arXiv · 2309.16577
Compilation as a Defense: Enhancing DL Model Attack Robustness via Tensor Optimization
Abstract
Adversarial Machine Learning (AML) is a rapidly growing field of security research, with an often overlooked area being model attacks through side-channels. Previous works show such attacks to be serious threats, though little progress has been made on efficient remediation strategies that avoid costly model re-engineering. This work demonstrates a new defense against AML side-channel attacks using model compilation techniques, namely tensor optimization. We show relative model attack effectiveness decreases of up to 43% using tensor optimization, discuss the implications, and direction of future work.
Explore related subjects
Keep this discovery
Stefan Trawicki, William Hackett, Lewis Birch, Neeraj Suri, Peter Garraghan. 2023-09-20. Compilation as a Defense: Enhancing DL Model Attack Robustness via Tensor Optimization. https://arxiv.org/abs/2309.16577
Cite the original work for its findings. Save a collection to share your selection of sources.