Power Side-Channel Membership Inference Attack on Embedded Machine Learning
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "Power Side-Channel Membership Inference Attack on Embedded Machine Learning".
Elias: The gist: PSCMIA, a power side-channel membership inference attack against embedded ML models, infers membership directly from power traces without requiring model outputs.
Nadia: First, who's behind it and why it matters.
Title and authors: Nadia: So we're looking at this paper titled "Power Side-Channel Membership Inference Attack on Embedded Machine Learning" and the authors are Sahan Sanjaya and Prabhat Mishra, Fellow of IEEE. It’s about how to check if someone used a specific training set to build an AI model just by looking at its power usage when it's running on a chip.
Elias: That sounds like they’re trying to find a way around the usual privacy tricks that rely on getting the model's answer, like the probability or the label. They’re focusing on what happens physically when an embedded machine learning model is making a decision.
Priya: I wonder what this means for those edge devices we talk about, you know, smart sensors or wearable tech where the data is super sensitive and you don't want to send it all to the cloud.
Nadia: Exactly. The core idea here is that even if you can't see the output of the model directly, there are still computations happening internally that depend on whether a specific piece of data was in the training set. This paper introduces PSCMIA, which lets you check membership right from power traces without needing any of those usual outputs.
Elias: What makes this methodology interesting to me is how they move away from relying on those explicit outputs and instead look at the internal computations that produce them, which they suggest can be correlated with membership information.
Priya: From a data perspective, I'm curious if this method actually works when you try it on different types of models or even different hardware platforms like the STM32F3 or XMEGA they tested.
Nadia: They did test across several things, including MNIST and CIFAR10 datasets, and both fully connected and convolutional neural network architectures on those two specific embedded platforms. The results show that PSCMIA can achieve ROC-AUC values up to zero point nine zero seven on the fully connected models they evaluated <ref:2610.10909#pg1,up to 0.907 on>.
Elias: A nine-zero-seven score on the FC models is pretty strong, especially since we're talking about inference happening on these constrained chips where every cycle counts. The paper also shows a gap of between zero point zero zero six and zero point one one six in ROC-AUC when comparing PSCMIA to probability vector based shadow MIA for their CNN models, which gives us some context on the performance difference.
Title and authors: Priya: That gap suggests that while this physical attack is effective, it might not be as immediately superior to attacks that use the model's output vectors in every single case across different architectures. But if they outperform label only MIA in eleven of sixteen configurations, that points to a real weakness in the label-only approach when you consider the hardware constraints.
Nadia: That’s right, and it shows that for many setups, physical measurement is a stronger signal than just looking at the final prediction vector. They also noted that this attack performs better when the target model is exhibiting stronger overfitting or making correct predictions across all datasets they tested.
Elias: That correlation between the model's tendency to overfit and its tendency to leak membership information through power traces is a key piece of insight for us as cryptographers, because it links model behavior directly to physical leakage channels.
Priya: It’s interesting that they also said this attack maintains ROC-AUC values above random guessing even when they introduce noise into the power traces up to a level of epsilon equal to one <ref:2610.10909#pg1>. That suggests a degree of resilience against some kind of measurement noise that you might expect in real-world hardware.
Nadia: It means that even if someone tries to mask the signal with some random interference, this membership leakage still stays detectable, which is important for understanding the practical risk here. They also pointed out that removing the segment of a trace corresponding to the final argmax computation doesn't really hurt their performance on FC models much.
Elias: So they’ve localized where the real leak is happening—near that final decision-making step—and it’s not just some random noise scattered everywhere in the power consumption during inference. That level of precision helps narrow down potential countermeasures significantly.
Priya: What this fundamentally changes for us is that we have to consider not just what information is exposed through the software interface, but also what information is unintentionally revealed through their physical side-channels when they're running on these embedded platforms.
Nadia: It definitely shifts the focus from just securing the model's output to securing the entire execution environment of the machine learning inference itself, which has big implications for deploying sensitive AI in constrained settings.
Title and authors: Elias: So we’ve seen how PSCMIA works, how it performs across different models and hardware, and where its leakage is concentrated. This sets us up nicely to look at what they suggest as improvements next.
Priya: I'm ready to hear what they propose to make this attack even more effective or easier for someone trying to exploit these systems.
Nadia: The paper points toward a few ways the work can be improved, focusing on making the attack more precise and robust against different scenarios. They suggest using symmetric KL divergence to quantify membership-dependent separation at each sample point, which is a way to pinpoint exactly where that leakage is occurring within the trace.
Elias: That mathematical tool they introduced for localization seems like it’s designed to give us a clearer map of the membership dependence across the entire inference process, rather than just getting one aggregate score.
Priya: And they also found that meaningful cross-dataset transfer is still possible, especially between datasets like CIFAR10 and CINIC10, which suggests that the attack representations they learn are quite general and not tied to one specific dataset.
Nadia: That cross-dataset transferability is a big deal for defense because if an attacker learns a pattern from one set of images, they can likely apply that same physical leakage knowledge to another set even if the underlying data distribution looks different.
Elias: It confirms that the physical side-channel signal isn't just specific to one particular model or dataset, which means any defense we design has to be more general than just tuning parameters for a single architecture.
Priya: So, in short, they’re suggesting we can use these localization techniques and understand the transferability better to build defenses that are more adaptable across different applications using embedded AI.
Nadia: Exactly. Moving forward, the implication is that protecting sensitive on-device ML deployments requires looking beyond just what the software interface exposes to considering what's unintentionally revealed through their physical side-channels when they're running on these small chips.
Elias: That’s where this paper lands us right now, showing us a concrete way to test that hypothesis with PSCMIA and how we can use it to guide future privacy engineering efforts in the embedded space.
The paper's summary: Nadia: So, this paper, "Power Side-Channel Membership Inference Attack on Embedded Machine Learning," essentially shows how you can figure out if a specific piece of data was used to train an AI model just by measuring its power while it's running on a chip.
Elias: Right. And the big point is that you don't need any outputs from the model, no probabilities or labels—just the physical power trace itself. That’s what makes it interesting for on-device stuff where you can’t always ask the AI for its answer directly.
Priya: From a measurement standpoint, what they found is that this leakage isn't random noise everywhere; it gets concentrated right around the final step where the model makes its decision. It's localized near that argmax computation, which means defenders could actually target those specific parts of the process instead of just trying to mask everything uniformly.
Nadia: That localization is key because it tells us exactly *where* to build our defenses, not just that we need a general shield around the whole operation. And they found that this leakage strength is tied to how much the target model overfits its training data and how well it performs on new stuff.
Elias: That link between model overfitting and physical leakage is a big thing for me because it suggests the more complex or sensitive a model is, the more information about its training set leaks through hardware. It makes you think about making models less prone to that kind of memorization if you’re worried about privacy.
Priya: And even when they tried to test this across different image datasets, like MNIST and CIFAR10, they found that the learned attack patterns still transfer reasonably well between those visually similar tasks. That means if an attacker learns a physical leakage signature for one type of AI task, they can probably use it against another related task.
Nadia: So what this means for us is that protecting sensitive AI deployed on devices isn't just about securing the data in transit or at rest; we also have to look at the physical execution layer when that AI is actually running on hardware.
Elias: It shifts the focus from just model security to system-level privacy, where you have to consider what information is unintentionally leaking through the way the computation itself consumes power.
Priya: It’s a reminder that for embedded systems, privacy isn't just about what you explicitly expose through a network call; it’s about everything happening physically inside the chip while it's working.
Nadia: Exactly. And this paper sets up some interesting next steps by suggesting ways to use tools like symmetric KL divergence to pinpoint where that membership dependence is actually hiding in the trace data.
The paper's improvements: Nadia: So, the paper doesn't just stop there; they suggest a few ways to make this attack even better and more precise. They propose using something called symmetric KL divergence to actually map out where that membership difference is happening at every single point in the trace data.
Elias: That mathematical tool they brought in for localization sounds like it’s supposed to give you a much clearer picture of the whole inference process, not just one total score for the whole thing. It's about getting better spatial resolution on that leakage.
Priya: And they also looked into how this attack behaves when you try to apply it across different image datasets, finding that meaningful transfer is still possible between visually similar collections like CIFAR10 and CINIC10. That suggests the physical leakage signature isn't totally tied to one specific dataset anymore.
Nadia: That cross-dataset transferability is significant because if an attacker learns a physical pattern from one set of images, they can probably use that same knowledge against another set even if the underlying data looks different.
Elias: It confirms that the physical side-channel signal isn't just specific to one particular model or dataset, so any defense we design has to be more general than just tuning parameters for a single architecture.
Priya: And they also pointed out that this attack is correlated with how much the target model overfits and how often it gets its predictions correct. That means defenses should probably focus on making models less prone to memorizing data in the first place if we want to stop the leakage at the source.
Nadia: So what this means for real-world security is that we can start building countermeasures that target those specific high-leakage operations they found, instead of just trying to add some general noise everywhere.
Elias: It’s moving us toward defenses that are more surgical in their approach, targeting the exact computational steps where the membership information is most visible physically.
Priya: And by showing this level of cross-dataset transfer, it gives us a broader view of how these physical leaks manifest across different kinds of machine learning applications.
Conclusion: Tom: So we're wrapping up this look at "Power Side-Channel Membership Inference Attack on Embedded Machine Learning." This paper basically lays out how we can infer membership directly from power traces, bypassing the need for any model outputs whatsoever.
Nadia: Right. The big picture here is that on-device AI systems are getting more sensitive because they aren't just sending data to the cloud; they're running locally, and this attack shows that physical power consumption can still give away training data usage.
Elias: It really highlights the gap between what we assume about software security and what actually happens at the hardware level during execution. The proof relies on exploiting those internal computations that happen even when you suppress the final prediction output.
Priya: What this means for measurement is that we have to start looking at power usage as a potential side channel, not just a black box input or output. It shows that privacy protection can't just be about what you expose through your software interface anymore; it has to include the physical execution layer on these small chips.
Nadia: Exactly. And while they showed strong results—up to zero point nine zero seven ROC-AUC on fully connected models—it’s important to remember that these are specific hardware setups, like the STM32F3 and XMEGA they tested, so we need to keep an eye on those platform-specific risks.
Elias: Yeah, and even with noise in the power traces up to a level of epsilon equal to one, this attack still managed to stay above random guessing. That’s a solid piece of evidence for how persistent this kind of information leakage can be under real-world conditions.
Priya: From my side, the main takeaway is that we need better ways to characterize these physical signals across different tasks and even different datasets because the paper suggests meaningful transferability still exists between them.
Nadia: So we're looking at improving the localization methods, using tools like KL divergence to pinpoint exactly where in the computation this leakage is happening. That’s a good direction for making defenses more targeted rather than just broad noise injection.
Elias: That precision helps us move toward defenses that are surgical, targeting specific high-leakage operations instead of trying to mask everything uniformly during inference on these embedded systems.
Priya: It really underscores the need for privacy researchers to work alongside hardware engineers because these physical side channels are going to be a bigger factor in protecting sensitive AI deployed everywhere.
Nadia: So, this paper, "Power Side-Channel Membership Inference Attack on Embedded Machine Learning," tells us that even when you don't get the model's answer, the way it runs on hardware can still betray its training data.
Elias: It’s a reminder that we have to think beyond just the software logic and consider the physical reality of running AI on constrained devices.
Priya: And as we look at future work, I'm interested in seeing how these cross-dataset transfer findings can help us build more robust privacy defenses that are general across different machine learning applications.
Sahan Sanjaya, Prabhat Mishra
University of Florida
cs.CR, cs.LG
Submitted: 2026-10-07
Updated: 2026-10-07
Code: https://github.com/cpldcpu/BitNetMCU
The gist: The gist: PSCMIA, a power side-channel membership inference attack against embedded ML models, infers membership directly from power traces without requiring model outputs.
Key concepts
- Membership Inference Attack (MIA)
- MIAs try to determine if a specific data point was part of the training set for a machine learning model. This attack usually relies on observing the model's output, such as a prediction score or label. PSCMIA is unique because it achieves this without needing those outputs.
- Power Side-Channel Attack
- This type of attack exploits physical leakage from hardware during computation. It measures the power consumed by an embedded ML device while it runs inference. The hypothesis is that the internal computations related to membership can be inferred from these power traces, even if the final result is hidden.
- Profiling Phase (PSCMIA)
- This initial phase involves training 'shadow models' using data similar to the target model's training set. These shadow models help identify which parts of the recorded power traces are most sensitive to membership information, allowing for precise localization of the leakage.
Terminology
Summary
The gist: PSCMIA, a power side-channel membership inference attack against embedded ML models, infers membership directly from power traces without requiring model outputs.
Introduction and Motivation
Membership inference attacks (MIAs) threaten the privacy of machine learning (ML) training data by determining whether a sample was used to train a target model. Existing MIAs rely on model outputs, ranging from prediction probabilities to predicted labels, an assumption that can be restrictive for ondevice ML systems with limited or inaccessible outputs. Suppressing model outputs does not eliminate the data-dependent computations that produce them, which may remain observable through physical side channels. We hypothesize that power traces collected during embedded ML inference can retain membership-dependent information correlated with the internal computations that determine the model output, even when detailed model outputs are unavailable to the adversary.
PSCMIA Methodology
The proposed attack, PSCMIA, is a power side-channel membership inference attack against embedded ML models that infers membership without access to prediction probabilities, confidence scores, or even the predicted label. The workflow consists of two main phases: a profiling phase and an attack phase.
The profiling phase involves training shadow models using auxiliary datasets drawn from the same distribution as the target model’s training data. Following this, profiling traces are used for leakage localization to identify informative regions. This localization uses the symmetric KL divergence Dj = 1/2 [DKL(p1,j∥p0,j) + DKL(p0,j∥p1,j)] to quantify membership-dependent separation at each sample point j. Feature extraction is performed by applying global standardization followed by principal component analysis (PCA) on the segmented traces to produce a compact representation zi = WT50T˜i.
Experimental Setup and Results
PSCMIA was evaluated across multiple datasets (MNIST, FMNIST, CIFAR10, CINIC10), fully connected (FC) and convolutional neural network (CNN) architectures. It was tested on two embedded platforms: STM32F3 and XMEGA. PSCMIA achieves ROC-AUC values of up to 0.907 on FC models. For CNN models, the ROC-AUC gap between PSCMIA and probability vector-based shadow MIA ranges from 0.006 to 0.116. Across the FC and CNN evaluations, PSCMIA outperforms labelonly MIA in 11 of 16 model-dataset-hardware configurations.
Characterization and Robustness
Analysis showed that membership leakage is concentrated near the final argmax stage. Furthermore, removing the trace segment corresponding to the argmax computation has only a limited effect on FC models. The attack effectiveness is correlated with target-model overfitting and prediction correctness. Finally, PSCMIA demonstrates robustness to noisy power traces, maintaining ROC-AUC values above random guessing even at the strongest evaluated noise level of ε = 1.
Conclusion
PSCMIA presents the first MIA against embedded ML models that relies solely on physically measured power traces, without requiring access to any target-model outputs. The work demonstrates that physical execution can expose membership information even when the model interface reveals no prediction output to the adversary. Therefore, protecting sensitive on-device ML deployments requires considering not only what information is exposed through the software interface, but also what information is unintentionally revealed through their physical side-channels.
References
[1] R. Shokri, M. Stronati, C. Song, and V. Shmatikov, “Membership inference attacks against machine learning models,” in 2017 IEEE symposium on security and privacy (SP). IEEE, 2017, pp. 3–18
[5] H. Hu, Z. Salcic, L. Sun, G. Dobbie, P. S. Yu, and X. Zhang, “Membership inference attacks on machine learning: A survey,” ACM Computing Surveys (CSUR), vol 54, no 11s, pp 1–37
[8] C. A. Choquette-Choo, F. Tramer, N. Carlini, and N. Papernot, “Labelonly membership inference attacks,” in International conference on machine learning PMLR, 2021, pp 1964–1974
[3] cpldcpu, “BitNetMCU: High accuracy low-bit quantized neural networks on a low-end microcontroller,” https://github.com/cpldcpu/BitNetMCU, 2024, accessed June 24, 2026
[4] S. Sanjaya, A. Jayasena, and P. Mishra, “Application-specific power side-channel attacks and countermeasures: A survey,” arXiv preprint arXiv:2512.23785, 2025
[6] A. Salem, Y. Zhang, M. Humbert, P. Berrang, M. Fritz, and M. Backes, “Ml-leaks: Model and data independent membership inference attacks and defenses on machine learning models,” arXiv preprint arXiv:1806.01246, 2018
[7] S. Yeom, I. Giacomelli, M. Fredrikson, and S. Jha, “Privacy risk in machine learning: Analyzing the connection to overfitting,” in 2018 IEEE 31st computer security foundations symposium (CSF). IEEE, 2018
[9] M. Nasr, R. Shokri, and A. Houmansadr, “Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning,” in 2019 IEEE symposium on security and privacy (SP). IEEE, 2019
[13] J. Hayes, L. Melis, G. Danezis, and E. De Cristofaro, “Logan: Membership inference attacks against generative models,” arXiv preprint arXiv:1705.07663, 2017
[25] Y. Chen, X. Jin, J. Sun, R. Zhang, and Y. Zhang, “Powerful: Mobile app fingerprinting via power analysis,” in IEEE INFOCOM 2017-IEEE Conference on Computer Communications. IEEE, 2017
[38] Z. Wang, Y. Wu, Y. Park, S. Yoo, X. Wang, J. K. Eshraghian, and W. D. Lu, “Powergan: a machine learning approach for power side-channel attack on compute-in-memory accelerators,” Advanced Intelligent Systems, vol 5, no 12, p 2300313, 2023
[48] NewAE, “Cw1200 chipwhisperer-pro,” 2023. [Online].
Improvements for AI systems
-
Improved Membership Inference via Unobservable Outputs: The improved system can perform membership inference
without requiring prediction probabilities or even the predicted labels,
directly frompower traces collected during inference.
This allows on-device ML systems to be assessed for training data usage even when conventional output interfaces are unavailable. -
Enhanced Robustness Against Output Suppression: The system is more resilient because it exploits
data-dependent computations that produce them,
hypothesizing thatpower traces collected during embedded ML inference can retain membership-dependent information correlated with the internal computations.
This means privacy protection is not eliminated by restricting outputs, as the leakage remains through physical execution. -
Class-Specific Leakage Characterization: The system can pinpoint exactly where leakage occurs by localizing
membership-relevant separation near the final decision computations
and retaining afixed terminal segment immediately preceding the completion of inference.
This enables defenses to target specific, high-leakage operations rather than suppressing all inference leakage uniformly. -
Overfitting and Correctness Awareness: The system can be optimized based on model vulnerability by showing that
target models exhibiting stronger membership-related behavior through their prediction probability vectors also tend to exhibit stronger membership leakage through power side-channel.
This allows for more targeted privacy hardening based on the target model's internal complexity (overfitting) and its tendency to produce correct predictions. -
Cross-Dataset Transferability Analysis: The improved system can leverage learned attack representations that show
meaningful cross-dataset transfer is still possible,
particularly between datasets with visually similar image classes like CIFAR10 and CINIC10, enabling more generalized privacy defenses across related ML tasks.
Sources
- Application-Specific Power Side-Channel Attacks and Countermeasures: A Survey
- ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models
- LOGAN: Membership Inference Attacks Against Generative Models
- Information Leakage through Physical Layer Supply Voltage Coupling Vulnerability
- SleepWalk: Exploiting Context Switching and Residual Power for Physical Side-Channel Attacks
- Sleep Reveals the Nonce: Breaking ECDSA using Sleep-Based Power Side-Channel Vulnerability
- MLPerf Tiny Benchmark
- TinyML for Ubiquitous Edge AI
- CINIC-10 is not ImageNet or CIFAR-10
- Fashion-MNIST: a Novel Image Dataset for Benchmarking Machine Learning Algorithms
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs