Hardening Deep Neural Network Binaries against Reverse Engineering Attacks
Zheng Zhong, Ruoyu Wu, Junpeng Wan, Muqi Zou, Dave (Jing) Tian
Abstract
Deep Neural Networks (DNNs) are proprietary assets due to the expertise, confidential data, and high development costs involved in model training. Well-trained DNN models are compiled into DNN binaries to be efficiently executed on various platforms, such as edge devices and cloud infrastructures. Recent research on DNN binary decompilation shows the potential of stealing DNN models via binary reverse engineering techniques. While obfuscation is a well-studied technique to hamper binary reverse engineering, general obfuscation schemes are not designed for this new type of binary and have limitations in concealing information within DNN binaries due to the unique characteristics of DNN binaries.
In this paper, we show that existing reverse engineering attacks on DNN binaries can recover 98.5% of DNN operators from DNN binaries that have been obfuscated using general obfuscators. We then propose new obfuscation schemes tailored for DNN binaries, namely, (1) Flexible Operator Fusion; (2) Fake Operator Insertion; and (3) Operator Computation Reordering. We implement our dedicated obfuscation schemes as an end-to-end obfuscation toolchain called NeuroShield. Experiments show that NeuroShield is resilient to existing model reverse engineering attacks while introducing a reasonable overhead. Specifically, NeuroShield reduces the operator recovery rate to 3.03% for CV models and 47.18% for NLP models. Moreover, it has comparable binary size overhead and significantly lower execution time overhead (7.8% -36.1%) compared to OLLVM, one of the commonly used general obfuscators.
• Security and privacy → Software reverse engineering.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4a33a5a8-767e-4b71-aba5-4c7b6b083ee7Builds on21
- ALBERT: A Lite BERT for Self-supervised Learning of Language RepresentationsZhenzhong Lan, Mingda Chen, Sebastian Goodman, Kevin Gimpel et al.ICLR 2020 · 7,418 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter et al.USENIX Security 2016 · 2,088 citations
- Efficient large-scale language model training on GPU clusters using megatron-LMDeepak Narayanan, Mohammad Shoeybi, Jared Casper, Patrick LeGresley et al.SC 2021 · 576 citations
- Mind Your Weight(s): A Large-scale Study on Insufficient Machine Learning Model Protection in Mobile AppsZhichuang Sun, Ruimin Sun, Long Lu, Alan MisloveUSENIX Security 2021 · 101 citations
Related papers
- NeuroScope: Reverse Engineering Deep Neural Network on Edge Devices using Dynamic AnalysisRuoyu Wu, Muqi Zou, Arslan Khan, Taegyu Kim et al.USENIX Security 2025
- GroupCover: A Secure, Efficient and Scalable Inference Framework for On-device Model Protection based on TEEsZheng Zhang, Na Wang, Ziqi Zhang, Yao Zhang et al.ICML 2024 · 13 citations
- DnD: A Cross-Architecture Deep Neural Network DecompilerRuoyu Wu, Taegyu Kim, Dave (Jing) Tian, Antonio Bianchi et al.USENIX Security 2022
- DynaMO: Protecting Mobile DL Models through Coupling Obfuscated DL OperatorsMingyi Zhou, Xiang Gao, Xiao Chen, Chunyang Chen et al.ASE 2024 · 1 citation
- Decompiling x86 Deep Neural Network ExecutablesZhibo Liu, Yuanyuan Yuan, Shuai Wang, Xiaofei Xie et al.USENIX Security 2023
