Security of Embedded AI against Fault Injection through Energy-based attacks

Univ Ubs
Lorient, France
7 days ago
Apply on labsticc.fr
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
French
Job source

Tech stack

Artificial Intelligence C++ (Programming Language) Cyber Security Field-Programmable Gate Array (FPGA) Hardware Security Module Python (Programming Language) Machine Learning Object Detection SQL Databases Graphics Processing Unit (GPU) Information Technology

Job description

This PhD / PostDoc is in the frame of the ANR JCJC Project CoPhyTEE, and will join the Junior Professor Chair environment on Trusted and Autonomous Swarm of Maritime Drones. The Chair aims at providing trust and security on maritime swarms of drones, a strategic and major issue in the current socio-political context. This PostDoc project will build upon previous work on the teams and will collaborate with a current PhD student within the project. The usage of drones, aerial or maritime (surface or underwater) is becoming increasingly widespread in various domains, including recreational and critical. Increasingly more intelligent and autonomous for their missions and navigation, drones embed more and more a certain form of Artificial Intelligence (AI), whose accuracy, depending on the task, might be critical. Complex systems such as drones, often integrate third party Intellectual Property, than can be potentially malicious or infected with trojans, a malicious code or hardware that can be activated under certain specific conditions. Insider trojans could intent to jeopardize the accuracy and function of critical tasks such as AI-based functions, to push towards malfunction and miss-classification, eventually leading to failure of the mission or even collateral damage in the case of drones. In previous work we have studied energy-based attacks through energy optimisation mechanisms such as Dynamic Voltage and Frequency Scaling in processors [LGBPMR25], as well as through the design of specific energy-waster circuits capable of inducing voltage drop-based glitches into the system [LGBPR26]. These attacks have proven successful to induce timing faults in different applications such as encryption tasks. First efforts have started to consider this type of attacks against machine learning models showing significant accuracy drops [SQL+23]. However, the real conditions of the attack, the inherent robustness of the machine learning models to fault injection, and the impact on a real system are still not clear. In this project, we will consider energy-based attacks on a CNN-based application on real drones.

Objectives and Work Program : In this project the main objective is to build upon our previous work on these attacks (on software or hardware) according to the candidate skills to understand the extent and impact on a realistic machine learning application on drones.

Expected outcomes include:

  • Analysis of the real impact of attacks in a realistic drone application. Considered applications, as developed within the team, can include object detection and avoidance, or autonomous navigation.

  • Development of an attack demonstrator on real maritime drones available in the team. We will consider the use of platforms including heterogeneous system-on-chips (SoC) that feature a CPU coupled with some accelerator like an FPGA, GPU, or more specific AI accelerators.

  • Design of countermeasures respecting embedded systems constraints., * Although flexible, the position will ideally start before the end of 2026, with a duration of up to 2 years

Requirements

PhD and PostDoc positions are open on this topic. PostDoc candidate must hold, or be close to defend, a PhD degree in Computer/Hardware Security, Computer/ Electrical Engineering, Computer Science, Embedded Systems, or related domains. PhD candidates must hold, or ensure to hold during the current year, a Master / Engineer degree in Computer/Hardware Security, Computer/Electrical Engineering, Computer Science, Embedded Systems, or related domains. French speaking is not required.

The required skills are:

  • Interest in, familiarity with and/or good knowledge of artificial intelligence, model generation tools and deployment on processors, FPGAs and/or GPUs.

  • Good knowledge of C/C++/Python
  • Good knowledge in Embedded Systems and Computer Architecture
  • Cybersecurity knowledge, skills or interest, for PostDoc and 3 years for PhD.

About the company

  • The candidate will be based and work within the SHAKER team of the Lab-STICC laboratory in Lorient, France and will benefit of SHAKER team drone expertise and platforms. This work is in collaboration

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on labsticc.fr
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:14 min

Evolution of distributed SQL database architectures

Wei Hu Wei Hu · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:36 min

Applying supervised machine learning for practical rule extraction

Katja Träumner

1:55 min

Current state of security in AI applications

Deepu Deepu · World Congress 2025

1:36 min

Evolution from key-value stores to distributed SQL

Wei Hu Wei Hu · World Congress 2025

2:42 min

Dissecting artificial intelligence layers from compute to applications

Christian Nagel Christian Nagel +3 · World Congress 2026 Europe

Videos

See all

Related articles

See all