EREBA: Black-box Energy Testing of Adaptive Neural Networks
Mirazul Haque, Yaswanth Yadlapalli, Wei Yang, Cong Liu
Abstract
Recently, various Deep Neural Network (DNN) models have been proposed for environments like embedded systems with stringent energy constraints. The fundamental problem of determining the robustness of a DNN with respect to its energy consumption (energy robustness) is relatively unexplored compared to accuracy-based robustness. This work investigates the energy robustness of Adaptive Neural Networks (AdNNs), a type of energy-saving DNNs proposed for many energy-sensitive domains and have recently gained traction. We propose EREBA, the first black-box testing method for determining the energy robustness of an AdNN. EREBA explores and infers the relationship between inputs and the energy consumption of AdNNs to generate energy surging samples. Extensive implementation and evaluation using three state-of-the-art AdNNs demonstrate that test inputs generated by EREBA could degrade the performance of the system substantially. The test inputs generated by EREBA can increase the energy consumption of AdNNs by 2,000% compared to the original inputs. Our results also show that test inputs generated via EREBA are valuable in detecting energy surging inputs. CCS CONCEPTS • Security and privacy → Software and application security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 306562bc-89a2-4e20-864a-28a0d5de72c8Cited by top-tier papers3
- NICGSlowDown: Evaluating the Efficiency Robustness of Neural Image Caption Generation ModelsSimin Chen, Zihe Song, Mirazul Haque, Cong Liu et al.CVPR 2022 · 34 citations
- VLMInferSlow: Evaluating the Efficiency Robustness of Large Vision-Language Models as a ServiceXiasi Wang, Tianliang Yao, Simin Chen, Runqi Wang et al.ACL 2025 · 3 citations
- SoK: Efficiency Robustness of Dynamic Deep Learning SystemsRavishka Rathnasuriya, Tingxi Li, Zexin Xu, Zihe Song et al.USENIX Security 2025
Builds on5
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- A Panda? No, It's a Sloth: Slowdown Attacks on Adaptive Multi-Exit Neural Network InferenceSanghyun Hong, Yigitcan Kaya, Ionut-Vlad Modoranu, Tudor DumitrasICLR 2021 · 85 citations
- Resolution Adaptive Networks for Efficient InferenceLe Yang, Yizeng Han, Xi Chen, Shiji Song et al.CVPR 2020
- ILFO: Adversarial Attack on Adaptive Neural NetworksMirazul Haque, Anki Chauhan, Cong Liu, Wei YangCVPR 2020
- Self-Training With Noisy Student Improves ImageNet ClassificationQizhe Xie, Minh-Thang Luong, Eduard H. Hovy, Quoc V. LeCVPR 2020
Related papers
- DeepPerform: An Efficient Approach for Performance Testing of Resource-Constrained Neural NetworksSimin Chen, Mirazul Haque, Cong Liu, Wei YangASE 2022 · 19 citations
- BET: black-box efficient testing for convolutional neural networksJialai Wang, Han Qiu, Yi Rong, Hengkai Ye et al.ISSTA 2022 · 18 citations
- DeepRover: A Query-Efficient Blackbox Attack for Deep Neural NetworksFuyuan Zhang, Xinwen Hu, Lei Ma, Jianjun ZhaoFSE 2023 · 7 citations
- Efficiency attacks on spiking neural networksSarada Krithivasan, Sanchari Sen, Nitin Rathi, Kaushik Roy et al.DAC 2022 · 10 citations
- EOS: An Energy-Oriented Attack Framework for Spiking Neural NetworksNing Yang, Fangxin Liu, Zongwu Wang, Haomin Li et al.DAC 2024 · 1 citation
