Understanding Real-world Threats to Deep Learning Models in Android Apps

09/20/2022
by   Zizhuang Deng, et al.
0

Famous for its superior performance, deep learning (DL) has been popularly used within many applications, which also at the same time attracts various threats to the models. One primary threat is from adversarial attacks. Researchers have intensively studied this threat for several years and proposed dozens of approaches to create adversarial examples (AEs). But most of the approaches are only evaluated on limited models and datasets (e.g., MNIST, CIFAR-10). Thus, the effectiveness of attacking real-world DL models is not quite clear. In this paper, we perform the first systematic study of adversarial attacks on real-world DNN models and provide a real-world model dataset named RWM. Particularly, we design a suite of approaches to adapt current AE generation algorithms to the diverse real-world DL models, including automatically extracting DL models from Android apps, capturing the inputs and outputs of the DL models in apps, generating AEs and validating them by observing the apps' execution. For black-box DL models, we design a semantic-based approach to build suitable datasets and use them for training substitute models when performing transfer-based attacks. After analyzing 245 DL models collected from 62,583 real-world apps, we have a unique opportunity to understand the gap between real-world DL models and contemporary AE generation algorithms. To our surprise, the current AE generation algorithms can only directly attack 6.53 success rate upgrades to 47.35

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/06/2023

Beyond the Model: Data Pre-processing Attack to Deep Learning Models in Android Apps

The increasing popularity of deep learning (DL) models and the advantage...
research
07/27/2021

Towards Black-box Attacks on Deep Learning Apps

Deep learning is a powerful weapon to boost application performance in m...
research
01/12/2021

Robustness of on-device Models: Adversarial Attack to Deep Learning Models on Android Apps

Deep learning has shown its power in many applications, including object...
research
09/15/2020

CorDEL: A Contrastive Deep Learning Approach for Entity Linkage

Entity linkage (EL) is a critical problem in data cleaning and integrati...
research
10/14/2021

On Adversarial Vulnerability of PHM algorithms: An Initial Study

With proliferation of deep learning (DL) applications in diverse domains...
research
01/18/2021

DeepPayload: Black-box Backdoor Attack on Deep Learning Models through Neural Payload Injection

Deep learning models are increasingly used in mobile applications as cri...
research
03/02/2021

Online Adversarial Attacks

Adversarial attacks expose important vulnerabilities of deep learning mo...

Please sign up or login with your details

Forgot password? Click here to reset