首次系统分析动态深度学习系统的效率攻击与防御难题。
Efficiency Robustness of Dynamic Deep Learning Systems
- 按动态计算、迭代次数、输出生成三类行为分类效率攻击
- 实验证明现有防御机制对新型攻击效果有限
- 为资源受限设备的自适应模型安全提供新方向
深度学习系统(DLSs)正广泛部署于移动和物联网等资源受限的实时场景。为应对效率挑战,动态深度学习系统(DDLSs)会根据输入复杂度调整推理计算量,降低开销。但这种动态行为引入了新的攻击面,尤其是效率对抗攻击可利用其动态机制降低系统性能。本文首次系统研究了DDLSs的效率鲁棒性,提出首个效率攻击综合分类体系,依据三种动态行为:(i) 针对单次推理的动态计算,(ii) 针对动态推理迭代,(iii) 针对下游任务的动态输出生成。通过深入评估,我们分析了针对DDLSs效率的对抗策略,并识别出安全防护的关键挑战。同时,我们考察了现有防御机制,发现其在面对日益流行的效率攻击时存在明显局限,亟需新型缓解策略以保障未来自适应DDLSs的安全性。
原文摘要 · Abstract (English)
Deep Learning Systems (DLSs) are increasingly deployed in real-time applications, including those in resourceconstrained environments such as mobile and IoT devices. To address efficiency challenges, Dynamic Deep Learning Systems (DDLSs) adapt inference computation based on input complexity, reducing overhead. While this dynamic behavior improves efficiency, such behavior introduces new attack surfaces. In particular, efficiency adversarial attacks exploit these dynamic mechanisms to degrade system performance. This paper systematically explores efficiency robustness of DDLSs, presenting the first comprehensive taxonomy of efficiency attacks. We categorize these attacks based on three dynamic behaviors: (i) attacks on dynamic computations per inference, (ii) attacks on dynamic inference iterations, and (iii) attacks on dynamic output production for downstream tasks. Through an in-depth evaluation, we analyze adversarial strategies that target DDLSs efficiency and identify key challenges in securing these systems. In addition, we investigate existing defense mechanisms, demonstrating their limitations against increasingly popular efficiency attacks and the necessity for novel mitigation strategies to secure future adaptive DDLSs.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。