In plain words: Deep learning models are small, but the software that runs them is big and full of outside code packages, where the study found security holes. Attackers can exploit them to crash voice or image recognition apps, or take over the system and fool the recognition.
Abstract · Security Risks in Deep Learning Implementations
Advance in deep learning algorithms overshadows their security risk in software implementations. This paper discloses a set of vulnerabilities in popular deep learning frameworks including Caffe, TensorFlow, and Torch. Contrast to the small code size of deep learning models, these deep learning frameworks are complex and contain heavy dependencies on numerous open source packages. This paper considers the risks caused by these vulnerabilities by studying their impact on common deep learning applications such as voice recognition and image classifications. By exploiting these framework implementations, attackers can launch denial-of-service attacks that crash or hang a deep learning application, or control-flow hijacking attacks that cause either system compromise or recognition evasions. The goal of this paper is to draw attention on the software implementations and call for the community effort to improve the security of deep learning frameworks.
Qixue Xiao, Kang Li, Deyue Zhang, Weilin Xu
arXiv:1711.11008 · cs.CR · submitted Nov 29, 2017
abstract · pdf · html