A system-level perspective to understand the vulnerability of deep learning systems

A system-level perspective to understand the vulnerability of deep learning systems
复制标题

从系统级角度理解深度学习系统的脆弱性

DOI:
10.1145/3287624.3288751
复制
发表时间:
2019
期刊:
2019 IEEE 24th Asia and South Pacific Design Automation Conference (ASP-DAC
影响因子:
--
通讯作者:
Wen, Wujie
Wen, Wujie
中科院分区:
--
文献类型:
--
作者:
Liu, Tao;Xu, Nuo;Liu, Qi;Wang, Yanzhi;Wen, Wujie

文献摘要

参考文献

被引文献

相似文献

深度神经网络(DNN)目前在自动驾驶汽车、游戏和计算机辅助诊断等许多机器学习应用中取得了人类水平的性能。然而,最近的研究表明,这样一种前景看好的技术已经逐渐成为主要的攻击目标,严重威胁着机器学习服务的安全。一方面,DNN算法漏洞引起的对抗性攻击或中毒攻击会导致决策的误导性和很高的置信度。另一方面,建立在DNN执行过程中的模型、训练/推理算法和硬件和软件之上的系统级DNN攻击也出现了,其危害更加多样化,如拒绝服务、私人数据窃取。在本文中,我们通过系统地制定攻击例程,对这些新兴的系统级DNN攻击进行了概述。本文选取了几个具有代表性的案例来总结系统级DNN攻击的特点。基于我们的公式,我们进一步讨论了挑战和几种可能的技术来缓解这种新出现的系统级DNN攻击。
Deep neural network (DNN) is nowadays achieving the human-level performance on many machine learning applications like self-driving car, gaming and computer-aided diagnosis. However, recent studies show that such a promising technique has gradually become the major attack target, significantly threatening the safety of machine learning services. On one hand, the adversarial or poisoning attacks incurred by DNN algorithm vulnerabilities can cause the decision misleading with very high confidence. On the other hand, the system-level DNN attacks built upon models, training/inference algorithms and hardware and software in DNN execution, have also emerged for more diversified damages like denial of service, private data stealing. In this paper, we present an overview of such emerging system-level DNN attacks by systematically formulating their attack routines. Several representative cases are selected in our study to summarize the characteristics of system-level DNN attacks. Based on our formulation, we further discuss the challenges and several possible techniques to mitigate such emerging system-level DNN attacks.
DOI: 10.1145/3133956.3134077
发表时间: 2017-09
期刊: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Congzheng Song;Thomas Ristenpart;Vitaly Shmatikov
通讯作者: Congzheng Song;Thomas Ristenpart;Vitaly Shmatikov