crucial for the digital transformation of industry and society. Machine Learning (ML) and Artificial Intelligence (AI) are increasingly shaping both daily life and industrial applications, with AI hardware playing a vital role in enabling efficient and scalable ML deployment. However, significant challenges remain in bridging the gap between ML algorithm development and hardware implementation, particularly for edge ML applications where efficiency, power constraints, and adaptability are critical. In such resource-constrained environments, hardware-software co-design becomes essential to achieve the necessary trade-offs between performance, energy efficiency, and system responsiveness. One of the key bottlenecks in ML hardware development is the lack of seamless integration between ML toolchains and electronic design automation (EDA) tools for hardware synthesis and mapping. Current solutions often require extensive manual optimization and costly proprietary software, limiting accessibility and innovation. Open-source tools can play a transformative role in democratizing ML hardware design, fostering collaboration, and addressing the growing shortage of skilled professionals. This paper covers key aspects of hardware-software co-design for ML systems, such as ML algorithms, hardware design, compiler technologies and system security, with a focus on open-source solutions. We highlight the critical need for open-source toolchains that connect ML model development with hardware synthesis and optimization and present solutions for custom hardware, as well as FPGA accelerators. Mehdi Baradaran Tahoori, Vincent Meyers, Mahboobe Sadeghipourrudsari, Huashuangyang Xu, Jürgen Becker 0001, Tanja Harbaum, Felix Frombach, Julian Höfer, Georgios Sotiropoulos, Jörg Henkel, Zeynep Demirdag, Heba Khdr, Hassan Nassar, Ulf Schlichtmann, Johannes Geier, Philipp van Kempen, Georg Sigl, Stefan Koegler, Matthias Probst, Jürgen Teich, Frank Hannig, Muhammad Sabih, Batuhan Sesli, Norbert Wehn, Lukas Steiner, Wolfgang Kunz, Mohamed Shelkamy Ali |
CODES+ISSS | 2 |
| 2025 | F2Opt: Novel Fine-Tuning and Folding Algorithms for FPGA-Based DNN AcceleratorsabstractFPGAs, with their parallelism, low power consumption, and reconfigurability, offer an ideal solution for accelerating quantized deep neural networks (qDNNs) on resource-constrained edge devices. They enable enhanced latency, reduced energy consumption, and improved computational efficiency. However, existing frameworks to accelerate qDNN inference on FPGA face challenges in fine-tuning the deployed models on the FPGAs, as expensive re-synthesis and re-mapping of the accelerator is required. Additionally, the folding algorithm for DNN compute engines in these frameworks introduces substantial padding overheads to align with memory widths. This paper introduces a novel evolutionary algorithm-based hardware-in-the-loop (EvoHIL) framework. EvoHIL uses hardware-level weight bit-flip operations to activate neurons and improve accelerator accuracy without requiring DNN re-training and rebuilding the entire accelerator. We also propose a novel algorithmic optimization (Aopt) for folding across DNN accelerator layers. Aopt optimally aligns folding factors with memory width, eliminating excessive padding overheads and improving throughput while reducing memory and resource utilization. Experimental results demonstrate the effectiveness of these solutions. EvoHIL optimization enhanced the accuracy of a binarized convolutional neural network (BCNN) accelerator to nearly 86%. Aopt delivered significant improvements, including up to 96.77 % padding overhead reduction, 33.2 % increased throughput, and 25 % reduced runtime compared to FINN. Muhammad Shakeel Akram, B. Sharat Chandra Varma 0001, Vincent Meyers, Mehdi Baradaran Tahoori, Dewar Finlay |
FPL | 3 |
| 2025 | Invited Paper: Hardware-Software Co-Design for Highly Optimized, Customized, and Reliable AI SystemsabstractOver the past decade, AI has been rapidly integrated into our daily life, coming in every shape and size and working across systems from big clouds to IoT. As a result, AI systems are increasingly requiring enhancements in model efficiency, hardware acceleration, and memory systems to satisfy stringent constraints on efficiency, reliability, and security. However, advancing across these fronts is challenging as compute demand outpaces Moore’s-law efficiency, hardening into an AI compute wall and an AI energy wall. Breaking through requires a unified AI co-design loop that co-optimizes algorithms and hardware, including efficient AI-to-hardware mapping, so that ongoing goals (accuracy, sparsity, latency) align with concrete hardware choices (precision modes, interconnects, memory hierarchies) and AI-specific execution and memory-reuse patterns. This paper details the principal co-design challenges, presents complementary strategies, and outlines a practical roadmap toward highly optimized, efficient, reliable, and secure AI systems. Jörg Henkel, Mehdi Baradaran Tahoori, Heba Khdr, Hassan Nassar, Vincent Meyers, Deming Chen, Selin Yildirim, Yingbing Huang, Nirmal Saxena, Saurabh Hukerikar, Srivi Dhruvanarayan |
ICCAD | 5 |
| 2025 | Lightweight Concurrent Out-of-Distribution Detection in Hyperdimensional Computing HardwareabstractHyperDimensional Computing (HDC) is a brain-inspired machine learning (ML) approach for cognitive tasks, where input data is transformed and encoded as high dimensional hypervectors and are then compared to aggregated class hypervec-tors for classification. Due to its computationally lightweight operations and noise resilience, it is well suited for resource-constrained edge Artificial Intelligence (AI). A well-known problem in ML tasks is dealing with inputs that are significantly different from the training and test data, which is referred to as Out-of-Distribution (OOD) inputs. When AI models are faced with such inputs, they behave incorrectly which can lead to safety violations, when they are deployed in safety-critical applications. Therefore, detecting OOD inputs is essential for maintaining the functional safety of machine learning accelerators in practice. In this work, we propose an extremely lightweight concurrent OOD detection mechanism in HDC hardware accelerators. Our results not only demonstrate higher OOD detection compared to other state of the arts but also requires no retraining, minimal hardware overhead (2 LUT, 1 Register), and does not introduce additional latency. Mahboobe Sadeghipourrudsari, Vincent Meyers, Mehdi Baradaran Tahoori |
IOLTS | 2 |
| 2025 | CED-HDC: Lightweight Concurrent Error Detection for Reliable Hyperdimensional ComputingabstractHyperDimensional Computing (HDC) is a machine learning paradigm that is well suited for edge devices due to its low-overhead inference hardware and inherent robustness to bit-flips and noise. For safety-critical applications, reliability is paramount, with runtime failures posing a serious threat to HDC accelerators. While HDC is robust to several bit flops in memory without significant loss of accuracy, its performance degrades rapidly once a critical threshold is exceeded where hardware faults exceed the tolerance capacity of the algorithm. Ensuring reliable operation over the lifetime of the system remains a challenge, particularly with runtime hardware failures. Conventional concurrent error detection (CED) methods often only address a limited number of faults or incur significant hardware overhead, which either fall under the algorithmic robustness of HDC or contradict the lightweight nature of HDC implementations. In this work, we propose a lightweight CED method that is tailored to HDC systems. Our method can dynamically detect faults before they cause noticeable accuracy degradation. It introduces negligible hardware overhead (< 0.1%), no additional latency, and ensures 100% coverage of critical errors. Mahboobe Sadeghipourrudsari, Vincent Meyers, Mehdi Baradaran Tahoori |
VTS | 2 |
| 2024 | Out-of-Distribution Detection Using Power-Side Channels for Improving Functional Safety of Neural Network FPGA AcceleratorsabstractAccurate out-of-distribution (OOD) detection is crucial for ensuring the safety and reliability of neural network (NN) accelerators in real-world scenarios. This paper proposes a novel OOD detection approach for NN FPGA accelerators using remote power side-channel measurements. We assess different methods for distinguishing power measurements of in-distribution (ID) samples from OOD samples, comparing the effectiveness of simple power analysis and OOD sample identification based on the reconstruction error of an autoencoder (AE). Leveraging on-chip voltage sensors enables non-intrusive and concurrent remote OOD detection, eliminating the need for explicit labels or modifications to the underlying NN. Vincent Meyers, Dennis Gnad, Mehdi Baradaran Tahoori |
DATE | 1 |
| 2024 | Reliability and Security of AI HardwareabstractIn recent years, Artificial Intelligence (AI) systems have achieved revolutionary capabilities, providing intelligent solutions that surpass human skills in many cases. However, such capabilities come with power-hungry computation workloads. Therefore, the implementation of hardware acceleration becomes as fundamental as the software design to improve energy efficiency, silicon area, and latency of AI systems. Thus, innovative hardware platforms, architectures, and compiler-level approaches have been used to accelerate AI workloads. Crucially, innovative AI acceleration platforms are being adopted in application domains for which dependability must be paramount, such as autonomous driving, healthcare, banking, space exploration, and industry 4.0. Unfortunately, the complexity of both AI software and hardware makes the dependability evaluation and improvement extremely challenging. Studies have been conducted on both the security and reliability of AI systems, such as vulnerability assessments and countermeasures to random faults and analysis for side-channel attacks. This paper describes and discusses various reliability and security threats in AI systems, and presents representative case studies along with corresponding efficient countermeasures. Dennis Gnad, Martin Gotthard, Jonas Krautter, Angeliki Kritikakou, Vincent Meyers, Paolo Rech, Josie E. Rodriguez Condia, Annachiara Ruospo, Ernesto Sánchez 0001, Fernando Santos 0001, Olivier Sentieys, Mehdi Baradaran Tahoori, Russell Tessier, Marcello Traiola |
ETS | 5 |
| 2024 | E3HDC: Energy Efficient Encoding for Hyper-Dimensional Computing on Edge DevicesabstractHyper-Dimensional Computing (HDC) as a brain-inspired computational model for cognitive tasks is suitable for edge devices due to its hardware-friendly and fault-resistant computations. Despite this potential, HDC has a large memory footprint, resulting high power consumption. In this work, we propose a hardware-aware encoding where parameters are generated on-the-fly without any large memory block requirements. Moreover, the hardware mapping of the trained HDC model is optimized to make it suitable for resource-constraint edge devices. In this work we propose an end-to-end flow from HDC training to FPGA mapping. We demonstrate the efficiency of this method compared to other state-of-the-art HDC implementations in terms of hardware usage and power consumption. Mahboobe Sadeghipourrudsari, Jonas Krautter, Vincent Meyers, Mehdi Baradaran Tahoori |
FPL | 3 |
| 2023 | Power2Picture: Using Generative CNNs for Input Recovery of Neural Network Accelerators through Power Side-Channels on FPGAsabstractArtificial neural networks pervade almost all areas of today's life, being used for both simple image classification tasks as well as highly complex decision making in mission-critical tasks. This makes artificial neural networks an attractive target for attackers to recover the model architecture or user inputs and outputs through either classical software vulnerabilities or hardware side-channel and fault attacks. With increasing complexity of the models, smaller companies now often opt for pre-trained public models, which are then used with potentially sensitive inputs, for instance, in medical applications. In this work, we present a novel remote side-channel attack methodology to steal neural network inputs using generative convolutional neural networks. After measuring voltage fluctuations using on-chip sensors, we are able to recover the original inputs to image classifiers on different FPGA platforms. Our results prove the effectiveness of our attack, as we are able to recover inputs from networks running on different devices, with different datasets, and under different operating conditions. Lukas Huegle, Martin Gotthard, Vincent Meyers, Jonas Krautter, Dennis Gnad, Mehdi Baradaran Tahoori |
FCCM | 3 |
| 2023 | Power Side-Channel Attacks and Defenses for Neural Network AcceleratorsabstractNeural networks are becoming increasingly utilized in a range of real-world applications, often involving privacy-sensitive or safety-critical tasks like medical image analysis or autonomous driving. Despite their usefulness, designing and training neural networks (NNs) can be costly, both in terms of financial and energy expenses [4]. Gathering and labeling training data, actual training, and fine-tuning require considerable resources. The network models themselves are also considered confidential intellectual property (IP). Additionally, the carbon footprint of model training and development has a significant impact on the environment [5]. Vincent Meyers, Mehdi Baradaran Tahoori |
FCCM | 1 |
| 2023 | Remote Identification of Neural Network FPGA Accelerators by Power FingerprintsabstractMachine learning acceleration has become increasingly popular in recent years, with machine learning-as-a-service (MLaaS) scenarios offering convenient and efficient ways to access pre-trained neural network models on devices such as cloud FPGAs. However, the ease of access and use also raises concerns over model theft or misuse through model manipulation. To address these concerns, this paper proposes a method for identifying neural network models in MLaaS scenarios by their unique power consumption. Current fingerprinting methods for neural networks rely on input/output pairs or characteristic of the decision boundary, which might not always be accessible in more complex systems. Our proposed method utilizes unique power characteristics of the black-box neural network accelerator to extract a fingerprint by measuring the voltage fluctuations of the device when querying specially crafted inputs. We take advantage of the fact that the power consumption of the accelerator varies depending on the input being processed. For evaluation of our method we conduct 200 fingerprint extraction and matching experiments and the results confirm that the proposed method can distinguish between correct and incorrect models in 100% of the cases. Furthermore, we show that the fingerprint is robust to environmental and chip-to-chip variations. Vincent Meyers, Michael Hefenbrock, Dennis Gnad, Mehdi Baradaran Tahoori |
FPL | 1 |
| 2022 | Reverse Engineering Neural Network Folding with Remote FPGA Power AnalysisabstractSpecialized hardware accelerators in the form of FPGAs are widely being used for neural network implementations. By that, they also become the target of power analysis attacks that try to reverse engineer the embedded secret information, in the form of model parameters. However, most of these attacks assume rather simple implementations, not realistic frameworks. Layer folding is used in such accelerators to optimize the network under given area constraints with various degrees of parallel and sequential operations. In this paper, we show that folding does mislead existing power side-channel attacks on frameworks such as FINN. We show how we can extract the folding parameters successfully and use that information to subsequently also recover the number of neurons–something not reliably possible without knowing the folding information. Following the methodologies of both profiling side-channel attacks and machine learning, our approach can extract the amount of neurons with 98% accuracy on a test device, compared to 44-79% accuracy based on related work under the same test conditions and datasets. Furthermore, we show how a classifier that is based on regression can detect previously unknown parameters, which has not been shown before. To verify our results under different environmental conditions, we test the target device in a climate chamber under various temperature ranges and still reach accuracies of at least 93%. Vincent Meyers, Dennis Gnad, Mehdi Baradaran Tahoori |
FCCM | 1 |
| 2021 | Stealthy Logic Misuse for Power Analysis Attacks in Multi-Tenant FPGAsabstractFPGAs have been used in the cloud since several years, for workloads such as machine learning, database processes and security tasks. As for other cloud services, a highly desired feature is virtualization in which multiple tenants share a single FPGA to increase utilization and by that efficiency. By solely using standard FPGA logic in the untrusted tenant, on-chip logic sensors have recently been proposed, allowing remote power analysis side-channel and covert channel attacks on the victim tenant. However, such sensors are implemented by unusual circuit constructions, such as ring oscillators or delay lines, which might be easily detected by bitstream and/or netlist checking. In this paper we show that such structural checking methods are not universal solutions as the attacks can make use of “benign-looking” circuits. We demonstrate this by showing a successful Correlation Power Analysis attack on the Advanced Encryption Standard. Dennis Gnad, Vincent Meyers, Nguyen Minh Dang, Falk Schellenberg, Amir Moradi 0001, Mehdi Baradaran Tahoori |
DATE | 2 |