Sponge Attack Against Multi-Exit Networks With Data Poisoning

被引:0
|
作者
Huang, Benxuan [1 ]
Pang, Lihui [2 ]
Fu, Anmin [1 ]
Al-Sarawi, Said F. [3 ]
Abbott, Derek [3 ]
Gao, Yansong [4 ]
机构
[1] Nanjing Univ Sci & Technol, Sch Cyber Sci & Engn, Nanjing 210094, Peoples R China
[2] Shenzhen Technol Univ, Sino German Coll Intelligent Mfg, Shenzhen 518118, Peoples R China
[3] Univ Adelaide, Sch Elect & Elect Engn, Adelaide, SA 5005, Australia
[4] CSIROs Data61, Sydney, NSW 2113, Australia
关键词
Training; Data models; Computational modeling; Perturbation methods; Object detection; Optimization; Meteorology; Data integrity; Machine learning; Computer network management; Data poisoning; sponge attack; multi-exit network; machine learning;
D O I
10.1109/ACCESS.2024.3370849
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The motivation for the development of multi-exit networks (MENs) lies in the desire to minimize the delay and energy consumption associated with the inference phase. Moreover, MENs are designed to expedite predictions for easily identifiable inputs by allowing them to exit the network prematurely, thereby reducing the computational burden due to challenging inputs. Nevertheless, there is a lack of comprehensive understanding regarding the security vulnerabilities inherent in MENs. In this study, we introduce a novel approach called the sponge attack, which aims to compromise the fundamental advantages of MENs that allow easily identifiable images to leave in early exits. By employing data poisoning techniques, we frame the sponge attack as an optimization problem that empowers an attacker to select a specific trigger, such as adverse weather conditions (e.g., raining), to compel inputs to traverse the complete network layers of the MEN (e.g., in the context of traffic sign recognition) instead of early-exits when the trigger condition is met. Remarkably, our attack has the capacity to increase inference latency, while maintaining the classification accuracy even in the presence of a trigger, thus operating discreetly. Extensive experimentation on three diverse natural datasets (CIFAR100, GTSRB, and STL10), each trained with three prominent MEN architectures (VGG16, ResNet56, and MSDNet), validates the efficacy of our attack in terms of latency augmentation and its effectiveness in preserving classification accuracy under trigger conditions.
引用
收藏
页码:33843 / 33851
页数:9
相关论文
共 50 条
  • [31] Improving Low-Latency Predictions in Multi-Exit Neural Networks via Block-Dependent Losses
    Han, Dong-Jun
    Park, Jungwuk
    Ham, Seokil
    Lee, Namjin
    Moon, Jaekyun
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2024, 35 (11) : 16927 - 16935
  • [32] Multi-Targeted Poisoning Attack in Deep Neural Networks
    Kwon H.
    Cho S.
    IEICE Transactions on Information and Systems, 2022, E105D (11): : 1916 - 1920
  • [33] An optimization model of multi-exit evacuation based on point queue model
    Li, Ming-Hua
    Yuan, Zhen-Zhou
    Xu, Yan
    Zang, Guan-Zhi
    Jiaotong Yunshu Xitong Gongcheng Yu Xinxi/Journal of Transportation Systems Engineering and Information Technology, 2015, 15 (04): : 166 - 172
  • [34] An Efficient Staged Evacuation Planning Algorithm Applied to Multi-Exit Buildings
    Han, Litao
    Guo, Huan
    Zhang, Haisi
    Kong, Qiaoli
    Zhang, Aiguo
    Gong, Cheng
    ISPRS INTERNATIONAL JOURNAL OF GEO-INFORMATION, 2020, 9 (01)
  • [35] Multi-exit DNN inference acceleration for intelligent terminal with heterogeneous processors
    Zhang, Jinghui
    Xin, Weilong
    Lv, Dingyang
    Wang, Jiawei
    Cai, Guangxing
    Dong, Fang
    SUSTAINABLE COMPUTING-INFORMATICS & SYSTEMS, 2023, 40
  • [36] A Probabilistic Re-Intepretation of Confidence Scores in Multi-Exit Models
    Pomponi, Jary
    Scardapane, Simone
    Uncini, Aurelio
    ENTROPY, 2022, 24 (01)
  • [37] Selective Fine-Tuning on a Classifier Ensemble: Realizing Adaptive Neural Networks With a Diversified Multi-Exit Architecture
    Hirose, Kazutoshi
    Takamaeda-Yamazaki, Shinya
    Yu, Jaehoon
    Motomura, Masato
    IEEE ACCESS, 2021, 9 : 6179 - 6187
  • [38] Improving Low-Latency Predictions in Multi-Exit Neural Networks via Block-Dependent Losses
    Han, Dong-Jun
    Park, Jungwuk
    Ham, Seokil
    Lee, Namjin
    Moon, Jaekyun
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2023, : 1 - 9
  • [39] A reconfigurable functional unit with conditional execution for multi-exit custom instructions
    Noori, Hamid
    Mehdipour, Farhad
    Inoue, Koji
    Murakami, Kazuaki
    IEICE TRANSACTIONS ON ELECTRONICS, 2008, E91C (04) : 497 - 508
  • [40] Generating and executing multi-exit custom instructions for an adaptive extensible processor
    Noori, Hamid
    Mehdipour, Farhad
    Murakami, Kazuaki
    Inoue, Koji
    Goudarzi, Maziar
    2007 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION, VOLS 1-3, 2007, : 325 - +