Deep learning models are widely used in security-sensitive tasks such as facial recognition and autonomous driving. Security issues in deep models could have serious implications for people’s lives, such as life-threatening situations resulting from autonomous driving failures. To enhance the security of deep models, security testing is necessary before their formal deployment. Since different scenarios may involve different deep models, a security testing method that targets multiple scenarios would be more universally applicable. In this paper, we propose a security testing method for deep models that can be applied across multiple scenarios, primarily utilizing adversarial attacks to test the models. For the deep model under test, we first construct threat scenarios and then associate the model with datasets and adversarial attack methods. Subsequently, we generate adversarial examples to input into the deep model to check its accuracy in classification. Finally, we evaluate the success rate of adversarial attacks on the deep model. A high attack success rate indicates low model security, necessitating developers to employ adversarial training or other methods to enhance model security.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Security Testing for Deep Learning Models in Multiple Scenarios

  • Zhendong Wu,
  • Hu Li,
  • Ming Zhang,
  • Shuaibing Lu

摘要

Deep learning models are widely used in security-sensitive tasks such as facial recognition and autonomous driving. Security issues in deep models could have serious implications for people’s lives, such as life-threatening situations resulting from autonomous driving failures. To enhance the security of deep models, security testing is necessary before their formal deployment. Since different scenarios may involve different deep models, a security testing method that targets multiple scenarios would be more universally applicable. In this paper, we propose a security testing method for deep models that can be applied across multiple scenarios, primarily utilizing adversarial attacks to test the models. For the deep model under test, we first construct threat scenarios and then associate the model with datasets and adversarial attack methods. Subsequently, we generate adversarial examples to input into the deep model to check its accuracy in classification. Finally, we evaluate the success rate of adversarial attacks on the deep model. A high attack success rate indicates low model security, necessitating developers to employ adversarial training or other methods to enhance model security.