{"id":"https://openalex.org/W4409311429","doi":"https://doi.org/10.1145/3720471","title":"Verification of Bit-Flip Attacks against Quantized Neural Networks","display_name":"Verification of Bit-Flip Attacks against Quantized Neural Networks","publication_year":2025,"publication_date":"2025-04-09","ids":{"openalex":"https://openalex.org/W4409311429","doi":"https://doi.org/10.1145/3720471"},"language":"en","primary_location":{"id":"doi:10.1145/3720471","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3720471","pdf_url":null,"source":{"id":"https://openalex.org/S4210216081","display_name":"Proceedings of the ACM on Programming Languages","issn_l":"2475-1421","issn":["2475-1421"],"is_oa":true,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM on Programming Languages","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"diamond","oa_url":"https://doi.org/10.1145/3720471","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5046247329","display_name":"Yedi Zhang","orcid":"https://orcid.org/0000-0003-1005-2114"},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":true,"raw_author_name":"Yedi Zhang","raw_affiliation_strings":["National University of Singapore, Singapore, Singapore"],"raw_orcid":"https://orcid.org/0000-0003-1005-2114","affiliations":[{"raw_affiliation_string":"National University of Singapore, Singapore, Singapore","institution_ids":["https://openalex.org/I165932596"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Lei Huang","orcid":"https://orcid.org/0009-0002-6412-2149"},"institutions":[{"id":"https://openalex.org/I30809798","display_name":"ShanghaiTech University","ror":"https://ror.org/030bhh786","country_code":"CN","type":"education","lineage":["https://openalex.org/I30809798"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Lei Huang","raw_affiliation_strings":["ShanghaiTech University, Shanghai, China"],"raw_orcid":"https://orcid.org/0009-0002-6412-2149","affiliations":[{"raw_affiliation_string":"ShanghaiTech University, Shanghai, China","institution_ids":["https://openalex.org/I30809798"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101924725","display_name":"Pengfei Gao","orcid":"https://orcid.org/0000-0003-3800-2565"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Pengfei Gao","raw_affiliation_strings":["ByteDance Inc, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0003-3800-2565","affiliations":[{"raw_affiliation_string":"ByteDance Inc, Beijing, China","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5027425633","display_name":"Fu Song","orcid":"https://orcid.org/0000-0002-0581-2679"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I2799736854","display_name":"Nanjing Institute of Technology","ror":"https://ror.org/00n6txq60","country_code":"CN","type":"education","lineage":["https://openalex.org/I2799736854"]},{"id":"https://openalex.org/I4210128818","display_name":"Institute of Software","ror":"https://ror.org/033dfsn42","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210128818"]},{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Fu Song","raw_affiliation_strings":["Institute of Software at Chinese Academy of Sciences, Beijing, China","Nanjing Institute of Software Technology, Nanjing, China","University of Chinese Academy of Sciences, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0002-0581-2679","affiliations":[{"raw_affiliation_string":"Institute of Software at Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210128818","https://openalex.org/I19820366"]},{"raw_affiliation_string":"Nanjing Institute of Software Technology, Nanjing, China","institution_ids":["https://openalex.org/I2799736854","https://openalex.org/I4210128818"]},{"raw_affiliation_string":"University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210165038"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100429004","display_name":"Jun Sun","orcid":"https://orcid.org/0000-0002-3545-1392"},"institutions":[{"id":"https://openalex.org/I79891267","display_name":"Singapore Management University","ror":"https://ror.org/050qmg959","country_code":"SG","type":"education","lineage":["https://openalex.org/I79891267"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Jun Sun","raw_affiliation_strings":["Singapore Management University, Singapore, Singapore"],"raw_orcid":"https://orcid.org/0000-0002-3545-1392","affiliations":[{"raw_affiliation_string":"Singapore Management University, Singapore, Singapore","institution_ids":["https://openalex.org/I79891267"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5085067496","display_name":"Jin Song Dong","orcid":"https://orcid.org/0000-0002-6512-8326"},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Jin Song Dong","raw_affiliation_strings":["National University of Singapore, Singapore, Singapore"],"raw_orcid":"https://orcid.org/0000-0002-6512-8326","affiliations":[{"raw_affiliation_string":"National University of Singapore, Singapore, Singapore","institution_ids":["https://openalex.org/I165932596"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5046247329"],"corresponding_institution_ids":["https://openalex.org/I165932596"],"apc_list":null,"apc_paid":null,"fwci":4.3465,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.93576412,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":91,"max":98},"biblio":{"volume":"9","issue":"OOPSLA1","first_page":"984","last_page":"1014"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9983999729156494,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/bit","display_name":"Bit (key)","score":0.652341365814209},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5744460821151733},{"id":"https://openalex.org/keywords/flip","display_name":"Flip","score":0.546323835849762},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.49595603346824646},{"id":"https://openalex.org/keywords/arithmetic","display_name":"Arithmetic","score":0.34279000759124756},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.25880300998687744},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.2092917561531067},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.19535741209983826},{"id":"https://openalex.org/keywords/chemistry","display_name":"Chemistry","score":0.09761619567871094}],"concepts":[{"id":"https://openalex.org/C117011727","wikidata":"https://www.wikidata.org/wiki/Q1278488","display_name":"Bit (key)","level":2,"score":0.652341365814209},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5744460821151733},{"id":"https://openalex.org/C2776591724","wikidata":"https://www.wikidata.org/wiki/Q5459651","display_name":"Flip","level":3,"score":0.546323835849762},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.49595603346824646},{"id":"https://openalex.org/C94375191","wikidata":"https://www.wikidata.org/wiki/Q11205","display_name":"Arithmetic","level":1,"score":0.34279000759124756},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.25880300998687744},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.2092917561531067},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.19535741209983826},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.09761619567871094},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C190283241","wikidata":"https://www.wikidata.org/wiki/Q14599311","display_name":"Apoptosis","level":2,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3720471","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3720471","pdf_url":null,"source":{"id":"https://openalex.org/S4210216081","display_name":"Proceedings of the ACM on Programming Languages","issn_l":"2475-1421","issn":["2475-1421"],"is_oa":true,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM on Programming Languages","raw_type":"journal-article"},{"id":"pmh:oai:ink.library.smu.edu.sg:sis_research-11159","is_oa":false,"landing_page_url":"https://ink.library.smu.edu.sg/sis_research/10159","pdf_url":null,"source":{"id":"https://openalex.org/S4306401925","display_name":"Singapore Management University Institutional Knowledge (InK) (Singapore Management University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I79891267","host_organization_name":"Singapore Management University","host_organization_lineage":["https://openalex.org/I79891267"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"https://doi.org/10.1145/3720471","raw_type":"Journal Article"}],"best_oa_location":{"id":"doi:10.1145/3720471","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3720471","pdf_url":null,"source":{"id":"https://openalex.org/S4210216081","display_name":"Proceedings of the ACM on Programming Languages","issn_l":"2475-1421","issn":["2475-1421"],"is_oa":true,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM on Programming Languages","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":67,"referenced_works":["https://openalex.org/W1829732909","https://openalex.org/W2085992264","https://openalex.org/W2170489924","https://openalex.org/W2594877703","https://openalex.org/W2747329762","https://openalex.org/W2794609696","https://openalex.org/W2802557767","https://openalex.org/W2807835252","https://openalex.org/W2896500468","https://openalex.org/W2900153411","https://openalex.org/W2917325587","https://openalex.org/W2939057911","https://openalex.org/W2946149952","https://openalex.org/W2957311447","https://openalex.org/W2963122961","https://openalex.org/W2963600714","https://openalex.org/W2974147052","https://openalex.org/W2974891422","https://openalex.org/W2981639301","https://openalex.org/W2981860227","https://openalex.org/W2982540258","https://openalex.org/W2998161546","https://openalex.org/W3004061291","https://openalex.org/W3034665124","https://openalex.org/W3046662910","https://openalex.org/W3092516112","https://openalex.org/W3094683669","https://openalex.org/W3102139284","https://openalex.org/W3102458427","https://openalex.org/W3103148066","https://openalex.org/W3133752511","https://openalex.org/W3136021864","https://openalex.org/W3147451797","https://openalex.org/W3153453329","https://openalex.org/W3155048100","https://openalex.org/W3157763265","https://openalex.org/W3166180472","https://openalex.org/W3168587836","https://openalex.org/W3176862352","https://openalex.org/W3183549096","https://openalex.org/W3212502396","https://openalex.org/W3213793813","https://openalex.org/W4211137390","https://openalex.org/W4224919922","https://openalex.org/W4233996382","https://openalex.org/W4242053016","https://openalex.org/W4245276998","https://openalex.org/W4280555383","https://openalex.org/W4287254789","https://openalex.org/W4296270209","https://openalex.org/W4306407446","https://openalex.org/W4312596145","https://openalex.org/W4312620108","https://openalex.org/W4312770063","https://openalex.org/W4313563880","https://openalex.org/W4319596548","https://openalex.org/W4378902066","https://openalex.org/W4378904019","https://openalex.org/W4384521896","https://openalex.org/W4385688985","https://openalex.org/W4388574628","https://openalex.org/W4390872667","https://openalex.org/W4391568841","https://openalex.org/W4393161192","https://openalex.org/W4394673457","https://openalex.org/W4402397315","https://openalex.org/W4402457520"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W4327546585","https://openalex.org/W2411923897","https://openalex.org/W4394546135","https://openalex.org/W4285347720","https://openalex.org/W4200259850","https://openalex.org/W2333831899","https://openalex.org/W2484894494"],"abstract_inverted_index":{"In":[0],"the":[1,9,61,72,86,94,139,154,160],"rapidly":[2],"evolving":[3],"landscape":[4],"of":[5,11,26,44,64,75,96,162],"neural":[6,12,66,77],"network":[7],"security,":[8],"resilience":[10,161],"networks":[13,67,78],"against":[14,57,99],"bit-flip":[15,97,141],"attacks":[16,70,98],"(i.e.,":[17],"an":[18,22,118,122,172],"attacker":[19],"maliciously":[20],"flips":[21],"extremely":[23],"small":[24],"amount":[25],"bits":[27],"within":[28],"its":[29,197],"parameter":[30],"storage":[31],"memory":[32],"system":[33],"to":[34,68,91,102,134,158],"induce":[35],"harmful":[36],"behavior),":[37],"has":[38],"emerged":[39],"as":[40,53],"a":[41,54,108,129,145,150],"relevant":[42],"area":[43],"research.":[45],"Existing":[46],"studies":[47],"suggest":[48],"that":[49,137],"quantization":[50,205],"may":[51],"serve":[52],"viable":[55],"defense":[56],"such":[58,69,163],"attacks.":[59],"Recognizing":[60],"documented":[62],"susceptibility":[63],"real-valued":[65],"and":[71,110,121,188,199,207],"comparative":[73],"robustness":[74],"quantized":[76],"(QNNs),":[79],"in":[80,107],"this":[81,168],"work,":[82],"we":[83,126,166],"introduce":[84],"BFAVerifier,":[85],"first":[87,127],"verification":[88,169],"framework":[89],"designed":[90],"formally":[92],"verify":[93],"absence":[95],"QNNs":[100],"or":[101],"identify":[103],"all":[104],"vulnerable":[105],"parameters":[106,136],"sound":[109,151],"rigorous":[111],"manner.":[112],"BFAVerifier":[113,184],"comprises":[114],"two":[115],"integral":[116],"components:":[117],"abstraction-based":[119],"method":[120],"MILP-based":[123],"method.":[124],"Specifically,":[125],"conduct":[128,192],"reachability":[130,155],"analysis":[131,156],"with":[132,149],"respect":[133],"symbolic":[135],"represent":[138],"potential":[140],"attacks,":[142,164],"based":[143],"on":[144],"novel":[146],"abstract":[147],"domain":[148],"guarantee.":[152],"If":[153],"fails":[157],"prove":[159],"then":[165],"encode":[167],"problem":[170,175],"into":[171],"equivalent":[173],"MILP":[174],"which":[176,195],"can":[177],"be":[178],"solved":[179],"by":[180],"off-the-shelf":[181],"solvers.":[182],"Therefore,":[183],"is":[185],"sound,":[186],"complete,":[187],"reasonably":[189],"efficient.":[190],"We":[191],"extensive":[193],"experiments,":[194],"demonstrate":[196],"effectiveness":[198],"efficiency":[200],"across":[201],"various":[202],"activation":[203],"functions,":[204],"bit-widths,":[206],"adversary":[208],"capabilities.":[209]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
