Dynamic slicing for deep neural networks
Ziqi Zhang, Yuanchun Li, Yao Guo, Xiangqun Chen, Yunxin Liu
Abstract
Program slicing has been widely applied in a variety of software engineering tasks. However, existing program slicing techniques only deal with traditional programs that are constructed with instructions and variables, rather than neural networks that are composed of neurons and synapses. In this paper, we introduce NNSlicer, the first approach for slicing deep neural networks based on data-flow analysis. Our method understands the reaction of each neuron to an input based on the difference between its behavior activated by the input and the average behavior over the whole dataset. Then we quantify the neuron contributions to the slicing criterion by recursively backtracking from the output neurons, and calculate the slice as the neurons and the synapses with larger contributions. We demonstrate the usefulness and effectiveness of NNSlicer with three applications, including adversarial input detection, model pruning, and selective model protection. In all applications, NNSlicer significantly outperforms other baselines that do not rely on data flow analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5c5a607b-7390-41ae-ac86-6dff1891441dCited by top-tier papers16
- PMC: A Privacy-preserving Deep Learning Model Customization Framework for Edge ComputingBingyan Liu, Yuanchun Li, Yunxin Liu, Yao Guo et al.UbiComp 2021 · 96 citations
- DeepPayload: Black-box Backdoor Attack on Deep Learning Models through Neural Payload InjectionYuanchun Li, Jiayi Hua, Haoyu Wang, Chunyang Chen et al.ICSE 2021 · 70 citations
- TransTailor: Pruning the Pre-trained Model for Improved Transfer LearningBingyan Liu, Yifeng Cai, Yao Guo, Xiangqun ChenAAAI 2021 · 69 citations
- No Privacy Left Outside: On the (In-)Security of TEE-Shielded DNN Partition for On-Device MLZiqi Zhang, Chen Gong, Yifeng Cai, Yuanyuan Yuan et al.S&P 2024 · 53 citations
- ModelDiff: testing-based DNN similarity comparison for model reuse detectionYuanchun Li, Ziqi Zhang, Bingyan Liu, Ziyue Yang et al.ISSTA 2021 · 44 citations
Builds on10
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- AI2: Safety and Robustness Certification of Neural Networks with Abstract InterpretationTimon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov et al.S&P 2018 · 987 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- Formal Security Analysis of Neural Networks using Symbolic IntervalsShiqi Wang, Kexin Pei, Justin Whitehouse, Junfeng Yang et al.USENIX Security 2018 · 523 citations
- NIC: Detecting Adversarial Samples with Neural Network Invariant CheckingShiqing Ma, Yingqi Liu, Guanhong Tao, Wen-Chuan Lee et al.NDSS 2019 · 283 citations
Related papers
- Few-shot Backdoor Defense Using Shapley EstimationJiyang Guan, Zhuozhuo Tu, Ran He, Dacheng TaoCVPR 2022 · 36 citations
- DeepArc: Modularizing Neural Networks for the Model MaintenanceXiaoning Ren, Yun Lin, Yinxing Xue, Ruofan Liu et al.ICSE 2023 · 6 citations
- Reversible Watermarking in Deep Convolutional Neural Networks for Integrity AuthenticationXiquan Guan, Huamin Feng, Weiming Zhang, Hang Zhou et al.ACM MM 2020 · 46 citations
- Topological Detection of Trojaned Neural NetworksSongzhu Zheng, Yikai Zhang, Hubert Wagner, Mayank Goswami et al.NeurIPS 2021 · 52 citations
- Dynamic Network Pruning with Interpretable Layerwise Channel SelectionYulong Wang, Xiaolu Zhang, Xiaolin Hu, Bo Zhang et al.AAAI 2020 · 44 citations
