Typhon Unleashed: Practical Adversarial Weight Attacks Against On-Device Deep Learning Models

Citations

WEB OF SCIENCE

0
Citations

SCOPUS

0

초록

On-device deep learning (DL) has emerged as a popular approach for mobile apps to deliver artificial intelligence services. Unlike traditional cloud-based approaches, it processes sensitive information locally, addressing severe concerns over sensitive data collection on cloud servers. However, this approach inevitably stores models on user devices and opens a new attack surface, i.e., adversarial weight attacks, which steer DL models to undesirable behaviors through direct model weight modification. Unfortunately, such risks stemming from on-device DL have been left unexplored. In this paper, we present the first practical adversarial weight attack against on-device DL models. To demonstrate this novel attack, we propose Typhon, an automated attack system that removes the read-only restriction of on-device DL models through the reconstruction of writable counterparts and leverages the inference-only nature of on-device DL models to solve malicious parameters and manipulate model behaviors. Extensive experimental results across diverse datasets and model architectures confirm the superiority of our attack across multiple evaluation metrics. In addition, three real-world case studies are conducted with 100% attack success rates, demonstrating the practicality of Typhon.

키워드

Computational modelingData modelsPredictive modelsMobile applicationsDeep learningCryptographyPerformance evaluationInternetCamerasMelanomaOn-device deep learningadversarial weight attackmobile application security
제목
Typhon Unleashed: Practical Adversarial Weight Attacks Against On-Device Deep Learning Models
저자
Huang, YujinYuan, XingliangChen, ChunyangHwang, Seong Oun
DOI
10.1109/TDSC.2026.3666979
발행일
2026-05
유형
Article
저널명
IEEE Transactions on Dependable and Secure Computing
23
3
페이지
6584 ~ 6601