DynaMO: Protecting Mobile DL Models through Coupling Obfuscated DL Operators
Mingyi Zhou, Xiang Gao, Xiao Chen, Chunyang Chen, John Grundy, Li Li
Abstract
Deploying deep learning (DL) models on mobile applications (Apps) has become ever-more popular. However, existing studies show attackers can easily reverse-engineer mobile DL models in Apps to steal intellectual property or generate effective attacks. A recent approach, Model Obfuscation, has been proposed to defend against such reverse engineering by obfuscating DL model representations, such as weights and computational graphs, without affecting model performance. These existing model obfuscation methods use static methods to obfuscate the model representation, or they use half-dynamic methods but require users to restore the model information through additional input arguments. However, these static methods or half-dynamic methods cannot provide enough protection for on-device DL models. Attackers can use dynamic analysis to mine the sensitive information in the inference codes as the correct model information and intermediate results must be recovered at runtime for static and half-dynamic obfuscation methods. We assess the vulnerability of the existing obfuscation strategies using an instrumentation method and tool, DLModelExplorer, that dynamically extracts correct sensitive model information (i.e., weights, computational graph) at runtime. Experiments show it achieves very high attack performance (e.g., 98.76% of weights extraction rate and 99.89% of obfuscating operator classification rate). To defend against such attacks based on dynamic instrumentation, we propose DynaMO, a Dynamic Model Obfuscation strategy similar to Homomorphic Encryption. The obfuscation and recovery process can be done through simple linear transformation for the weights of randomly coupled eligible operators, which is a fully dynamic obfuscation strategy. Experiments show that our proposed strategy can dramatically improve model security compared with the existing obfuscation strategies, with only negligible overheads for on-device models. Our prototype tool is publicly available at https://github.com/zhoumingyi/DynaMO.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5261da59-235e-4375-8465-5b79623d10c7Cited by top-tier papers1
Ask how each one uses itBuilds on7
- DeepPayload: Black-box Backdoor Attack on Deep Learning Models through Neural Payload InjectionYuanchun Li, Jiayi Hua, Haoyu Wang, Chunyang Chen et al.ICSE 2021 · 70 citations
- Investigating Top-k White-Box and Transferable Black-box AttackChaoning Zhang, Philipp Benz, Adil Karjauv, Jae-Won Cho et al.CVPR 2022 · 34 citations
- ModelObfuscator: Obfuscating Model Information to Protect Deployed ML-Based SystemsMingyi Zhou, Xiang Gao, Jing Wu, John C. Grundy et al.ISSTA 2023 · 11 citations
- DEMISTIFY: Identifying On-device Machine Learning Models Stealing and Reuse Vulnerabilities in Mobile AppsPengcheng Ren, Chaoshun Zuo, Xiaofeng Liu, Wenrui Diao et al.ICSE 2024 · 10 citations
- Investigating White-Box Attacks for On-Device ModelsMingyi Zhou, Xiang Gao, Jing Wu, Kui Liu et al.ICSE 2024 · 9 citations
Related papers
- Model-less Is the Best Model: Generating Pure Code Implementations to Replace On-Device DL ModelsMingyi Zhou, Xiang Gao, Pei Liu, John Grundy et al.ISSTA 2024 · 4 citations
- Mind Your Weight(s): A Large-scale Study on Insufficient Machine Learning Model Protection in Mobile AppsZhichuang Sun, Ruimin Sun, Long Lu, Alan MisloveUSENIX Security 2021 · 101 citations
- Hardening Deep Neural Network Binaries against Reverse Engineering AttacksZheng Zhong, Ruoyu Wu, Junpeng Wan, Muqi Zou et al.CCS 2025
- GroupCover: A Secure, Efficient and Scalable Inference Framework for On-device Model Protection based on TEEsZheng Zhang, Na Wang, Ziqi Zhang, Yao Zhang et al.ICML 2024 · 13 citations
- NeuroScope: Reverse Engineering Deep Neural Network on Edge Devices using Dynamic AnalysisRuoyu Wu, Muqi Zou, Arslan Khan, Taegyu Kim et al.USENIX Security 2025
