Paper 2025/1899
FeatureFence: A Regularization Approach for Energy-Efficient Secure Inference on Edge NPUs
Abstract
Feature-snooping attacks (FSA) are very powerful for reverse engineering machine learning models running on neural processing units (NPUs). While memory encryption is an effective countermeasure for cloud devices, the increased data movement causes significant overheads, making it inefficient for edge devices. We make a crucial observation that features dominate the off-chip memory accesses in edge NPUs and propose FeatureFence, which eliminates and compensates for feature encryption via a regularization approach to protect against FSA during inference. Our approach creates neuron pairs in the first layer called couples, and equates weights and biases of neurons within each couple, thereby making reverse engineering mathematically impossible beyond the first layer. During FeatureFence training, the nature of perturbations is gradually learnt across epochs, leading to graceful recovery of functional accuracy. When implemented across a wide range of neural network models mapped to the Eyeriss architecture, on average, FeatureFence is able to reduce energy overheads by ≈ 41% when compared to GuardNN.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- Published elsewhere. Major revision. Accepted at IJCNN 2026
- Keywords
- Neural Processing UnitsMemory EncryptionEnergy-EfficiencyRegularization
- Contact author(s)
-
kjayarathne @ albany edu
spotluri @ albany edu - History
- 2026-04-28: last of 5 revisions
- 2025-10-11: received
- See all versions
- Short URL
- https://ia.cr/2025/1899
- License
-
CC BY-NC-SA
BibTeX
@misc{cryptoeprint:2025/1899,
author = {Sachintha Kavishan Jayarathne and Seetal Potluri},
title = {{FeatureFence}: A Regularization Approach for Energy-Efficient Secure Inference on Edge {NPUs}},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1899},
year = {2025},
url = {https://eprint.iacr.org/2025/1899}
}