The increasing popularity of deep learning (DL) models and the advantages of computing, including low latency and bandwidth savings on smartphones, have led to the emergence of intelligent mobile applications, also known as DL apps, in recent years. However, this technological development has also given rise to several security concerns, including adversarial examples, model stealing, and data poisoning issues. Existing works on attacks and countermeasures for on-device DL models have primarily focused on the models themselves. However, scant attention has been paid to the impact of data processing disturbance on the model inference. This knowledge disparity highlights the need for additional research to fully comprehend and address security issues related to data processing for on-device models. In this paper, we introduce a data processing-based attacks against real-world DL apps. In particular, our attack could influence the performance and latency of the model without affecting the operation of a DL app. To demonstrate the effectiveness of our attack, we carry out an empirical study on 517 real-world DL apps collected from Google Play. Among 320 apps utilizing MLkit, we find that 81.56\% of them can be successfully attacked. The results emphasize the importance of DL app developers being aware of and taking actions to secure on-device models from the perspective of data processing.
翻译:随着深度学习模型的日益普及以及计算优势(包括智能手机上的低延迟和带宽节省)的出现,近年来催生了智能移动应用,即所谓的深度学习应用。然而,这一技术发展也引发了若干安全问题,包括对抗样本、模型窃取和数据中毒问题。现有关于设备端深度学习模型的攻击与防御研究工作主要集中在模型本身。然而,数据处理扰动对模型推理的影响却鲜有关注。这一知识差距凸显了需要进一步研究以全面理解并解决设备端模型在数据处理方面的安全问题。在本文中,我们提出了一种针对真实世界深度学习应用的数据处理攻击。特别地,我们的攻击能够在不影响深度学习应用运行的情况下影响模型的性能和延迟。为了证明我们攻击的有效性,我们对从Google Play收集的517个真实世界深度学习应用进行了实证研究。在使用MLkit的320个应用中,我们发现其中81.56%可以被成功攻击。研究结果强调了深度学习应用开发者从数据处理角度意识到并采取行动保护设备端模型的重要性。