Research Article

Inversion Attacks against CNN Models Based on Timing Attack

Table 3

Meaning of parameters.

Influence of convolution layersMeaningAttribute

The size of input picturesInherent parameters of the convolution layer
The size of the convolution kernelInherent parameters of the convolution layer
Stride convolutionsInherent parameters of the convolution layer
PaddingInherent parameters of the convolution layer
The size of the feature mapAcquired by formula (1)
Input channelInherent parameters of the convolution layer
Output channelInherent parameters of the convolution layer
Execution time of convolutionProvided with profiling file
BiasInherent parameters of the convolution layer
The memory of model weightProvided with profiling file
The memory of model parametersProvided with profiling file
Parameter to be solvedInherent parameters of the model carrier
Weight coefficientInherent parameters of the model carrier
Parameter coefficientInherent parameters of the model carrier
Calculation of convolutionAcquired by formula (5)