Papers
Topics
Authors
Recent
Search
2000 character limit reached

Disarming Steganography Attacks Inside Neural Network Models

Published 6 Sep 2023 in cs.CR and cs.MM | (2309.03071v2)

Abstract: Similar to the revolution of open source code sharing, AI model sharing is gaining increased popularity. However, the fast adaptation in the industry, lack of awareness, and ability to exploit the models make them significant attack vectors. By embedding malware in neurons, the malware can be delivered covertly, with minor or no impact on the neural network's performance. The covert attack will use the Least Significant Bits (LSB) weight attack since LSB has a minimal effect on the model accuracy, and as a result, the user will not notice it. Since there are endless ways to hide the attacks, we focus on a zero-trust prevention strategy based on AI model attack disarm and reconstruction. We proposed three types of model steganography weight disarm defense mechanisms. The first two are based on random bit substitution noise, and the other on model weight quantization. We demonstrate a 100\% prevention rate while the methods introduce a minimal decrease in model accuracy based on Qint8 and K-LRBP methods, which is an essential factor for improving AI security.

Authors (1)
Definition Search Book Streamline Icon: https://streamlinehq.com
References (46)
  1. Blackberry, “Threat thursday: Malicious macros still causing chaos,” 2022, accessed: 2022-01-15. [Online]. Available: https://blogs.blackberry.com/en/2022/03/threat-thursday-malicious-macros
  2. A. Grafi, “Why file-borne malware has become the weapon of choice for attackers,2022,” url=https://www.scmagazine.com/perspective/malware/why-file-borne-malware-has-become-the-weapon-of-choice-for-attackers.
  3. Av-comparatives, “Malware Protection Test March 2021 Date,” 2021, accessed: 2022-02-19. [Online]. Available: https://www.av-comparatives.org/tests/malware-protection-test-march-2021/
  4. G. Karantzas and C. Patsakis, “An empirical assessment of endpoint detection and response systems against advanced persistent threats attack vectors,” Journal of Cybersecurity and Privacy, vol. 1, no. 3, pp. 387–421, 2021.
  5. D. Goodin, “Organizations are spending billions on malware defense that’s easy to bypass,” 2021, accessed: 2022-12-19. [Online]. Available: https://arstechnica.com/information-technology/2022/08/newfangled-edr-malware-detection-generates-billions-but-is-easy-to-bypass/
  6. B. Toulas, “Open-source repositories flooded by 144,000 phishing packages ,” 2022, accessed: 2022-12-19. [Online]. Available: https://www.bleepingcomputer.com/news/security/open-source-repositories-flooded-by-144-000-phishing-packages/
  7. Z. Wang, C. Liu, and X. Cui, “Evilmodel: hiding malware inside of neural network models,” in 2021 IEEE Symposium on Computers and Communications (ISCC).   IEEE, 2021, pp. 1–7.
  8. Z. Wang, C. Liu, X. Cui, J. Yin, and X. Wang, “Evilmodel 2.0: bringing neural network models into malware attacks,” Computers & Security, vol. 120, p. 102807, 2022.
  9. E. Sultanik, “Never a dill moment: Exploiting machine learning pickle files,” 2022, accessed: 2022-12-19. [Online]. Available: https://blog.trailofbits.com/2021/03/15/never-a-dill-moment-exploiting-machine-learning-pickle-files/
  10. HuggingFace, “Fickling pickle scanning,” 2022, accessed: 2022-12-19. [Online]. Available: https://huggingface.co/
  11. PyTorch, “Pytorch model sharing hub,” 2022, accessed: 2022-01-15. [Online]. Available: https://pytorch.org/hub/
  12. TensorFlow, “TensorFlow Hub,” 2022, accessed: 2022-12-19. [Online]. Available: https://www.tensorflow.org/hub
  13. ClamAV, “ClamAV® open-source antivirus engine for detecting trojans, viruses, malware & other malicious threats.” 2022, accessed: 2022-12-19. [Online]. Available: https://www.clamav.net/
  14. E. Sultanik, “Fickling pickle scanning,” 2021, accessed: 2022-12-19. [Online]. Available: https://github.com/trailofbits/fickling
  15. T. Liu, Z. Liu, Q. Liu, W. Wen, W. Xu, and M. Li, “Stegonet: Turn deep neural network into a stegomalware,” in Annual Computer Security Applications Conference, 2020, pp. 928–938.
  16. L. Abrams, “GIFShell attack creates reverse shell using Microsoft Teams GIFs ,” 2022, accessed: 2022-12-19. [Online]. Available: https://www.bleepingcomputer.com/news/security/gifshell-attack-creates-reverse-shell-using-microsoft-teams-gifs/
  17. B. N, “Stegomalware Surge – Attackers Using File, Video, Image & Others To Hide Malware,” 2022, accessed: 2022-12-19. [Online]. Available: https://gbhackers.com/stegomalware-surge-attackers-using-file-video-image-others-to-hide-malware/amp/
  18. NSA, “Inspection and sanitization guidance for rich text format (rtf),” 2017, accessed: 2022-01-15. [Online]. Available: https://www.iad.gov/iad/library/reports/rtf_inspection_and_sanitization_guidance_v1_0.cfm
  19. R. Dubin, “Content disarm and reconstruction of rtf files a zero file trust methodology,” IEEE Transactions on Information Forensics and Security, 2023.
  20. N. Zmora, H. Wu, and J. Rodge, “Achieving fp32 accuracy for int8 inference using quantization aware training with nvidia tensorrt,” 2023, accessed: 2023-01-15. [Online]. Available: https://developer.nvidia.com/blog/achieving-fp32-accuracy-for-int8-inference-using-quantization-awaretraining-with-tensorrt/
  21. R. Dubin, “Disarming attacks inside neural network models code repository,” 2022, accessed: 2023-07-15. [Online]. Available: https://github.com/ArielCyber/AI-MODEL-CDR
  22. ——, “Content disarm and reconstruction of pdf files,” IEEE Access, vol. 11, pp. 38 399–38 416, 2023.
  23. E. Sultanik, “Fickling is a decompiler, static analyzer, and bytecode rewriter for python pickle object serializations,” 2021, accessed: 2022-01-15. [Online]. Available: https://github.com/trailofbits/fickling
  24. I. Alodat and M. Alodat, “Detection of image malware steganography using deep transfer learning model,” in Proceedings of International Conference on Data Science and Applications.   Springer, 2022, pp. 323–333.
  25. G. Sim, “Defending against the malware flood,” Network Security, vol. 2018, no. 5, pp. 12–13, 2018.
  26. Y. Sunshine, “The rise of msp & csp vulnerabilities: storehouses for secure data,” Computer Fraud & Security, vol. 2021, no. 2, pp. 15–19, 2021.
  27. J. Han, Y. Yoon, G. Hur, J. Lee, J. Choi, S. Hong, and S. Lee, “Secure file transfer method and forensic readiness by converting file format in network segmentation environment,” Journal of The Korea Institute of Information Security & Cryptology, vol. 29, no. 4, pp. 859–866, 2019.
  28. S. Adhatarao and C. Lauradoux, “Exploitation and sanitization of hidden data in pdf files,” arXiv preprint arXiv:2103.02707, 2021.
  29. T. Aura, T. Kuhn, and M. Roe, “Scanning electronic documents for personally identifiable information,” in Workshop on Privacy in electronic society, 2006, pp. 41–50.
  30. Y. Feng, B. Liu, X. Cui, C. Liu, X. Kang, and J. Su, “A systematic method on pdf privacy leakage issues,” in International Conference on Big Data Science and Engineering.   IEEE, 2018, pp. 1020–1029.
  31. S. L. Garfinkel, “Leaking sensitive information in complex document files–and how to prevent it,” SP, vol. 12, no. 1, pp. 20–27, 2013.
  32. D. Sánchez, M. Batet, and A. Viejo, “Automatic general-purpose sanitization of textual documents,” TIFS, vol. 8, no. 6, pp. 853–862, 2013.
  33. E. Belkind, R. Dubin, and A. Dvir, “Open image content disarm and reconstruction,” arXiv preprint arXiv:2307.14057, 2023.
  34. NSA, “Redaction of pdf files using adobe acrobat professional x,” 2015, accessed: 2022-01-15. [Online]. Available: https://www.cs.columbia.edu/~smb/doc/Redaction-of-PDF-Files-Using-Adobe-Acrobat-Professional-X.pdf
  35. E. Wickens, M. Janus, and T. Bonner, “Weaponizing maching learning models with ransomware,” 2022, accessed: 2022-01-15. [Online]. Available: https://hiddenlayer.com/research/weaponizing-machine-learning-models-with-ransomware/
  36. I. M. S. Committee, “Ieee 754-2019 - ieee standard for floating-point arithmetic,” 2019, accessed: 2022-01-15. [Online]. Available: https://standards.ieee.org/ieee/754/6210/
  37. G. Stoll, “Float to hex conversion online tool,” 2022, accessed: 2022-01-15. [Online]. Available: https://gregstoll.com/~gregstoll/floattohex/
  38. K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in Proceedings of the IEEE conference on computer vision and pattern recognition, 2016, pp. 770–778.
  39. K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” CoRR, vol. abs/1512.03385, 2015. [Online]. Available: http://arxiv.org/abs/1512.03385
  40. K. Simonyan and A. Zisserman, “Very deep convolutional networks for large-scale image recognition,” arXiv preprint arXiv:1409.1556, 2014.
  41. C. Szegedy, W. Liu, Y. Jia, P. Sermanet, S. Reed, D. Anguelov, D. Erhan, V. Vanhoucke, and A. Rabinovich, “Going deeper with convolutions,” in Proceedings of the IEEE conference on computer vision and pattern recognition, 2015, pp. 1–9.
  42. A. G. Howard, M. Zhu, B. Chen, D. Kalenichenko, W. Wang, T. Weyand, M. Andreetto, and H. Adam, “Mobilenets: Efficient convolutional neural networks for mobile vision applications,” arXiv preprint arXiv:1704.04861, 2017.
  43. PyTorch, “Quantization,” 2023, accessed: 2022-01-15. [Online]. Available: https://pytorch.org/docs/stable/quantization.html
  44. Q. Zhang, X. Li, X. Che, X. Ma, A. Zhou, M. Xu, S. Wang, Y. Ma, and X. Liu, “A comprehensive benchmark of deep learning libraries on mobile devices,” in Proceedings of the ACM Web Conference 2022, 2022, pp. 3298–3307.
  45. A. Gholami, S. Kim, Z. Dong, Z. Yao, M. W. Mahoney, and K. Keutzer, “A survey of quantization methods for efficient neural network inference,” arXiv preprint arXiv:2103.13630, 2021.
  46. T. Muralidharan, A. Cohen, A. Cohen, and N. Nissim, “The infinite race between steganography and steganalysis in images,” Signal Processing, p. 108711, 2022.
Citations (4)

Summary

No one has generated a summary of this paper yet.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.

Continue Learning

We haven't generated follow-up questions for this paper yet.