ObfuNAS: A Neural Architecture Search-based DNN Obfuscation Approach

被引:0
|
作者
Zhou, Tong [1 ]
Ren, Shaolei [2 ]
Xu, Xiaolin [1 ]
机构
[1] Northeastern Univ, Boston, MA 02115 USA
[2] UC Riverside, Riverside, CA USA
关键词
Deep neural network; Security; Side channels; Architecture obfuscation;
D O I
10.1145/3508352.3549429
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Malicious architecture extraction has been emerging as a crucial concern for deep neural network (DNN) security. As a defense, architecture obfuscation is proposed to remap the victim DNN to a different architecture. Nonetheless, we observe that, with only extracting an obfuscated DNN architecture, the adversary can still retrain a substitute model with high performance (e.g., accuracy), rendering the obfuscation techniques ineffective. To mitigate this under-explored vulnerability, we propose ObfuNAS, which converts the DNN architecture obfuscation into a neural architecture search (NAS) problem. Using a combination of function-preserving obfuscation strategies, ObfuNAS ensures that the obfuscated DNN architecture can only achieve lower accuracy than the victim. We validate the performance of ObfuNAS with open-source architecture datasets like NAS-Bench-101 and NAS-Bench-301. The experimental results demonstrate that ObfuNAS can successfully find the optimal mask for a victim model within a given FLOPs constraint, leading up to 2.6% inference accuracy degradation for attackers with only 0.14x FLOPs overhead. The code is available at: https://github.com/Tongzhou0101/ObfuNAS.
引用
收藏
页数:9
相关论文
共 50 条
  • [21] A Max-Flow Based Approach for Neural Architecture Search
    Xue, Chao
    Wang, Xiaoxing
    Yan, Junchi
    Li, Chun-Guang
    COMPUTER VISION, ECCV 2022, PT XX, 2022, 13680 : 685 - 701
  • [22] Neural-Driven Search-Based Paraphrase Generation
    Fabre, Betty
    Chevelu, Jonathan
    Urvoy, Tanguy
    Lolive, Damien
    16TH CONFERENCE OF THE EUROPEAN CHAPTER OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS (EACL 2021), 2021, : 2100 - 2111
  • [23] Arachne: Search-Based Repair of Deep Neural Networks
    Sohn, Jeongju
    Kang, Sungmin
    Yoo, Shin
    ACM TRANSACTIONS ON SOFTWARE ENGINEERING AND METHODOLOGY, 2023, 32 (04)
  • [24] TypeWriter: Neural Type Prediction with Search-Based Validation
    Pradel, Michael
    Gousios, Georgios
    Liu, Jason
    Chandra, Satish
    PROCEEDINGS OF THE 28TH ACM JOINT MEETING ON EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING (ESEC/FSE '20), 2020, : 209 - 220
  • [25] Stochastic Search-Based Neural Networks Learning Algorithms
    Nikolic, Konstantin P.
    Scepanovic, Ivan B.
    NEUREL 2008: NINTH SYMPOSIUM ON NEURAL NETWORK APPLICATIONS IN ELECTRICAL ENGINEERING, PROCEEDINGS, 2008, : 98 - 102
  • [26] Towards Search-Based Modelling and Analysis of Requirements and Architecture Decisions
    Busari, Saheed A.
    PROCEEDINGS OF THE 2017 32ND IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING (ASE'17), 2017, : 1026 - 1029
  • [27] Untangling the Knot: Enabling Architecture Evolution with Search-Based Refactoring
    Ivers, James
    Seifried, Chris
    Ozkaya, Ipek
    IEEE 19TH INTERNATIONAL CONFERENCE ON SOFTWARE ARCHITECTURE (ICSA 2022), 2022, : 101 - 111
  • [28] Orthogonal search-based rule extraction (OSRE) for trained neural networks: A practical and efficient approach
    Etchells, TA
    Lisboa, PJG
    IEEE TRANSACTIONS ON NEURAL NETWORKS, 2006, 17 (02): : 374 - 384
  • [29] THE PRICING OF INFORMATION - A SEARCH-BASED APPROACH TO PRICING AN ONLINE SEARCH SERVICE
    BOYLE, HF
    ONLINE REVIEW, 1982, 6 (06): : 517 - 523
  • [30] Search-based models of money and finance: An integrated approach
    Trejos, Alberto
    Wright, Randall
    JOURNAL OF ECONOMIC THEORY, 2016, 164 : 10 - 31