ObfuNAS: A Neural Architecture Search-based DNN Obfuscation Approach

被引:0
|
作者
Zhou, Tong [1 ]
Ren, Shaolei [2 ]
Xu, Xiaolin [1 ]
机构
[1] Northeastern Univ, Boston, MA 02115 USA
[2] UC Riverside, Riverside, CA USA
关键词
Deep neural network; Security; Side channels; Architecture obfuscation;
D O I
10.1145/3508352.3549429
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Malicious architecture extraction has been emerging as a crucial concern for deep neural network (DNN) security. As a defense, architecture obfuscation is proposed to remap the victim DNN to a different architecture. Nonetheless, we observe that, with only extracting an obfuscated DNN architecture, the adversary can still retrain a substitute model with high performance (e.g., accuracy), rendering the obfuscation techniques ineffective. To mitigate this under-explored vulnerability, we propose ObfuNAS, which converts the DNN architecture obfuscation into a neural architecture search (NAS) problem. Using a combination of function-preserving obfuscation strategies, ObfuNAS ensures that the obfuscated DNN architecture can only achieve lower accuracy than the victim. We validate the performance of ObfuNAS with open-source architecture datasets like NAS-Bench-101 and NAS-Bench-301. The experimental results demonstrate that ObfuNAS can successfully find the optimal mask for a victim model within a given FLOPs constraint, leading up to 2.6% inference accuracy degradation for attackers with only 0.14x FLOPs overhead. The code is available at: https://github.com/Tongzhou0101/ObfuNAS.
引用
收藏
页数:9
相关论文
共 50 条
  • [31] A Tabu search-based optimization approach for process planning
    Li, WD
    Ong, SK
    Lu, YQ
    Nee, AYC
    KNOWLEDGE-BASED INTELLIGNET INFORMATION AND ENGINEERING SYSTEMS, PT 2, PROCEEDINGS, 2003, 2774 : 1000 - 1007
  • [32] Model refactoring using examples: a search-based approach
    Ghannem, Adnane
    El Boussaidi, Ghizlane
    Kessentini, Marouane
    JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2014, 26 (07) : 692 - 713
  • [33] Constructing Search Spaces for Search-Based Software Testing Using Neural Networks
    Joffe, Leonid
    Clark, David
    SEARCH-BASED SOFTWARE ENGINEERING, SSBSE 2019, 2019, 11664 : 27 - 41
  • [34] Search-based Neural Structured Learning for Sequential Question Answering
    Iyyer, Mohit
    Yih, Wen-tau
    Chang, Ming-Wei
    PROCEEDINGS OF THE 55TH ANNUAL MEETING OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS (ACL 2017), VOL 1, 2017, : 1821 - 1831
  • [35] Construction of heuristics for a search-based approach to solving Snudoku
    Jones, S. K.
    Roach, P. A.
    Perkins, S.
    RESEARCH AND DEVELOPMENT IN INTELLIGENT SYSTEMS XXIV, 2008, : 37 - 49
  • [36] A tabu search-based approach for online motion planning
    Masehian, Ellips
    Amin-Naseri, M. R.
    2006 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL TECHNOLOGY, VOLS 1-6, 2006, : 1639 - +
  • [37] An experimental search-based approach to cohesion metric evaluation
    Mel Ó Cinnéide
    Iman Hemati Moghadam
    Mark Harman
    Steve Counsell
    Laurence Tratt
    Empirical Software Engineering, 2017, 22 : 292 - 329
  • [38] An experimental search-based approach to cohesion metric evaluation
    Cinneide, Mel O.
    Moghadam, Iman Hemati
    Harman, Mark
    Counsell, Steve
    Tratt, Laurence
    EMPIRICAL SOFTWARE ENGINEERING, 2017, 22 (01) : 292 - 329
  • [39] A SEARCH-BASED APPROACH FOR PREDICTION OF FLEXIBLE HOSE SHAPES
    Hermann, Tristan
    Patil, Lalit
    Srinivas, Lakshmi
    Murthy, Krishna
    Dutta, Debasish
    INTERNATIONAL MECHANICAL ENGINEERING CONGRESS AND EXPOSITION - 2012, VOL 3, PTS A-C: DESIGN, MATERIALS, AND MANUFACTURING, 2013, : 397 - 404
  • [40] NAS-AMR: Neural Architecture Search-Based Automatic Modulation Recognition for Integrated Sensing and Communication Systems
    Zhang, Xixi
    Zhao, Haitao
    Zhu, Hongbo
    Adebisi, Bamidele
    Gui, Guan
    Gacanin, Haris
    Adachi, Fumiyuki
    IEEE TRANSACTIONS ON COGNITIVE COMMUNICATIONS AND NETWORKING, 2022, 8 (03) : 1374 - 1386