
Curated index of deep learning latency, energy-latency & timing (availability) attacks and defenses — companion to the ACM Computing Surveys submission.
This repository is maintained as a companion resource for the survey “Deep Learning Latency Attacks and Defenses: A Cross-Domain Survey.” It indexes papers, code links, taxonomy notes, and figures on latency-oriented availability threats in deployed AI systems.
The list focuses on attacks and defenses that affect inference-time or system-level cost — latency, energy, throughput pressure, and deadline misses — rather than attacks that only change model predictions. It currently includes 110 works (71 inference-stage attacks, 13 training-stage attacks, 26 defenses).
Search and filter the catalog in the interactive table on GitHub Pages.
Figure 1. Overview of the survey structure.

Figure 2. Latency attacks as system-level availability threats.

Latency attacks are availability attacks: rather than corrupting a prediction, the adversary inflates the inference-time computation, energy, or wall-clock latency of a model so a real-time consumer (a vehicle controller, an interactive service, a battery-powered sensor) misses its deadline or exhausts its resources — often while the prediction itself remains nominally correct. It connects deployed AI systems, attack-exploited bottlenecks, intermediate-work amplification, system-level failures, and defense control points.
Every attack family shares one mechanism we call intermediate-work amplification: the adversary forces some downstream stage (NMS, self-attention, autoregressive decoding, expert routing) to process more intermediate objects, tokens, or steps than a benign input would generate. Because those stages have super-linear worst-case complexity, a modest increase in count produces a disproportionate cost increase. The natural cross-domain defense is a work budget — an enforced cap on intermediate objects/tokens per unit time.