arrow
Return

Toward a Generalized Defense Across Sparse, Continuous, and Structured Parameter Attacks

delete2026-07-16
delete0
PRE
AI
B
Bin Duan
Z
Zeyu Bai
G
Guowei Yang
DOI:10.1109/tdsc.2026.3713473delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Deep neural networks are increasingly deployed across heterogeneous and partially untrusted environments, where models are distributed through cloud storage, CI/CD pipelines, containerized services, and edge execution platforms. This broad deployment landscape exposes model parameters to various integrity risks. Unlike input-space adversarial attacks, parameter attacks directly tamper with the model’s internal parameters and persist across all subsequent inferences. Existing defenses either require retraining, incur significant accuracy degradation, or are limited to specific attack classes. However, in real-world deployment scenarios, the forms of parameter attacks are often unpredictable. To address this challenge, we present ParDef, a generalized defense for deep neural networks against diverse types of parameter attacks. ParDef integrates keyed channel reparameterization, which obscures sensitive parameter directions, QC-LDPC quantization, which embeds redundancy and supports error correction, and adaptive robust inference, which stabilizes predictions under uncertainty. Our evaluation on CIFAR-10, CIFAR-100, and Tiny-ImageNet using ResNet and VGG models, together with additional DeiT experiments on ImageNet-1 K and CIFAR-100, demonstrates that ParDef consistently reduces attack success rates across different parameter attacks while maintaining high model performance and incurring only moderate deployment overhead. These results highlight that ParDef is a practical and generalized defense for securing at-rest model parameters in DNN deployments.
Keywords:
Deep neural networks
parameter attacks
model robustness
neural network security

Journal

IEEE Transactions on Dependable and Secure Computing cover
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
Papers:
2.5K
Citations:
9.6K

Organization

T
the university of queensland
Scholars:
3.1K
Papers: 1.2K
Citations: 0
Cited Papers

Cited Papers

No cited papers available