SearcharxivSearch

arXiv subjects

Tiago Alves

Publications and source records attributed to Tiago Alves.

4 recordsLinked to original sources

InferNet: Exploiting Aggregate GPU Profiles as Side-Channel for DNN Architecture Inference

Deep Neural Networks (DNNs) have become ubiquitous for their ability to solve problems across various domains, including computer vision, natural language processing, and speech recognition. However, as their adoption grows, they face a range of security threats, such as model stealing, architecture extraction, and manipulation, which can compromise their integrity, privacy, and functionality. Past works have relied on complex, fine-grained, and time-series analysis to launch DNN model extraction attacks. These approaches require extensive amounts of data, which are often challenging to acquire and analyze effectively. This paper introduces InferNet, an attack method that leverages simple, non-intrusive, and coarse-grained system-level information to identify the underlying DNN architecture of a victim's application. By analyzing GPU kernel calls, memory events, and system-level metrics, InferNet fingerprints the DNN and infers its architecture with very high accuracy. It can predict the architecture family (e.g., Inception vs. BERT), as well as the architecture variant (e.g., InceptionV1 vs. InceptionV3). The evaluation results demonstrate the effectiveness of InferNet across AI/ML frameworks (TensorFlow, PyTorch), different DNN types (vision, LLMs), and hardware platforms (NVIDIA Tesla T4, NVIDIA Quadro RTX 8000). The results show that InferNet achieves 100% model extraction accuracy using only a partial GPU profile under various attack settings.

cs.LG

Hardening DNNs against Transfer Attacks during Network Compression using Greedy Adversarial Pruning

The prevalence and success of Deep Neural Network (DNN) applications in recent years have motivated research on DNN compression, such as pruning and quantization. These techniques accelerate model inference, reduce power consumption, and reduce the size and complexity of the hardware necessary to run DNNs, all with little to no loss in accuracy. However, since DNNs are vulnerable to adversarial inputs, it is important to consider the relationship between compression and adversarial robustness. In this work, we investigate the adversarial robustness of models produced by several irregular pruning schemes and by 8-bit quantization. Additionally, while conventional pruning removes the least important parameters in a DNN, we investigate the effect of an unconventional pruning method: removing the most important model parameters based on the gradient on adversarial inputs. We call this method Greedy Adversarial Pruning (GAP) and we find that this pruning method results in models that are resistant to transfer attacks from their uncompressed counterparts.

cs.LG

Dynamic Prediction of ICU Mortality Risk Using Domain Adaptation

Early recognition of risky trajectories during an Intensive Care Unit (ICU) stay is one of the key steps towards improving patient survival. Learning trajectories from physiological signals continuously measured during an ICU stay requires learning time-series features that are robust and discriminative across diverse patient populations. Patients within different ICU populations (referred here as domains) vary by age, conditions and interventions. Thus, mortality prediction models using patient data from a particular ICU population may perform suboptimally in other populations because the features used to train such models have different distributions across the groups. In this paper, we explore domain adaptation strategies in order to learn mortality prediction models that extract and transfer complex temporal features from multivariate time-series ICU data. Features are extracted in a way that the state of the patient in a certain time depends on the previous state. This enables dynamic predictions and creates a mortality risk space that describes the risk of a patient at a particular time. Experiments based on cross-ICU populations reveals that our model outperforms all considered baselines. Gains in terms of AUC range from 4% to 8% for early predictions when compared with a recent state-of-the-art representative for ICU mortality prediction. In particular, models for the Cardiac ICU population achieve AUC numbers as high as 0.88, showing excellent clinical utility for early mortality prediction. Finally, we present an explanation of factors contributing to the possible ICU outcomes, so that our models can be used to complement clinical reasoning.

cs.LG

Discovery prospects of dwarf spheroidal galaxies for indirect dark matter searches

We study the prospects for the Large Synoptic Survey Telescope (LSST) to find new dwarf spheroidal galaxies in the Milky Way. Adopting models of Milky-Way halo substructure and phenomenological prescriptions connecting subhalos and satellite galaxies, we obtain surface brightness distributions of $V$-band magnitude that lead us to predict that LSST will discover tens to hundreds of dwarf spheroidal galaxies above its sensitivity. The soon-to-be-discovered dwarfs will be interesting targets for indirect searches of dark matter annihilation yields. We forecast the distribution function of gamma-ray emission from dark matter annihilation in these objects, and discuss the detectability of these signals at both Fermi Large Area Telescope (LAT) and Cherenkov Telescope Array (CTA). By combining information from the predicted dwarf galaxies, we obtain an expected sensitivity to the annihilation cross section $\langle σv \rangle$ of $10^{-26}$ cm$^3$ s$^{-1}$ (for dark matter particles of mass 10 GeV with Fermi-LAT) and $5\times 10^{-24}$ cm$^3$ s$^{-1}$ (for dark matter particles of mass 500 GeV with CTA). We find that the current uncertainties in the mass measurement of the Milky-Way halo are relatively minor compared with the Poisson errors associated to drawing the most promising dwarfs from the underlying flux distribution.

astro-ph.CO