arrow
Return

Disarming Attacks Inside Neural Network Models

delete2023-01-01
delete2
delete
OA
AI
R
Ran Dubin *
DOI:10.1109/ACCESS.2023.3330141delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Similar to the revolution of open source code sharing, Artificial Intelligence (AI) model sharing is gaining increased popularity. However, the fast adaptation in the industry, lack of awareness, and ability to exploit the models make them significant attack vectors. By embedding malware in neurons, the malware can be delivered covertly, with minor or no impact on the neural network's performance. The covert attack will use the Least Significant Bits (LSB) weight attack since LSB has a minimal effect on the model accuracy, and as a result, the user will not notice it. Since there are endless ways to hide the attacks, we focus on a zero-trust prevention strategy based on AI model attack disarm and reconstruction. We proposed three types of model steganography weight disarm defense mechanisms. The first two are based on random bit substitution noise, and the other on model weight quantization. We demonstrate a 100% prevention rate while the methods introduce a minimal decrease in model accuracy based on Qint8 and K-LRBP methods, which is an essential factor for improving AI security.
Keywords:
Malware
Steganography
Load modeling
Artificial intelligence
Artificial neural networks
Codes
Quantization (signal)
Zero Trust
Microsoft OLE
attack prevention
CDR
malware
sensitization
threat disarm
zero-trust

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.8W
Citations:
29.4W

Organization

A
Ariel University
Scholars:
3.9K
Papers: 3.3K
Citations: 2.4K
Cited Papers

Cited Papers

errShare
errSave
Pliocene–Pleistocene orographic control on denudation in northwest Argentina
err2019-02-26
err0
PREAI
errHeiko Pingel; Taylor Schildgen; Manfred R. Strecker; Hella Wittmann
errShare
errSave
errShare
errSave
Structural study of lanthanides(III) in aqueous nitrate and chloride solutions by EXAFS
err1999-02-01
err0
PREAI
errT. Yaita; H. Narita; Sh. Suzuki; Sh. Tachimori; H. Motohashi; H. Shiwaku
errShare
errSave
EvilModel 2.0: Bringing Neural Network Models into Malware Attacks
err2022-09-01
err6
errOAAI
errWang, Zhi; Liu, Chaoge; Cui, Xiang; Yin, Jie; Wang, Xutong
errShare
errSave
The infinite race between steganography and steganalysis in images
err2022-12-01
err24
PREAI
errMuralidharan, Trivikram; Cohen, Aviad; Cohen, Assaf; Nissim, Nir
errShare
errSave
Interstitial pulmonary inflammation due to Microbacterium sp. after heart transplantation
err2006-03-01
err0
errOAAI
errGiovanni M. Giammanco; Sarina Pignato; Patrick A. D. Grimont; Francine Grimont; Carmelita Santangelo; Giuseppe Leonardi; Angelo Giuffrida; Vivian Legname; Giuseppe Giammanco
errShare
errSave
researcher View more