USENIX Security2022Top-tier venue
On the Security Risks of AutoML
Ren Pang, Zhaohan Xi, Shouling Ji, Xiapu Luo, Ting Wang
Abstract
Neural Architecture Search (NAS) represents an emerging machine learning (ML) paradigm that automatically searches for models tailored to given tasks, which greatly simplifies the development of ML systems and propels the trend of ML democratization. Yet, little is known about the potential security risks incurred by NAS, which is concerning given the increasing use of NAS-generated models in critical domains. This work represents a solid initial step towards bridging the gap. Through an extensive empirical study of 10 popular NAS methods, we show that compared with their manually designed counterparts, NAS-generated models tend to suffer greater vulnerability to various malicious attacks (e.g., adversarial evasion, model poisoning, and functionality stealing). Further, with both empirical and analytical evidence, we provide possible explanations for such phenomena: given the prohibitive search space and training cost, most NAS methods favor models that converge fast at early training stages; this preference results in architectural properties associated with attack vulnerability (e.g., high loss smoothness and low gradient variance). Our findings not only reveal the relationships between model characteristics and attack vulnerability but also suggest the inherent connections underlying different attacks. Finally, we discuss potential remedies to mitigate such drawbacks, including increasing cell depth and suppressing skip connects, which lead to several promising research directions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7b738f30-6123-48ef-beb5-74e5e8a36945Cited by top-tier papers8
- AutoML in The Wild: Obstacles, Workarounds, and ExpectationsYuan Sun, Qiurong Song, Xinning Gui, Fenglong Ma et al.CHI 2023 · 28 citations
- Transfer Attacks Revisited: A Large-Scale Empirical Study in Real Computer Vision SettingsYuhao Mao, Chong Fu, Saizhuo Wang, Shouling Ji et al.S&P 2022 · 23 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- "Is your explanation stable?": A Robustness Evaluation Framework for Feature AttributionYuyou Gan, Yuhao Mao, Xuhong Zhang, Shouling Ji et al.CCS 2022 · 13 citations
- On the Privacy Risks of Cell-Based NAS ArchitecturesHai Huang, Zhikun Zhang, Yun Shen, Michael Backes et al.CCS 2022 · 6 citations
Builds on22
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter et al.USENIX Security 2016 · 2,088 citations
- Trojaning Attack on Neural NetworksYingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee et al.NDSS 2018 · 1,377 citations
- MagNet: A Two-Pronged Defense against Adversarial ExamplesDongyu Meng, Hao ChenCCS 2017 · 1,295 citations
Related papers
- The Dark Side of AutoML: Towards Architectural Backdoor SearchRen Pang, Changjiang Li, Zhaohan Xi, Shouling Ji et al.ICLR 2023
- Adversarially Robust Neural Architecture Search for Graph Neural NetworksBeini Xie, Heng Chang, Ziwei Zhang, Xin Wang et al.CVPR 2023
- TRNAS: A Training-Free Robust Neural Architecture SearchYeming Yang, Qingling Zhu, Jianping Luo, Ka-Chun Wong et al.ICCV 2025 · 1 citation
- Towards Accurate and Robust Architectures via Neural Architecture SearchYuwei Ou, Yuqi Feng, Yanan SunCVPR 2024 · 8 citations
- NASGuard: A Novel Accelerator Architecture for Robust Neural Architecture Search (NAS) NetworksXingbin Wang, Boyan Zhao, Rui Hou, Amro Awad et al.ISCA 2021 · 9 citations
