返回
Disarming Attacks Inside Neural Network Models
DOI:10.1109/ACCESS.2023.3330141.png)
摘要
En 中文
Similar to the revolution of open source code sharing, Artificial Intelligence (AI) model sharing is gaining increased popularity. However, the fast adaptation in the industry, lack of awareness, and ability to exploit the models make them significant attack vectors. By embedding malware in neurons, the malware can be delivered covertly, with minor or no impact on the neural network's performance. The covert attack will use the Least Significant Bits (LSB) weight attack since LSB has a minimal effect on the model accuracy, and as a result, the user will not notice it. Since there are endless ways to hide the attacks, we focus on a zero-trust prevention strategy based on AI model attack disarm and reconstruction. We proposed three types of model steganography weight disarm defense mechanisms. The first two are based on random bit substitution noise, and the other on model weight quantization. We demonstrate a 100% prevention rate while the methods introduce a minimal decrease in model accuracy based on Qint8 and K-LRBP methods, which is an essential factor for improving AI security.
Keyword:
Malware
Steganography
Load modeling
Artificial intelligence
Artificial neural networks
Codes
Quantization (signal)
Zero Trust
Microsoft OLE
attack prevention
CDR
malware
sensitization
threat disarm
zero-trust
期刊
IF:
3.6
论文数:
9.8W
被引数:
29.4W
机构
引用论文
Susceptibility of clinical isolates of Candida spp. to terconazole and other azole antifungal agents
Structural study of lanthanides(III) in aqueous nitrate and chloride solutions by EXAFS通过EXAFS对硝酸盐和氯化物水溶液中镧系元素 (III) 的结构研究
EvilModel 2.0: Bringing Neural Network Models into Malware AttacksEvilModel 2.0: 将神经网络模型引入恶意软件攻击
COMPUTERS & SECURITY
IF5.4
The infinite race between steganography and steganalysis in images图像中隐写术和隐写分析之间的无限竞争
SIGNAL PROCESSING
IF3.6

