Machine Learning (ML)-powered apps are used in pervasive devices such as phones, tablets, smartwatches and IoT devices. Recent advances in collaborative, distributed ML such as Federated Learning (FL) attempt to solve privacy concerns of users and data owners, and thus used by tech industry leaders such as Google, Facebook and Apple. However, FL systems and models are still vulnerable to adversarial membership and attribute inferences and model poisoning attacks, especially in FL-as-a-Service ecosystems recently proposed, which can enable attackers to access multiple ML-powered apps. In this work, we focus on the recently proposed Sponge attack: It is designed to soak up energy consumed while executing inference (not training) of ML model, without hampering the classifier's performance. Recent work has shown sponge attacks on ASCI-enabled GPUs can potentially escalate the power consumption and inference time. For the first time, in this work, we investigate this attack in the mobile setting and measure the effect it can have on ML models running inside apps on mobile devices.
翻译:机器学习(ML)驱动的应用广泛部署于手机、平板、智能手表及物联网设备等泛在终端中。联邦学习等协作式分布式ML的最新进展试图解决用户与数据所有者的隐私问题,因此被谷歌、Facebook和苹果等科技行业巨头所采用。然而,联邦学习系统与模型仍易遭受对抗性成员推理、属性推理及模型中毒攻击,尤其是在近期提出的联邦学习即服务生态系统中,攻击者可借此访问多个ML驱动的应用。本研究聚焦于近期提出的Sponge攻击:该攻击旨在吸收ML模型执行推理(而非训练)时消耗的能量,同时不影响分类器性能。最新研究表明,针对支持ASCI的GPU的Sponge攻击可能显著增加功耗与推理时间。在本工作中,我们首次针对移动端场景探究此类攻击,并评估其对移动设备应用中运行的ML模型产生的影响。