揭示深度学习能效优化中的新型攻击威胁,可引发系统拒绝服务。
Energy-Latency Attacks: A New Adversarial Threat to Deep Learning
- 基于传统对抗攻击分类法,系统梳理能效延迟攻击类型
- 发现攻击可使模型延迟和能耗飙升至最坏情况水平
- 适合关注AI安全与可持续部署的研究者阅读
深度神经网络(DNN)日益增长的计算需求引发了对其能耗和碳足迹的担忧,尤其在模型规模与复杂度持续上升的背景下。为应对挑战,能效硬件与专用加速器成为关键,自适应DNN也被开发以动态平衡性能与效率。然而,这些以效率为导向的设计可能引入新漏洞:攻击者可通过触发最坏性能场景,恶意增加延迟与能耗。此类新型攻击被称为能效-延迟攻击,近期受到广泛关注,其可导致拒绝服务(DoS)攻击。本文对当前能效延迟攻击研究进行全面综述,采用传统对抗攻击的分类体系进行归类,探讨衡量攻击成功率的不同指标,分析并比较现有攻击策略。同时,评估现有防御机制,指出当前挑战及未来研究方向。相关代码与资料可在GitHub获取:https://github.com/hbrachemi/Survey_energy_attacks/
原文摘要 · Abstract (English)
The growing computational demand for deep neural networks ( DNNs) has raised concerns about their energy consumption and carbon footprint, particularly as the size and complexity of the models continue to increase. To address these challenges, energy-efficient hardware and custom accelerators have become essential. Additionally, adaptable DNN s are being developed to dynamically balance performance and efficiency. The use of these strategies became more common to enable sustainable AI deployment. However, these efficiency-focused designs may also introduce vulnerabilities, as attackers can potentially exploit them to increase latency and energy usage by triggering their worst-case-performance scenarios. This new type of attack, called energy-latency attacks, has recently gained significant research attention, focusing on the vulnerability of DNN s to this emerging attack paradigm, which can trigger denial-of-service ( DoS) attacks. This paper provides a comprehensive overview of current research on energy-latency attacks, categorizing them using the established taxonomy for traditional adversarial attacks. We explore different metrics used to measure the success of these attacks and provide an analysis and comparison of existing attack strategies. We also analyze existing defense mechanisms and highlight current challenges and potential areas for future research in this developing field. The GitHub page for this work can be accessed at https://github.com/hbrachemi/Survey_energy_attacks/
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。