Securing neural networks (NNs) against model extraction and parameter exfiltration attacks is an important problem primarily because modern NNs take a lot of time and resources to build and train. We observe that there are no countermeasures (CMs) against recently proposed attacks on sparse NNs and there is no single CM that effectively protects against all types of known attacks for both sparse as well as dense NNs. In this paper, we propose SparseLock, a comprehensive CM that protects against all types of attacks including some of the very recently proposed ones for which no CM exists as of today. We rely on a novel compression algorithm and binning strategy. Our security guarantees are based on the inherent hardness of bin packing and inverse bin packing problems. We also perform a battery of statistical and information theory based tests to successfully show that we leak very little information and side channels in our architecture are akin to random sources. In addition, we show a performance benefit of 47.13% over the nearest competing secure architecture.
翻译:保护神经网络模型免遭模型提取和参数泄露攻击是一个重要问题,主要因为现代神经网络的构建和训练需要大量时间和资源。我们观察到,目前尚无针对近期提出的稀疏神经网络攻击的有效防御措施,也没有一种单一的防御方法能同时有效保护稀疏和密集神经网络免受所有已知攻击。本文提出SparseLock,一种全面的防御机制,可抵御包括部分最新提出的尚无防御措施的攻击在内的所有攻击类型。我们依赖于一种新颖的压缩算法和分箱策略。我们的安全保证基于装箱问题和逆装箱问题的固有难度。我们还进行了一系列基于统计和信息理论的测试,成功证明我们泄露的信息极少,且架构中的侧信道类似于随机源。此外,相比最接近的竞争性安全架构,我们展示了47.13%的性能提升。