Decoding HDF5: Machine Learning File Forensics and Data Injection

Decoding HDF5: Machine Learning File Forensics and Data Injection
复制标题

DOI:
10.1007/978-3-031-56580-9_12
复制
发表时间:
2023
期刊:
--
影响因子:
--
通讯作者:
Clinton Walker;I. Baggili;Hao Wang
Clinton Walker;I. Baggili;Hao Wang
中科院分区:
其他
文献类型:
--
作者:
Clinton Walker;I. Baggili;Hao Wang

文献摘要

相似文献

ML在计算中的流行正在迅速扩大,机器学习(ML)系统不断应用于新的挑战。随着这些系统的采用越来越多,其安全性变得越来越重要。ML系统中的任何安全漏洞都可能危及相关系统的完整性。现代机器学习系统通常以紧凑格式封装训练模型以进行存储和分发,包括TensorFlow 2(TF2)及其对分层数据格式5(HDF5)文件格式的利用。这项工作探讨了TF2使用HDF5格式保存训练模型的安全影响,旨在通过取证分析发现潜在的弱点。具体来说,我们调查的注入和检测外来数据在这些打包文件使用自定义工具外部的TF2,导致开发一个专门的取证分析工具TF2的HDF5模型文件。
The prevalence of ML in computing is rapidly expanding and Machine Learning (ML) systems are continuously applied to novel challenges. As the adoption of these systems grows, their security becomes increasingly important. Any security vulnerabilities within an ML system can jeopardize the integrity of dependent and related systems. Modern ML systems commonly encapsulate trained models in a compact format for storage and distribution, including TensorFlow 2 (TF2) and its utilization of the Hierarchical Data Format 5 (HDF5) file format. This work explores into the security implications of TF2 ’s use of the HDF5 format to save trained models, aiming to uncover potential weaknesses via forensic analysis. Specifically, we investigate the injection and detection of foreign data in these packaged files using a custom tool external to TF2, leading to the development of a dedicated forensic analysis tool for TF2 ’s HDF5 model files.