StegoNet: Turn Deep Neural Network into a Stegomalware

StegoNet: Turn Deep Neural Network into a Stegomalware
复制标题

DOI:
10.1145/3427228.3427268
复制
发表时间:
2020-12
期刊:
Proceedings of the 36th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Tao Liu;Zihao Liu;Qi Liu;Wujie Wen;Wenyao Xu;Ming Li
Tao Liu;Zihao Liu;Qi Liu;Wujie Wen;Wenyao Xu;Ming Li
中科院分区:
其他
文献类型:
--
作者:
Tao Liu;Zihao Liu;Qi Liu;Wujie Wen;Wenyao Xu;Ming Li

文献摘要

被引文献

相似文献

深度神经网络(DNN)如今在许多现实应用中展现出了人类水平的性能,基于DNN的智能服务在我们生活的各个方面也变得越来越受欢迎。不幸的是,不断增加的DNN服务隐含着一个尚未得到充分研究的危险特征——允许将现有的恶意软件与DNN模型结合,以实现任何预先定义的恶意目的。在本文中,我们全面研究了如何将DNN转变为一种新型的隐蔽自包含隐写恶意软件,即StegoNet,利用模型参数作为一种新颖的有效载荷注入通道,且不会降低服务质量(即准确性),并通过特定的DNN输入将触发事件与现实世界相联系。针对未压缩模型(具有模型冗余)和为资源受限设备定制的深度压缩模型(无模型冗余),开发了一系列利用神经网络的多种独特性质(如复杂结构、高容错能力和巨大的参数规模)的有效载荷注入技术,包括最低有效位替换、容错训练、值映射和符号映射。我们还提出了一组触发技术,如对数触发、秩触发和微调秩触发,以便在现实环境变化下通过特定的物理事件触发StegoNet。我们在英伟达Jetson TX2测试平台上实现了StegoNet原型。关于隐蔽性、所提出的有效载荷注入技术的完整性以及触发技术的可靠性和敏感性的大量实验结果和讨论,很好地证明了StegoNet的可行性和实用性。
Deep Neural Networks (DNNs) are now presenting human-level performance on many real-world applications, and DNN-based intelligent services are becoming more and more popular across all aspects of our lives. Unfortunately, the ever-increasing DNN service implies a dangerous feature which has not yet been well studied–allowing the marriage of existing malware and DNN model for any pre-defined malicious purpose. In this paper, we comprehensively investigate how to turn DNN into a new breed evasive self-contained stegomalware, namely StegoNet, using model parameter as a novel payload injection channel, with no service quality degradation (i.e. accuracy) and the triggering event connected to the physical world by specified DNN inputs. A series of payload injection techniques which take advantage of a variety of unique neural network natures like complex structure, high error resilience capability and huge parameter size, are developed for both uncompressed models (with model redundancy) and deeply compressed models tailored for resource-limited devices (no model redundancy), including LSB substitution, resilience training, value mapping, and sign-mapping. We also proposed a set of triggering techniques like logits trigger, rank trigger and fine-tuned rank trigger to trigger StegoNet by specific physical events under realistic environment variations. We implement the StegoNet prototype on Nvidia Jetson TX2 testbed. Extensive experimental results and discussions on the evasiveness, integrity of proposed payload injection techniques, and the reliability and sensitivity of the triggering techniques, well demonstrate the feasibility and practicality of StegoNet.