Sponge Attack Against Multi-Exit Networks With Data Poisoning

被引:0
|
作者
Huang, Benxuan [1 ]
Pang, Lihui [2 ]
Fu, Anmin [1 ]
Al-Sarawi, Said F. [3 ]
Abbott, Derek [3 ]
Gao, Yansong [4 ]
机构
[1] Nanjing Univ Sci & Technol, Sch Cyber Sci & Engn, Nanjing 210094, Peoples R China
[2] Shenzhen Technol Univ, Sino German Coll Intelligent Mfg, Shenzhen 518118, Peoples R China
[3] Univ Adelaide, Sch Elect & Elect Engn, Adelaide, SA 5005, Australia
[4] CSIROs Data61, Sydney, NSW 2113, Australia
关键词
Training; Data models; Computational modeling; Perturbation methods; Object detection; Optimization; Meteorology; Data integrity; Machine learning; Computer network management; Data poisoning; sponge attack; multi-exit network; machine learning;
D O I
10.1109/ACCESS.2024.3370849
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The motivation for the development of multi-exit networks (MENs) lies in the desire to minimize the delay and energy consumption associated with the inference phase. Moreover, MENs are designed to expedite predictions for easily identifiable inputs by allowing them to exit the network prematurely, thereby reducing the computational burden due to challenging inputs. Nevertheless, there is a lack of comprehensive understanding regarding the security vulnerabilities inherent in MENs. In this study, we introduce a novel approach called the sponge attack, which aims to compromise the fundamental advantages of MENs that allow easily identifiable images to leave in early exits. By employing data poisoning techniques, we frame the sponge attack as an optimization problem that empowers an attacker to select a specific trigger, such as adverse weather conditions (e.g., raining), to compel inputs to traverse the complete network layers of the MEN (e.g., in the context of traffic sign recognition) instead of early-exits when the trigger condition is met. Remarkably, our attack has the capacity to increase inference latency, while maintaining the classification accuracy even in the presence of a trigger, thus operating discreetly. Extensive experimentation on three diverse natural datasets (CIFAR100, GTSRB, and STL10), each trained with three prominent MEN architectures (VGG16, ResNet56, and MSDNet), validates the efficacy of our attack in terms of latency augmentation and its effectiveness in preserving classification accuracy under trigger conditions.
引用
收藏
页码:33843 / 33851
页数:9
相关论文
共 50 条
  • [21] EXTENDING PASCAL WITH ONE-ENTRY MULTI-EXIT PROCEDURES
    COTTAM, ID
    SIGPLAN NOTICES, 1985, 20 (02): : 21 - 31
  • [22] Joint Speech Activity and Overlap Detection with Multi-Exit Architecture
    Du, Ziqing
    Liu, Kai
    Wan, Xucheng
    Zhou, Huan
    PROCEEDINGS OF 2022 ASIA-PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE (APSIPA ASC), 2022, : 59 - 65
  • [23] GRADIENT DECONFLICTION-BASED TRAINING FOR MULTI-EXIT ARCHITECTURES
    Wang, Xinglu
    Li, Yingming
    2020 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2020, : 1866 - 1870
  • [24] Towards improving fast adversarial training in multi-exit network
    Chen, Sihong
    Shen, Haojing
    Wang, Ran
    Wang, Xizhao
    NEURAL NETWORKS, 2022, 150 : 1 - 11
  • [25] Multi-round Data Poisoning Attack and Defense against Truth Discovery in Crowdsensing Systems
    Zhang, Hongniu
    Li, Mohan
    2022 23RD IEEE INTERNATIONAL CONFERENCE ON MOBILE DATA MANAGEMENT (MDM 2022), 2022, : 109 - 118
  • [26] When Monte-Carlo Dropout Meets Multi-Exit: Optimizing Bayesian Neural Networks on FPGA
    Fan, Hongxiang
    Chen, Mark
    Castelli, Liam
    Que, Zhiqiang
    Li, He
    Long, Kenneth
    Luk, Wayne
    2023 60TH ACM/IEEE DESIGN AUTOMATION CONFERENCE, DAC, 2023,
  • [27] ClubMED: Coordinated Multi-Exit Discriminator Strategies for Peering Carriers
    Secci, Stefano
    Rougier, Jean-Louis
    Pattavina, Achille
    Patrone, Fioravante
    Maier, Guido
    2009 NEXT GENERATION INTERNET NETWORKS, 2009, : 196 - +
  • [28] Simulating multi-exit evacuation using deep reinforcement learning
    Xu, Dong
    Huang, Xiao
    Mango, Joseph
    Li, Xiang
    Li, Zhenlong
    TRANSACTIONS IN GIS, 2021, 25 (03) : 1542 - 1564
  • [29] Harmonized Dense Knowledge Distillation Training for Multi-Exit Architectures
    Wang, Xinglu
    Li, Yingming
    THIRTY-FIFTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THIRTY-THIRD CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE AND THE ELEVENTH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2021, 35 : 10218 - 10226
  • [30] RENOGRAM COLLIMATOR MAZE . A DESCRIPTION OF PROBLEM AND A MULTI-EXIT SOLUTION
    BROWN, NJG
    BRITTON, KE
    BRITISH JOURNAL OF RADIOLOGY, 1968, 41 (485): : 397 - +