Transactions on Cryptographic Hardware and Embedded Systems 2026
ARMOR:
First-Order Masking of Activation and ArgMax Gadgets for Side-Channel Resistant Neural Networks
Won Geun Shin
Department of Cyber Security, College of Science and Technology, Korea University, Sejong, Republic of Korea
JeongHwan Lee
School of Cybersecurity, Korea University, Seoul, Republic of Korea
Sangyun Jung
Department of Cyber Security, College of Science and Technology, Korea University, Sejong, Republic of Korea
HeeSeok Kim
Department of Cyber Security, College of Science and Technology, Korea University, Sejong, Republic of Korea
Keywords: Side-Channel Analysis, Masking, Binarized Neural Network
Abstract
The widespread deployment of AI applications on wearable and IoT devices has raised security concerns, including model stealing and personal information leakage. Model stealing attacks rely on issuing queries to the target model and analyzing the corresponding outputs. Side-channel analysis, traditionally used to attack cryptographic algorithms, can now facilitate the performance of model stealing attacks on neural networks (NN), by recovering their architectures and parameters. This exposure to model stealing presents risks such as intellectual property theft and adversarial attacks. Masking, a widely used countermeasure for side-channel attacks, has recently been adapted to NN to protect secret model information. However, existing masked NNs incur significant computational overhead or lead to accuracy degradation. In this work, we focus on reducing the main degradation in masking computational costs of non-linear operations specifically activation and argmax. As both operations hinge on sign bit extraction, we achieved an efficient realization using LuTs. Furthermore, we systematically identify and remove flawed masking gadgets that cause accuracy degradation and subsequently apply our gadgets to binarized neural network (BNN). As a result, our proposed BNN implementation securely maintains model accuracy while achieving a 42% performance improvement compared to state-of-the-art software-based masking methods [AWDF21].
Publication
IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2026, Issue 2
PaperArtifact
Artifact number
tches/2026/a24
Artifact published
June 02, 2026
Badge
✅ IACR CHES Artifacts Available
License
This work is licensed under the MIT License.
Note that license information is supplied by the authors and has not been confirmed by the IACR.
BibTeX How to cite
Won Geun Shin, JeongHwan Lee, Sangyun Jung, HeeSeok Kim. (2026). ARMOR: First-Order Masking of Activation and ArgMax Gadgets for Side-Channel Resistant Neural Networks. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(2), 106–131. https://doi.org/10.46586/tches.v2026.i2.106-131. Artifact at https://artifacts.iacr.org/tches/2026/a24.