A Novel Obfuscation Method Based on Majority Logic for Preventing Unauthorized Access to Binary Deep Neural Networks | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Article A Novel Obfuscation Method Based on Majority Logic for Preventing Unauthorized Access to Binary Deep Neural Networks Alireza Mohseni, Mohammad Hossein Moaiyeri, Mohammad Javad Adel This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-6049848/v1 This work is licensed under a CC BY 4.0 License Status: Under Review Version 1 posted 12 You are reading this latest preprint version Abstract The significant expansion of deep learning applications has necessitated safeguarding the deep neural network (DNN) model from potential unauthorized access, highlighting its importance as a valuable asset. This study proposes an innovative key-based algorithm-hardware co-design methodology to protect deep neural network (DNN) models from unauthorized access. The proposed approach significantly reduces model accuracy when an incorrect key is used, thereby preventing unauthorized users from accessing the design. The significance and advancements of binary neural networks (BNNs) in the hardware implementation of cutting-edge DNN models have led us to develop our methodology for BNNs. However, the proposed technique can be broadly applied to various designs for implementing neural network accelerators. The proposed protective approach increases efficiency more than similar solutions across different BNN architectures and standard datasets. We validate our proposed hardware design using post-layout simulations using the Cadence Virtuoso tool and the well-established TSMC 40nm CMOS technology. The proposed approach yields reductions of 43%, 79%, and 71% in area, average power, and weight modification energy per filter in the neural network structures. Additionally, the security of the key circuit has been analyzed and evaluated against Boolean satisfiability-based attacks, structural attacks, reverse engineering, and power-based side-channel attacks. Physical sciences/Engineering/Electrical and electronic engineering Physical sciences/Engineering Deep Neural Network Hardware Obfuscation Spintronic In-Memory Computing Majority Logic Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Under Review Version 1 posted Editorial decision: Revision requested 28 May, 2025 Reviews received at journal 07 May, 2025 Reviews received at journal 06 May, 2025 Reviews received at journal 04 May, 2025 Reviews received at journal 27 Apr, 2025 Reviewers agreed at journal 23 Apr, 2025 Reviewers agreed at journal 22 Apr, 2025 Reviewers agreed at journal 21 Apr, 2025 Reviewers agreed at journal 21 Apr, 2025 Reviewers invited by journal 21 Apr, 2025 Submission checks completed at journal 19 Apr, 2025 First submitted to journal 07 Apr, 2025 You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-6049848","acceptedTermsAndConditions":true,"allowDirectSubmit":false,"archivedVersions":[],"articleType":"Article","associatedPublications":[],"authors":[{"id":446100132,"identity":"dcca95b8-af32-4335-820b-e3059b38e1cf","order_by":0,"name":"Alireza Mohseni","email":"","orcid":"","institution":"Shahid Beheshti University","correspondingAuthor":false,"prefix":"","firstName":"Alireza","middleName":"","lastName":"Mohseni","suffix":""},{"id":446100133,"identity":"e253f4b7-0cd3-4971-a3e1-f01e4de05fc4","order_by":1,"name":"Mohammad Hossein Moaiyeri","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA2UlEQVRIiWNgGAWjYBACAzjJzHyAGSLG2ECsFrYEUrSAAY8BM1EOM2fgTnzwo+CwnHk7z+fPhW0M8vwNzG0f8GmxbODdbNhjcNhY5jDvNumZbQyGMw4wNs/A67ADvNskeAwOJ85g5t3GzNvGwLiBgbEZv1+AWiT/GByun8HM8/gzUIs9UVqkgbYkSDDzMEgDtSQSo2WzsYxBuuEMZjYz6RnnJJJnHCasZePDN3+s5SX4Dz/+XFBmY9vf3v4YrxYG+QcgEm6uBDBO8WuAgTrilI2CUTAKRsHIBADfJT+Kx12g4QAAAABJRU5ErkJggg==","orcid":"","institution":"Shahid Beheshti University","correspondingAuthor":true,"prefix":"","firstName":"Mohammad","middleName":"Hossein","lastName":"Moaiyeri","suffix":""},{"id":446100134,"identity":"477a6e82-5ac0-452f-ba43-c8231b8cec70","order_by":2,"name":"Mohammad Javad Adel","email":"","orcid":"","institution":"Shahid Beheshti University","correspondingAuthor":false,"prefix":"","firstName":"Mohammad","middleName":"Javad","lastName":"Adel","suffix":""}],"badges":[],"createdAt":"2025-02-17 16:53:09","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-6049848/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-6049848/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":81169886,"identity":"b0646632-449b-4a96-904a-90e85885db13","added_by":"auto","created_at":"2025-04-23 05:05:13","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":1223405,"visible":true,"origin":"","legend":"","description":"","filename":"MAJOBFSCR1.pdf","url":"https://assets-eu.researchsquare.com/files/rs-6049848/v1_covered_598aa48a-beda-4bc8-8adc-6a13c4941133.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"A Novel Obfuscation Method Based on Majority Logic for Preventing Unauthorized Access to Binary Deep Neural Networks ","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":true,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"scientific-reports","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"scirep","sideBox":"Learn more about [Scientific Reports](http://www.nature.com/srep/)","snPcode":"","submissionUrl":"","title":"Scientific Reports","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"stoa","reportingPortfolio":"Scientific Reports","inReviewEnabled":true,"inReviewRevisionsEnabled":true},"keywords":"Deep Neural Network, Hardware Obfuscation, Spintronic, In-Memory Computing, Majority Logic","lastPublishedDoi":"10.21203/rs.3.rs-6049848/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-6049848/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eThe significant expansion of deep learning applications has necessitated safeguarding the deep neural network (DNN) model from potential unauthorized access, highlighting its importance as a valuable asset. This study proposes an innovative key-based algorithm-hardware co-design methodology to protect deep neural network (DNN) models from unauthorized access. The proposed approach significantly reduces model accuracy when an incorrect key is used, thereby preventing unauthorized users from accessing the design. The significance and advancements of binary neural networks (BNNs) in the hardware implementation of cutting-edge DNN models have led us to develop our methodology for BNNs. However, the proposed technique can be broadly applied to various designs for implementing neural network accelerators. The proposed protective approach increases efficiency more than similar solutions across different BNN architectures and standard datasets. We validate our proposed hardware design using post-layout simulations using the Cadence Virtuoso tool and the well-established TSMC 40nm CMOS technology. The proposed approach yields reductions of 43%, 79%, and 71% in area, average power, and weight modification energy per filter in the neural network structures. Additionally, the security of the key circuit has been analyzed and evaluated against Boolean satisfiability-based attacks, structural attacks, reverse engineering, and power-based side-channel attacks.\u003c/p\u003e","manuscriptTitle":"A Novel Obfuscation Method Based on Majority Logic for Preventing Unauthorized Access to Binary Deep Neural Networks","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2025-04-23 04:57:00","doi":"10.21203/rs.3.rs-6049848/v1","editorialEvents":[{"type":"communityComments","content":0},{"type":"decision","content":"Revision requested","date":"2025-05-28T06:38:56+00:00","index":"","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2025-05-07T08:24:09+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2025-05-06T12:14:00+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2025-05-04T14:07:20+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2025-04-27T08:39:48+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"145786552991343662597726732804113429127","date":"2025-04-23T14:23:27+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"332111581549293634610540617355163392603","date":"2025-04-22T06:03:47+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"97997260487320799119960616142942805268","date":"2025-04-21T12:14:24+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"245759762954910279197461200401827552102","date":"2025-04-21T12:09:28+00:00","index":"hide","fulltext":""},{"type":"reviewersInvited","content":"","date":"2025-04-21T11:42:04+00:00","index":"","fulltext":""},{"type":"checksComplete","content":"","date":"2025-04-19T06:18:18+00:00","index":"","fulltext":""},{"type":"submitted","content":"Scientific Reports","date":"2025-04-07T07:49:41+00:00","index":"","fulltext":""}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"scientific-reports","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"scirep","sideBox":"Learn more about [Scientific Reports](http://www.nature.com/srep/)","snPcode":"","submissionUrl":"","title":"Scientific Reports","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"stoa","reportingPortfolio":"Scientific Reports","inReviewEnabled":true,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"dc2618b8-fb6b-4495-ac3e-f01e658576b2","owner":[],"postedDate":"April 23rd, 2025","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"under-review","subjectAreas":[{"id":47482267,"name":"Physical sciences/Engineering/Electrical and electronic engineering"},{"id":47482268,"name":"Physical sciences/Engineering"}],"tags":[],"updatedAt":"2025-06-30T07:08:39+00:00","versionOfRecord":[],"versionCreatedAt":"2025-04-23 04:57:00","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-6049848","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-6049848","identity":"rs-6049848","version":["v1"]},"buildId":"8U1c8b4HqxoKbykW_rLl7","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.