用密码学后门让神经网络既能攻防,还能防拷贝。
Cryptographic Backdoor for Neural Networks: Boon and Bane
- 用密码学后门植入隐蔽攻击,可绕过常规检测
- 实现可证明鲁棒的水印、认证与版权追踪协议
- 支持后量子加密,为未来安全应用奠基
本文展示神经网络中的密码学后门在攻防两端均具高效性。攻击方面,精心植入的后门可发动强大且隐蔽的攻击;防御方面,提出三种应用:一是可证明鲁棒的神经网络水印方案;二是用户身份认证协议;三是未经授权共享的神经网络知识产权追踪协议。从理论看,借鉴Goldwasser等人[FOCS 2022]思想,所有协议在黑盒攻击者下均具备可证明鲁棒性。尽管攻击机制沿用已有理论,防御部分的证明仍需深入研究。所有协议均在主流神经网络架构上实现,实验证实理论结论。此外,可使用后量子密码原语构建后门,为机器学习的量子时代应用奠定基础。
原文摘要 · Abstract (English)
In this paper we show that cryptographic backdoors in a neural network (NN) can be highly effective in two directions, namely mounting the attacks as well as in presenting the defenses as well. On the attack side, a carefully planted cryptographic backdoor enables powerful and invisible attack on the NN. Considering the defense, we present applications: first, a provably robust NN watermarking scheme; second, a protocol for guaranteeing user authentication; and third, a protocol for tracking unauthorized sharing of the NN intellectual property (IP). From a broader theoretical perspective, borrowing the ideas from Goldwasser et. al. [FOCS 2022], our main contribution is to show that all these instantiated practical protocol implementations are provably robust. The protocols for watermarking, authentication and IP tracking resist an adversary with black-box access to the NN, whereas the backdoor-enabled adversarial attack is impossible to prevent under the standard assumptions. While the theoretical tools used for our attack is mostly in line with the Goldwasser et. al. ideas, the proofs related to the defense need further studies. Finally, all these protocols are implemented on state-of-the-art NN architectures with empirical results corroborating the theoretical claims. Further, one can utilize post-quantum primitives for implementing the cryptographic backdoors, laying out foundations for quantum-era applications in machine learning (ML).
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。