ObfuNAS: A Neural Architecture Search-based DNN Obfuscation Approach

被引:0
|
作者
Zhou, Tong [1 ]
Ren, Shaolei [2 ]
Xu, Xiaolin [1 ]
机构
[1] Northeastern Univ, Boston, MA 02115 USA
[2] UC Riverside, Riverside, CA USA
关键词
Deep neural network; Security; Side channels; Architecture obfuscation;
D O I
10.1145/3508352.3549429
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Malicious architecture extraction has been emerging as a crucial concern for deep neural network (DNN) security. As a defense, architecture obfuscation is proposed to remap the victim DNN to a different architecture. Nonetheless, we observe that, with only extracting an obfuscated DNN architecture, the adversary can still retrain a substitute model with high performance (e.g., accuracy), rendering the obfuscation techniques ineffective. To mitigate this under-explored vulnerability, we propose ObfuNAS, which converts the DNN architecture obfuscation into a neural architecture search (NAS) problem. Using a combination of function-preserving obfuscation strategies, ObfuNAS ensures that the obfuscated DNN architecture can only achieve lower accuracy than the victim. We validate the performance of ObfuNAS with open-source architecture datasets like NAS-Bench-101 and NAS-Bench-301. The experimental results demonstrate that ObfuNAS can successfully find the optimal mask for a victim model within a given FLOPs constraint, leading up to 2.6% inference accuracy degradation for attackers with only 0.14x FLOPs overhead. The code is available at: https://github.com/Tongzhou0101/ObfuNAS.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] FPL Demo: Logic Shrinkage: A Neural Architecture Search-Based Approach to FPGA Netlist Generation
    Auffret, Marie
    Wang, Erwei
    Davis, James J.
    2022 32ND INTERNATIONAL CONFERENCE ON FIELD-PROGRAMMABLE LOGIC AND APPLICATIONS, FPL, 2022, : 470 - 470
  • [2] Negotiation of service level agreements: An architecture and a search-based approach
    Di Nitto, Elisabetta
    Di Penta, Massimiliano
    Gambi, Alessio
    Ripa, Gianluca
    Villani, Maria Luisa
    SERVICE-ORIENTED COMPUTING - ICSOC 2007, PROCEEDINGS, 2007, 4749 : 295 - +
  • [3] NASEI: Neural Architecture Search-Based Specific Emitter Identification Method
    Huang, Yuxuan
    Zhang, Xixi
    Wang, Yu
    Jiao, Donglai
    Gui, Guan
    Ohtsuki, Tomoaki
    2023 IEEE 97TH VEHICULAR TECHNOLOGY CONFERENCE, VTC2023-SPRING, 2023,
  • [4] SearchAuth: Neural Architecture Search-based Continuous Authentication Using Auto Augmentation Search
    Li, Yantao
    Luo, Jiaxing
    Deng, Shaojiang
    Zhou, Gang
    ACM TRANSACTIONS ON SENSOR NETWORKS, 2023, 19 (04)
  • [5] DeepEvolution: A Search-Based Testing Approach for Deep Neural Networks
    Ben Braiek, Houssem
    Khomh, Foutse
    2019 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE AND EVOLUTION (ICSME 2019), 2019, : 454 - 458
  • [6] AutoReCon: Neural Architecture Search-based Reconstruction for Data-free Compression
    Zhu, Baozhou
    Hofstee, Peter
    Peltenburg, Johan
    Lee, Jinho
    Alars, Zaid
    PROCEEDINGS OF THE THIRTIETH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, IJCAI 2021, 2021, : 3470 - 3476
  • [7] Harmony Search-Based Approach for Multi-Objective Software Architecture Reconstruction
    Prajapati, Amarjeet
    Geem, Zong Woo
    MATHEMATICS, 2020, 8 (11) : 1 - 21
  • [8] Neural Architecture Search-Based Few-Shot Learning for Hyperspectral Image Classification
    Xiao, Fen
    Xiang, Han
    Cao, Chunhong
    Gao, Xieping
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2024, 62 : 1 - 15
  • [9] Differentiable Architecture Search-Based Automatic Modulation Classification
    Wei, Xun
    Luo, Wang
    Zhang, Xixi
    Yang, Jie
    Gui, Guan
    Ohtsuki, Tomoaki
    2021 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2021,
  • [10] Interleaving human and search-based software architecture design
    Vathsavayi, Sriharsha
    Hadaytullah
    Koskimies, Kai
    PROCEEDINGS OF THE ESTONIAN ACADEMY OF SCIENCES, 2013, 62 (01) : 16 - 26