English

EI-MTD:Moving Target Defense for Edge Intelligence against Adversarial Attacks

Cryptography and Security 2020-11-26 v3 Artificial Intelligence Computer Vision and Pattern Recognition Machine Learning Machine Learning

Abstract

With the boom of edge intelligence, its vulnerability to adversarial attacks becomes an urgent problem. The so-called adversarial example can fool a deep learning model on the edge node to misclassify. Due to the property of transferability, the adversary can easily make a black-box attack using a local substitute model. Nevertheless, the limitation of resource of edge nodes cannot afford a complicated defense mechanism as doing on the cloud data center. To overcome the challenge, we propose a dynamic defense mechanism, namely EI-MTD. It first obtains robust member models with small size through differential knowledge distillation from a complicated teacher model on the cloud data center. Then, a dynamic scheduling policy based on a Bayesian Stackelberg game is applied to the choice of a target model for service. This dynamic defense can prohibit the adversary from selecting an optimal substitute model for black-box attacks. Our experimental result shows that this dynamic scheduling can effectively protect edge intelligence against adversarial attacks under the black-box setting.

Keywords

Cite

@article{arxiv.2009.10537,
  title  = {EI-MTD:Moving Target Defense for Edge Intelligence against Adversarial Attacks},
  author = {Yaguan Qian and Qiqi Shao and Jiamin Wang and Xiang Lin and Yankai Guo and Zhaoquan Gu and Bin Wang and Chunming Wu},
  journal= {arXiv preprint arXiv:2009.10537},
  year   = {2020}
}
R2 v1 2026-06-23T18:43:09.930Z