Matches in SemOpenAlex for { <https://semopenalex.org/work/W4378976928> ?p ?o ?g. }
Showing items 1 to 88 of
88
with 100 items per page.
- W4378976928 abstract "Recent increases in the computational demands of deep neural networks (DNNs) have sparked interest in efficient deep learning mechanisms, e.g., quantization or pruning. These mechanisms enable the construction of a small, efficient version of commercial-scale models with comparable accuracy, accelerating their deployment to resource-constrained devices. In this paper, we study the security considerations of publishing on-device variants of large-scale models. We first show that an adversary can exploit on-device models to make attacking the large models easier. In evaluations across 19 DNNs, by exploiting the published on-device models as a transfer prior, the adversarial vulnerability of the original commercial-scale models increases by up to 100x. We then show that the vulnerability increases as the similarity between a full-scale and its efficient model increase. Based on the insights, we propose a defense, similarity-unpairing, that fine-tunes on-device models with the objective of reducing the similarity. We evaluated our defense on all the 19 DNNs and found that it reduces the transferability up to 90% and the number of queries required by a factor of 10-100x. Our results suggest that further research is needed on the security (or even privacy) threats caused by publishing those efficient siblings." @default.
- W4378976928 created "2023-06-02" @default.
- W4378976928 creator A5034257647 @default.
- W4378976928 creator A5052664531 @default.
- W4378976928 creator A5089615282 @default.
- W4378976928 date "2023-02-01" @default.
- W4378976928 modified "2023-10-18" @default.
- W4378976928 title "Publishing Efficient On-device Models Increases Adversarial Vulnerability" @default.
- W4378976928 cites W2051267297 @default.
- W4378976928 cites W2108598243 @default.
- W4378976928 cites W2194775991 @default.
- W4378976928 cites W2243397390 @default.
- W4378976928 cites W2603766943 @default.
- W4378976928 cites W2745565856 @default.
- W4378976928 cites W2884150179 @default.
- W4378976928 cites W2895097814 @default.
- W4378976928 cites W2925709178 @default.
- W4378976928 cites W2962711307 @default.
- W4378976928 cites W2963446712 @default.
- W4378976928 cites W2963857521 @default.
- W4378976928 cites W2964081807 @default.
- W4378976928 cites W2985462664 @default.
- W4378976928 cites W3004127093 @default.
- W4378976928 cites W3007318395 @default.
- W4378976928 cites W3034455297 @default.
- W4378976928 cites W3035467354 @default.
- W4378976928 cites W3091857398 @default.
- W4378976928 cites W3099502074 @default.
- W4378976928 cites W3118479706 @default.
- W4378976928 cites W9657784 @default.
- W4378976928 doi "https://doi.org/10.1109/satml54575.2023.00026" @default.
- W4378976928 hasPublicationYear "2023" @default.
- W4378976928 type Work @default.
- W4378976928 citedByCount "0" @default.
- W4378976928 crossrefType "proceedings-article" @default.
- W4378976928 hasAuthorship W4378976928A5034257647 @default.
- W4378976928 hasAuthorship W4378976928A5052664531 @default.
- W4378976928 hasAuthorship W4378976928A5089615282 @default.
- W4378976928 hasConcept C103278499 @default.
- W4378976928 hasConcept C108583219 @default.
- W4378976928 hasConcept C11413529 @default.
- W4378976928 hasConcept C115961682 @default.
- W4378976928 hasConcept C119857082 @default.
- W4378976928 hasConcept C121332964 @default.
- W4378976928 hasConcept C140547941 @default.
- W4378976928 hasConcept C154945302 @default.
- W4378976928 hasConcept C165696696 @default.
- W4378976928 hasConcept C2778755073 @default.
- W4378976928 hasConcept C28855332 @default.
- W4378976928 hasConcept C2984842247 @default.
- W4378976928 hasConcept C37736160 @default.
- W4378976928 hasConcept C38652104 @default.
- W4378976928 hasConcept C41008148 @default.
- W4378976928 hasConcept C62520636 @default.
- W4378976928 hasConcept C95713431 @default.
- W4378976928 hasConceptScore W4378976928C103278499 @default.
- W4378976928 hasConceptScore W4378976928C108583219 @default.
- W4378976928 hasConceptScore W4378976928C11413529 @default.
- W4378976928 hasConceptScore W4378976928C115961682 @default.
- W4378976928 hasConceptScore W4378976928C119857082 @default.
- W4378976928 hasConceptScore W4378976928C121332964 @default.
- W4378976928 hasConceptScore W4378976928C140547941 @default.
- W4378976928 hasConceptScore W4378976928C154945302 @default.
- W4378976928 hasConceptScore W4378976928C165696696 @default.
- W4378976928 hasConceptScore W4378976928C2778755073 @default.
- W4378976928 hasConceptScore W4378976928C28855332 @default.
- W4378976928 hasConceptScore W4378976928C2984842247 @default.
- W4378976928 hasConceptScore W4378976928C37736160 @default.
- W4378976928 hasConceptScore W4378976928C38652104 @default.
- W4378976928 hasConceptScore W4378976928C41008148 @default.
- W4378976928 hasConceptScore W4378976928C62520636 @default.
- W4378976928 hasConceptScore W4378976928C95713431 @default.
- W4378976928 hasLocation W43789769281 @default.
- W4378976928 hasOpenAccess W4378976928 @default.
- W4378976928 hasPrimaryLocation W43789769281 @default.
- W4378976928 hasRelatedWork W2791691546 @default.
- W4378976928 hasRelatedWork W2950066684 @default.
- W4378976928 hasRelatedWork W2952919291 @default.
- W4378976928 hasRelatedWork W3034953030 @default.
- W4378976928 hasRelatedWork W3193857078 @default.
- W4378976928 hasRelatedWork W3208304128 @default.
- W4378976928 hasRelatedWork W4293054861 @default.
- W4378976928 hasRelatedWork W4298388782 @default.
- W4378976928 hasRelatedWork W4300837091 @default.
- W4378976928 hasRelatedWork W4312831135 @default.
- W4378976928 isParatext "false" @default.
- W4378976928 isRetracted "false" @default.
- W4378976928 workType "article" @default.