arXiv:2411.10500cs.CRcs.AI2024-11被引 3

攻击者仅知边缘模型就能让云端分类出错,突破了传统攻击必须全模型知识的限制。

Edge-Only Universal Adversarial Attacks in Distributed Learning

  • 只利用边缘部分模型生成通用扰动,操控中间特征影响云端判断。
  • 在ImageNet上实现强迁移性,对未知云端组件有效误导分类结果。
  • 首次揭示边缘仅知条件下攻击可行,适合研究分布式系统安全的学者。

分布式学习框架将神经网络模型分置于多个计算节点,提升边缘-云协同系统的效率,但也可能引入逃避攻击的新漏洞,通常表现为对抗扰动。本文提出一种新威胁模型,探索当攻击者仅能访问模型边缘部分(即初始网络层)时,生成通用对抗扰动(UAPs)的可行性。与传统需完整模型知识的攻击不同,本方法表明攻击者可通过操纵边缘的关键特征表示,有效诱导未知云端组件产生错误预测。基于该威胁模型,我们提出仅依赖边缘的无目标和有目标两种UAP形式,旨在控制分割点前的中间特征。ImageNet实验表明,所提方法在未知云端部分具有强大的攻击迁移能力,并与经典白盒及黑盒攻击方法对比,凸显其有效性。此外,我们分析了攻击者在仅有边缘知识下实现有目标对抗效应的能力,揭示了多网络中的有趣行为。本工作首次在分割推理中引入仅边缘知识的对抗攻击,强调了在对抗鲁棒性研究中考虑部分模型访问的重要性,推动该方向的进一步探索。

原文摘要 · Abstract (English)

Distributed learning frameworks, which partition neural network models across multiple computing nodes, enhance efficiency in collaborative edge-cloud systems, but may also introduce new vulnerabilities to evasion attacks, often in the form of adversarial perturbations. In this work, we present a new threat model that explores the feasibility of generating universal adversarial perturbations (UAPs) when the attacker has access only to the edge portion of the model, consisting of its initial network layers. Unlike traditional attacks that require full model knowledge, our approach shows that adversaries can induce effective mispredictions in the unknown cloud component by manipulating key feature representations at the edge. Following the proposed threat model, we introduce both edge-only untargeted and targeted formulations of UAPs designed to control intermediate features before the split point. Our results on ImageNet demonstrate strong attack transferability to the unknown cloud part, and we compare the proposed method with classical white-box and black-box techniques, highlighting its effectiveness. Additionally, we analyze the capability of an attacker to achieve targeted adversarial effects with edge-only knowledge, revealing intriguing behaviors across multiple networks. By introducing the first adversarial attacks with edge-only knowledge in split inference, this work underscores the importance of addressing partial model access in adversarial robustness, encouraging further research in this area.

对抗攻击分布式学习边缘计算通用扰动

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。