Co(ve)rtex: ML Models as storage channels and their (mis-)applications

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Mamun, Md Abdullah Al, Alam, Quazi Mishkatul, Shayegani, Erfan, Zaree, Pedram, Alouani, Ihsen, Abu-Ghazaleh, Nael
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916242290376704
author Mamun, Md Abdullah Al
Alam, Quazi Mishkatul
Shayegani, Erfan
Zaree, Pedram
Alouani, Ihsen
Abu-Ghazaleh, Nael
author_facet Mamun, Md Abdullah Al
Alam, Quazi Mishkatul
Shayegani, Erfan
Zaree, Pedram
Alouani, Ihsen
Abu-Ghazaleh, Nael
contents Machine learning (ML) models are overparameterized to support generality and avoid overfitting. The state of these parameters is essentially a "don't-care" with respect to the primary model provided that this state does not interfere with the primary model. In both hardware and software systems, don't-care states and undefined behavior have been shown to be sources of significant vulnerabilities. In this paper, we propose a new information theoretic perspective of the problem; we consider the ML model as a storage channel with a capacity that increases with overparameterization. Specifically, we consider a sender that embeds arbitrary information in the model at training time, which can be extracted by a receiver with a black-box access to the deployed model. We derive an upper bound on the capacity of the channel based on the number of available unused parameters. We then explore black-box write and read primitives that allow the attacker to:(i) store data in an optimized way within the model by augmenting the training data at the transmitter side, and (ii) to read it by querying the model after it is deployed. We also consider a new version of the problem which takes information storage covertness into account. Specifically, to obtain storage covertness, we introduce a new constraint such that the data augmentation used for the write primitives minimizes the distribution shift with the initial (baseline task) distribution. This constraint introduces a level of "interference" with the initial task, thereby limiting the channel's effective capacity. Therefore, we develop optimizations to improve the capacity in this case, including a novel ML-specific substitution based error correction protocol. We believe that the proposed modeling of the problem offers new tools to better understand and mitigate potential vulnerabilities of ML, especially in the context of increasingly large models.
format Preprint
id arxiv_https___arxiv_org_abs_2307_08811
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Co(ve)rtex: ML Models as storage channels and their (mis-)applications
Mamun, Md Abdullah Al
Alam, Quazi Mishkatul
Shayegani, Erfan
Zaree, Pedram
Alouani, Ihsen
Abu-Ghazaleh, Nael
Machine Learning
Information Theory
Machine learning (ML) models are overparameterized to support generality and avoid overfitting. The state of these parameters is essentially a "don't-care" with respect to the primary model provided that this state does not interfere with the primary model. In both hardware and software systems, don't-care states and undefined behavior have been shown to be sources of significant vulnerabilities. In this paper, we propose a new information theoretic perspective of the problem; we consider the ML model as a storage channel with a capacity that increases with overparameterization. Specifically, we consider a sender that embeds arbitrary information in the model at training time, which can be extracted by a receiver with a black-box access to the deployed model. We derive an upper bound on the capacity of the channel based on the number of available unused parameters. We then explore black-box write and read primitives that allow the attacker to:(i) store data in an optimized way within the model by augmenting the training data at the transmitter side, and (ii) to read it by querying the model after it is deployed. We also consider a new version of the problem which takes information storage covertness into account. Specifically, to obtain storage covertness, we introduce a new constraint such that the data augmentation used for the write primitives minimizes the distribution shift with the initial (baseline task) distribution. This constraint introduces a level of "interference" with the initial task, thereby limiting the channel's effective capacity. Therefore, we develop optimizations to improve the capacity in this case, including a novel ML-specific substitution based error correction protocol. We believe that the proposed modeling of the problem offers new tools to better understand and mitigate potential vulnerabilities of ML, especially in the context of increasingly large models.
title Co(ve)rtex: ML Models as storage channels and their (mis-)applications
topic Machine Learning
Information Theory
url https://arxiv.org/abs/2307.08811