Matches in SemOpenAlex for { <https://semopenalex.org/work/W4313305574> ?p ?o ?g. }
Showing items 1 to 67 of
67
with 100 items per page.
- W4313305574 abstract "Recent increases in the computational demands of deep neural networks (DNNs) have sparked interest in efficient deep learning mechanisms, e.g., quantization or pruning. These mechanisms enable the construction of a small, efficient version of commercial-scale models with comparable accuracy, accelerating their deployment to resource-constrained devices. In this paper, we study the security considerations of publishing on-device variants of large-scale models. We first show that an adversary can exploit on-device models to make attacking the large models easier. In evaluations across 19 DNNs, by exploiting the published on-device models as a transfer prior, the adversarial vulnerability of the original commercial-scale models increases by up to 100x. We then show that the vulnerability increases as the similarity between a full-scale and its efficient model increase. Based on the insights, we propose a defense, $similarity$-$unpairing$, that fine-tunes on-device models with the objective of reducing the similarity. We evaluated our defense on all the 19 DNNs and found that it reduces the transferability up to 90% and the number of queries required by a factor of 10-100x. Our results suggest that further research is needed on the security (or even privacy) threats caused by publishing those efficient siblings." @default.
- W4313305574 created "2023-01-06" @default.
- W4313305574 creator A5034257647 @default.
- W4313305574 creator A5052664531 @default.
- W4313305574 creator A5089615282 @default.
- W4313305574 date "2022-12-28" @default.
- W4313305574 modified "2023-09-23" @default.
- W4313305574 title "Publishing Efficient On-device Models Increases Adversarial Vulnerability" @default.
- W4313305574 doi "https://doi.org/10.48550/arxiv.2212.13700" @default.
- W4313305574 hasPublicationYear "2022" @default.
- W4313305574 type Work @default.
- W4313305574 citedByCount "0" @default.
- W4313305574 crossrefType "posted-content" @default.
- W4313305574 hasAuthorship W4313305574A5034257647 @default.
- W4313305574 hasAuthorship W4313305574A5052664531 @default.
- W4313305574 hasAuthorship W4313305574A5089615282 @default.
- W4313305574 hasBestOaLocation W43133055741 @default.
- W4313305574 hasConcept C103278499 @default.
- W4313305574 hasConcept C108583219 @default.
- W4313305574 hasConcept C11413529 @default.
- W4313305574 hasConcept C115961682 @default.
- W4313305574 hasConcept C119857082 @default.
- W4313305574 hasConcept C121332964 @default.
- W4313305574 hasConcept C140547941 @default.
- W4313305574 hasConcept C154945302 @default.
- W4313305574 hasConcept C165696696 @default.
- W4313305574 hasConcept C2778755073 @default.
- W4313305574 hasConcept C28855332 @default.
- W4313305574 hasConcept C2984842247 @default.
- W4313305574 hasConcept C37736160 @default.
- W4313305574 hasConcept C38652104 @default.
- W4313305574 hasConcept C41008148 @default.
- W4313305574 hasConcept C62520636 @default.
- W4313305574 hasConcept C95713431 @default.
- W4313305574 hasConceptScore W4313305574C103278499 @default.
- W4313305574 hasConceptScore W4313305574C108583219 @default.
- W4313305574 hasConceptScore W4313305574C11413529 @default.
- W4313305574 hasConceptScore W4313305574C115961682 @default.
- W4313305574 hasConceptScore W4313305574C119857082 @default.
- W4313305574 hasConceptScore W4313305574C121332964 @default.
- W4313305574 hasConceptScore W4313305574C140547941 @default.
- W4313305574 hasConceptScore W4313305574C154945302 @default.
- W4313305574 hasConceptScore W4313305574C165696696 @default.
- W4313305574 hasConceptScore W4313305574C2778755073 @default.
- W4313305574 hasConceptScore W4313305574C28855332 @default.
- W4313305574 hasConceptScore W4313305574C2984842247 @default.
- W4313305574 hasConceptScore W4313305574C37736160 @default.
- W4313305574 hasConceptScore W4313305574C38652104 @default.
- W4313305574 hasConceptScore W4313305574C41008148 @default.
- W4313305574 hasConceptScore W4313305574C62520636 @default.
- W4313305574 hasConceptScore W4313305574C95713431 @default.
- W4313305574 hasLocation W43133055741 @default.
- W4313305574 hasOpenAccess W4313305574 @default.
- W4313305574 hasPrimaryLocation W43133055741 @default.
- W4313305574 hasRelatedWork W2180612164 @default.
- W4313305574 hasRelatedWork W2610321374 @default.
- W4313305574 hasRelatedWork W2949152835 @default.
- W4313305574 hasRelatedWork W2950066684 @default.
- W4313305574 hasRelatedWork W2952919291 @default.
- W4313305574 hasRelatedWork W3034953030 @default.
- W4313305574 hasRelatedWork W3193857078 @default.
- W4313305574 hasRelatedWork W4298388782 @default.
- W4313305574 hasRelatedWork W4300837091 @default.
- W4313305574 hasRelatedWork W4312831135 @default.
- W4313305574 isParatext "false" @default.
- W4313305574 isRetracted "false" @default.
- W4313305574 workType "article" @default.