Safety and Performance, Why not Both? Bi-Objective Optimized Model Compression toward AI Software Deployment
Jie Zhu, Leye Wang, Xiao Han
Abstract
The size of deep learning models in artificial intelligence (AI) software is increasing rapidly, which hinders the large-scale deployment on resource-restricted devices (e.g., smartphones). To mitigate this issue, AI software compression plays a crucial role, which aims to compress model size while keeping high performance. However, the intrinsic defects in the big model may be inherited by the compressed one. Such defects may be easily leveraged by attackers, since the compressed models are usually deployed in a large number of devices without adequate protection. In this paper, we try to address the safe model compression problem from a safety-performance co-optimization perspective. Specifically, inspired by the test-driven development (TDD) paradigm in software engineering, we propose a test-driven sparse training framework called SafeCompress. By simulating the attack mechanism as the safety test, SafeCompress can automatically compress a big model to a small one following the dynamic sparse training paradigm. Further, considering a representative attack, i.e., membership inference attack (MIA), we develop a concrete safe model compression mechanism, called MIA-SafeCompress. Extensive experiments are conducted to evaluate MIA-SafeCompress on five datasets for both computer vision and natural language processing tasks. The results verify the effectiveness and generalization of our method. We also discuss how to adapt SafeCompress to other attacks besides MIA, demonstrating the flexibility of SafeCompress. CCS CONCEPTS • Security and privacy → Software security engineering; • Computing methodologies → Artificial intelligence.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8ebdc900-32ce-4ada-aed1-befe0ca38453Cited by top-tier papers5
- MoLE: Enhancing Human-centric Text-to-image Diffusion via Mixture of Low-rank ExpertsJie Zhu, Yixiong Chen, Mingyu Ding, Ping Luo et al.NeurIPS 2024 · 17 citations
- Efficient Decentralized Federated Singular Vector DecompositionDi Chai, Junxue Zhang, Liu Yang, Yilun Jin et al.USENIX ATC 2024 · 9 citations
- FedSlice: Protecting Federated Learning Models from Malicious Participants with Model SlicingZiqi Zhang, Yuanchun Li, Bingyan Liu, Yifeng Cai et al.ICSE 2023 · 8 citations
- A Unified Membership Inference Method for Visual Self-supervised Encoder via Part-aware CapabilityJie Zhu, Jirong Zha, Ding Li, Leye WangCCS 2024 · 4 citations
- Efficient DNN-Powered Software with Fair Sparse ModelsXuanqi Gao, Weipeng Jiang, Juan Zhai, Shiqing Ma et al.ISSTA 2024
Builds on20
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu et al.ICCV 2021 · 31,683 citations
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 1,778 citations
Related papers
- CompLeak: Deep Learning Model Compression Exacerbates Privacy LeakageNa Li, Yansong Gao, Hongsheng Hu, Boyu Kuang et al.USENIX Security 2026
- TDDBench: A Benchmark for Training data detectionZhihao Zhu, Yi Yang, Defu LianICLR 2025
- TeDA: A Testing Framework for Data Usage Auditing in Deep Learning Model DevelopmentXiangshan Gao, Jialuo Chen, Jingyi Wang, Jie Shi et al.ISSTA 2024
- Unveiling Structural Memorization: Structural Membership Inference Attack for Text-to-Image Diffusion ModelsQiao Li, Xiaomeng Fu, Xi Wang, Jin Liu et al.ACM MM 2024 · 6 citations
- Defending Against Membership Inference Attacks on Iteratively Pruned Deep Neural NetworksJing Shang, Jian Wang, Kailun Wang, Jiqiang Liu et al.NDSS 2025
