Compilation as a Defense: Enhancing DL Model Attack Robustness via Tensor Optimization
Adversarial Machine Learning (AML) is a rapidly growing field of security research, with an often overlooked area being model attacks through side-channels. Previous works show such attacks to be serious threats, though little progress has been made on efficient remediation strategies that avoid costly model re-engineering. This work demonstrates a new defense against AML side-channel attacks using model compilation techniques, namely tensor optimization. We show relative model attack effectiveness decreases of up to 43% using tensor optimization, discuss the implications, and direction of future work.
Code (0)
등록된 구현이 없습니다.
Similar Papers 제목 키워드 기반
Robust Vision-Language Models via Tensor Decomposition: A Defense Against Adversarial Attacks
Vision language models (VLMs) excel in multimodal understanding but are prone to adversarial attacks. Existing defenses often demand costly retraining or significant architecture changes. We introduce a lightweight defen…
Towards Robust Policy: Enhancing Offline Reinforcement Learning with Adversarial Attacks and Defenses
Offline reinforcement learning (RL) addresses the challenge of expensive and high-risk data exploration inherent in RL by pre-training policies on vast amounts of offline data, enabling direct deployment or fine-tuning i…
D4RLOffline RLReinforcement Learning (RL)Raccoon: Prompt Extraction Benchmark of LLM-Integrated Applications
With the proliferation of LLM-integrated applications such as GPT-s, millions are deployed, offering valuable services through proprietary instruction prompts. These systems, however, are prone to prompt extraction attac…
Robust Adversarial Defense by Tensor Factorization
As machine learning techniques become increasingly prevalent in data analysis, the threat of adversarial attacks has surged, necessitating robust defense mechanisms. Among these defenses, methods exploiting low-rank appr…
Adversarial DefenseRethinking the Adversarial Robustness of Multi-Exit Neural Networks in an Attack-Defense Game
Multi-exit neural networks represent a promising approach to enhancing model inference efficiency, yet like common neural networks, they suffer from significantly reduced robustness against adversarial attacks. While…
Adversarial Robustness