arrow
Return

Breaking Tiny Machine Learning: Why Quantized Neural Networks Need Domain-Specific Security Analysis

delete2026-02-23
delete0
PRE
AI
J
Jacob Huckelberry
A
Andrea Mattia Garavagno
Y
Yuke Zhang
P
Peter A. Beerel
J
James Mickens
V
Vijay Janapa Reddi
DOI:10.1109/MM.2026.3666128delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Most tiny machine learning (TinyML) hardware focuses on supporting quantized neural networks (QNNs) to meet stringent constraints on power consumption, size, and cost. Despite this, the security aspects of quantization within TinyML hardware remain largely unexplored. Although previous studies indicate that QNNs demonstrate similar or enhanced robustness when compared to full-precision deep neural networks against typical evasion attacks, no attack strategies tailored specifically for TinyML hardware have been proposed yet. This article addresses the aforementioned shortfall by demonstrating how a two-step attack pipeline can surpass the current state of the art in the QNN context and shows the need for more hardware-aware security research.
Keywords:
Hardware
Tiny machine learning
Security
Quantization (signal)
Robustness
Perturbation methods
Glass box
Closed box
Pipelines
Computational modeling

Journal

IEEE Micro cover
IEEE Micro
IF:
2.9
Papers:
125
Citations:
2.7K

Organization

H
Harvard University
Scholars:
26.5W
Papers: 22.0W
Citations: 28.7W
U
university of southern california
Scholars:
4.6W
Papers: 3.8W
Citations: 51