A Generative Framework for Low-Cost Result Validation of Machine Learning-as-a-Service Inference

A Generative Framework for Low-Cost Result Validation of Machine Learning-as-a-Service Inference
复制标题

DOI:
10.1145/3634737.3657015
复制
发表时间:
2023-03
期刊:
Proceedings of the 19th ACM Asia Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Abhinav Kumar;Miguel A. Guirao Aguilera;R. Tourani;S. Misra
Abhinav Kumar;Miguel A. Guirao Aguilera;R. Tourani;S. Misra
中科院分区:
其他
文献类型:
--
作者:
Abhinav Kumar;Miguel A. Guirao Aguilera;R. Tourani;S. Misra

文献摘要

相似文献

机器学习(ML)日益普及,已被应用于各个敏感领域,这促使大量研究聚焦于ML的安全和隐私问题。然而,在一些应用中,比如增强/虚拟现实,外包ML任务的完整性验证更为关键——这是一个尚未受到足够关注的方面。现有的解决方案,如多方计算和基于证明的系统,会产生巨大的计算开销,这使得它们不适合实时应用。我们提出了Fides,一种用于ML即服务(MLaaS)推理实时完整性验证的新颖框架。Fides具有一种新颖且高效的蒸馏技术——贪婪蒸馏迁移学习,它能动态蒸馏并微调一个空间和计算高效的验证模型,以便在可信执行环境中运行时验证相应的服务模型。Fides具有一个客户端攻击检测模型,该模型利用统计分析和差异度量来高概率地识别服务模型是否受到攻击。Fides还提供了一个重新分类功能,每当识别到攻击时,它能预测原始类别。我们设计了一个生成对抗网络框架来训练攻击检测和重新分类模型。评估表明,Fides的攻击检测准确率高达98%,重新分类准确率高达94%。
The growing popularity of Machine Learning (ML) has led to its deployment in various sensitive domains, which has resulted in significant research focused on ML security and privacy. However, in some applications, such as Augmented/Virtual Reality, integrity verification of the outsourced ML tasks is more critical-a facet that has not received much attention. Existing solutions, such as multi-party computation and proof-based systems, impose significant computation overhead, which makes them unfit for real-time applications. We propose Fides, a novel framework for real-time integrity validation of ML-as-a-Service (MLaaS) inference. Fides features a novel and efficient distillation technique-Greedy Distillation Transfer Learning-that dynamically distills and fine-tunes a space and compute-efficient verification model for verifying the corresponding service model while running inside a trusted execution environment. Fides features a client-side attack detection model that uses statistical analysis and divergence measurements to identify, with a high likelihood, if the service model is under attack. Fides also offers a re-classification functionality that predicts the original class whenever an attack is identified. We devised a generative adversarial network framework for training the attack detection and re-classification models. The evaluation shows that Fides achieves an accuracy of up to 98% for attack detection and 94% for re-classification.