cs.CROct 7, 2026

Power Side-Channel Membership Inference Attack on Embedded Machine Learning

Authors: Sahan Sanjaya, Prabhat Mishra

Organizations: Department of Computer & Information Science & Engineering, University of Florida, USA

Abstract

Membership inference attacks (MIAs) threaten the privacy of machine learning (ML) training data by determining whether a sample was used to train a target model. Existing MIAs rely on model outputs, ranging from prediction probabilities to predicted labels, an assumption that can be restrictive for on-device ML systems with limited or inaccessible outputs. However, suppressing model outputs does not eliminate the data-dependent computations that produce them, which may remain observable through physical side channels. We present PSCMIA, a power side-channel membership inference attack against embedded ML models that can infer membership directly from power traces without requiring prediction probabilities or even the predicted labels. We evaluate PSCMIA across multiple datasets (MNIST, FMNIST, CIFAR10, CINIC10), fully connected (FC) and convolutional neural network (CNN) architectures, and two embedded platforms (STM32F3, XMEGA). PSCMIA achieves ROC-AUC values of up to 0.907 on FC models. For CNN models, the ROC-AUC gap between PSCMIA and probability vector-based shadow MIA ranges from 0.006 to 0.116. Across the FC and CNN evaluations, PSCMIA outperforms label-only MIA in 11 of 16 model-dataset-hardware configurations, demonstrating that physical execution can expose membership information even when conventional model outputs are unavailable through unintended power side-channel leakage.

Figures & tables

Appendix figures & tables7 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. LoMime: Query-Efficient Membership Inference using Model Extraction in Label-Only Settings

    Feb 21, 2026Abdullah Caglar Oksuz, Anisa Halimi, Erman AydayMembership Inference Attacks

  2. CheckMIABench: Firm Foundations For Membership Inference Attacks on Language Models

    Jun 16, 2026Jeffrey G. Wang, Jason Wang, Marvin Li +1LLM EvaluationMembership Inference Attacks

  3. Automated Membership Inference Attacks (AutoMIA): Discovering MIA Signal Computations using LLM Agents

    Mar 19, 2026Toan Tran, Olivera Kotevska, Li XiongMembership Inference Attacks