发现动态深度学习系统效率漏洞,可被恶意输入触发性能崩溃
Exploiting Efficiency Vulnerabilities in Dynamic Deep Learning Systems
- 分析动态模型运行路径,识别输入诱导的效率攻击面
- 实验证明恶意输入可使延迟和能耗飙升数倍
- 适合关注AI系统安全与鲁棒性的研究者和工程师
深度学习模型在真实场景中的广泛部署,对推理效率提出了严苛的延迟和资源约束要求。为应对这些挑战,动态深度学习系统(DDLS)应运而生,通过输入自适应计算优化运行效率。然而,其动态特性引入了细微且未充分探索的安全风险。具体而言,输入依赖的执行路径为攻击者提供了降低效率的机会,导致过度延迟、高能耗,甚至在时间敏感场景中引发拒绝服务。本文研究了DDLS中动态行为的潜在安全影响,揭示了现有系统中可被恶意输入利用的效率漏洞。通过对现有攻击策略的调研,我们识别出对新兴模型架构覆盖不足及防御机制局限性的问题。基于此,我们评估了现代DDLS中效率攻击的可行性,并提出针对性防御措施,以在对抗环境下保持系统鲁棒性。
原文摘要 · Abstract (English)
The growing deployment of deep learning models in real-world environments has intensified the need for efficient inference under strict latency and resource constraints. To meet these demands, dynamic deep learning systems (DDLSs) have emerged, offering input-adaptive computation to optimize runtime efficiency. While these systems succeed in reducing cost, their dynamic nature introduces subtle and underexplored security risks. In particular, input-dependent execution pathways create opportunities for adversaries to degrade efficiency, resulting in excessive latency, energy usage, and potential denial-of-service in time-sensitive deployments. This work investigates the security implications of dynamic behaviors in DDLSs and reveals how current systems expose efficiency vulnerabilities exploitable by adversarial inputs. Through a survey of existing attack strategies, we identify gaps in the coverage of emerging model architectures and limitations in current defense mechanisms. Building on these insights, we propose to examine the feasibility of efficiency attacks on modern DDLSs and develop targeted defenses to preserve robustness under adversarial conditions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。