
모바일 온디바이스 AI 시스템을 위한 공격 및 방어 연구의 엄선된 읽기 목록 및 분류 체계로, 적대적 공격, 백도어 공격, 모델 도난 공격, 에너지-지연 공격을 비롯해 난독화, TEE, 워터마킹 방어를 다룹니다.
모바일 온디바이스 AI 시스템은 LiteRT/TFLite, Core ML, ExecuTorch, ONNX와 같은 ML 프레임워크와 하드웨어 기반 가속기를 통해 AI 모델을 로컬에서 실행합니다. 이 저장소는 온디바이스 모델의 로컬 저장이 새로운 보안 위험을 도입함에 따라, 이러한 시스템을 이해하고 보호하는 데 필요한 보안 연구를 추적합니다.
MoAI 보안이 처음이신가요? 여기서 시작하세요:
• A First Look at Deep Learning Apps on Smartphones
• A First Look at On-device Models in iOS Apps
• Mind Your Weight(s): A Large-scale Study on Insufficient ML Model Protection in Mobile Apps
• Robustness of On-device Models: Adversarial Attack to Deep Learning Models on Android Apps
• DeepPayload: Black-box Backdoor Attack on Deep Learning Models through Neural Payload Injection
• Typhon Unleashed: Practical Adversarial Weight Attacks Against On-Device Deep Learning Models
• Energy-Latency Attacks to On-Device Neural Networks via Sponge Poisoning
• ModelObfuscator: Obfuscating Model Information to Protect Deployed ML-based Systems
• ShadowNet: A Secure and Efficient On-device Model Inference System
• THEMIS: Towards Practical IP Protection for Post-Deployment On-Device DL Models
| MoAI 보안 기둥 | 보호 대상 | 대표적 공격 | 대표적 방어 |
|---|---|---|---|
| 사용자 관리 입력 무결성 | 모바일 데이터 수집부터 모델 입력 전달까지 사용자 입력의 종단 간 무결성 | 적대적 공격, 백도어 공격, 에너지-지연 공격 | - |
| 기기 상주 모델 보안 | 배포된 모델 아티팩트와 기기에서 모델이 저장, 로드, 변환, 구체화되는 모든 배포 후 형태 | 적대적 공격, 백도어 공격, 적대적 가중치 공격, 모델 탈취 공격, 에너지-지연 공격 | 모델 난독화, 모델 인가, TEE, 모델 워터마킹 |
| 기기 네이티브 환경 격리 | 모바일 OS, AI 런타임, 메모리 하위 시스템, 하드웨어 기반 실행 환경 전반의 민감한 추론 계산 및 런타임 상태 | 모델 탈취 공격, 에너지-지연 공격 | 모델 난독화, TEE |
Robustness of On-device Models: Adversarial Attack to Deep Learning Models on Android Apps [Code]
IEEE/ACM International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP 2021)
Smart App Attack: Hacking Deep Learning Models in Android Apps [Code]
IEEE Transactions on Information Forensics and Security (TIFS 2022)
Understanding Real-world Threats to Deep Learning Models in Android Apps [Code]
ACM SIGSAC Conference on Computer and Communications Security (CCS 2022)
Cheating Your Apps: Black-box Adversarial Attacks on Deep Learning Apps
Journal of Software: Evolution and Process (JSEP 2024)
A First Look at On-device Models in iOS Apps [Code]
ACM Transactions on Software Engineering and Methodology (TOSEM 2024)