An Empirical Study of Artifacts and Security Risks in the Pre-trained Model Supply Chain

An Empirical Study of Artifacts and Security Risks in the Pre-trained Model Supply Chain
复制标题

DOI:
10.1145/3560835.3564547
复制
发表时间:
2022-11
期刊:
Proceedings of the 2022 ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses
影响因子:
--
通讯作者:
Wenxin Jiang;Nicholas Synovic;R. Sethi;Aryan Indarapu;Matt Hyatt;Taylor R. Schorlemmer;G. Thiruvathukal
Wenxin Jiang;Nicholas Synovic;R. Sethi;Aryan Indarapu;Matt Hyatt;Taylor R. Schorlemmer;G. Thiruvathukal
中科院分区:
其他
文献类型:
--
作者:
Wenxin Jiang;Nicholas Synovic;R. Sethi;Aryan Indarapu;Matt Hyatt;Taylor R. Schorlemmer;G. Thiruvathukal

文献摘要

相似文献

深层神经网络在许多任务上实现最新的表现,但需要越来越复杂的体系结构和昂贵的培训程序。工程师可以通过重复预培训模型(PTM)来降低成本,并为其自己的任务进行微调。为了促进软件重复使用,工程师围绕模型中心,问题域组织的PTM和数据集的集合进行了协作。尽管现在的模型中心与其他软件生态系统相比,但尚未从软件工程的角度检查相关的PTM供应链。我们介绍了8个模型中心中的工件和安全特征的实证研究。我们指出了潜在的威胁模型,并表明现有的防御不足以确保PTM的安全性。我们比较了PTM和传统供应链,并提出了方向,以进一步测量和工具,以提高PTM供应链的可靠性。
Deep neural networks achieve state-of-the-art performance on many tasks, but require increasingly complex architectures and costly training procedures. Engineers can reduce costs by reusing a pre-trained model (PTM) and fine-tuning it for their own tasks. To facilitate software reuse, engineers collaborate around model hubs, collections of PTMs and datasets organized by problem domain. Although model hubs are now comparable in popularity and size to other software ecosystems, the associated PTM supply chain has not yet been examined from a software engineering perspective. We present an empirical study of artifacts and security features in 8 model hubs. We indicate the potential threat models and show that the existing defenses are insufficient for ensuring the security of PTMs. We compare PTM and traditional supply chains, and propose directions for further measurements and tools to increase the reliability of the PTM supply chain.