arrow
Return

Quantization Backdoors to Deep Learning Commercial Frameworks

delete2024-05-01
delete7
delete
OA
AI
H
Hua Ma
H
Huming Qiu
高艳松 (Yansong Gao) *
Z
Zhi Zhang
A
Alsharif Abuadbba
M
Minhui Xue
A
Anmin Fu
J
Jiliang Zhang
S
Said F. Al-Sarawi
D
Derek Abbott
DOI:10.1109/TDSC.2023.3271956delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
This work reveals that standard quantization toolkits can be abused to activate a backdoor. We demonstrate that a full-precision backdoored model which does not have any backdoor effect in the presence of a trigger-as the backdoor is dormant-can be activated by (i) TensorFlow-Lite (TFLite) quantization, the only product-ready quantization framework to date, and (ii) the beta released PyTorch Mobile framework. In our experiments, we employ three popular model architectures (VGG16, ResNet18, and ResNet50), and train each across three popular datasets: MNIST, CIFAR10 and GTSRB. We ascertain that all trained float-32 backdoored models exhibit no backdoor effect even in the presence of trigger inputs. Particularly, four influential backdoor defenses are evaluated, and they fail to identify a backdoor in the float-32 models. When each of the float-32 models is converted into an int-8 format model through the standard TFLite or PyTorch Mobile framework's post-training quantization, the backdoor is activated in the quantized model, which shows a stable attack success rate close to 100% upon inputs with the trigger, while it usually behaves upon non-trigger inputs. This work highlights that a stealthy security threat occurs when an end-user utilizes the on-device post-training model quantization frameworks, informing security researchers of a cross-platform overhaul of DL models post-quantization even if these models pass security-aware front-end backdoor inspections. Significantly, we have identified Gaussian noise injection into the malicious full-precision model as an easy-to-use preventative defense against the PQ backdoor.
Keywords:
Deep learning
PyTorch mobile
quantization backdoor attack
TensorFlow- lite

Journal

IEEE Transactions on Dependable and Secure Computing cover
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
Papers:
2.4K
Citations:
9.6K

Organization

U
University of Western Australia
Scholars:
2.9W
Papers: 3.0W
Citations: 46
U
University of Adelaide
Scholars:
2.3W
Papers: 2.4W
Citations: 4.2W
H
hunan university
Scholars:
4.4W
Papers: 3.3W
Citations: 70
researcher View more organizations