arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

深度学习延迟攻击与防御:可用性威胁的跨领域综述

Deep Learning Latency Attacks and Defenses: A Cross-Domain Survey of Availability Threats

Zonghua Gu, Zeyu Gao, Amin Saremi, Samarjit Chakraborty

arXiv 2609.36732首次发表:更新:

发表机构

Hofstra University; Umeå University; University of North Carolina at Chapel Hill(霍夫斯特拉大学; 于默奥大学; 北卡罗来纳大学教堂山分校)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本综述统一跨领域延迟攻击,按计算瓶颈分类,提出工作预算防御抽象,并分析系统级可用性故障条件,提供威胁模型分类和开放挑战。

AI 中文摘要

对抗性机器学习主要关注完整性,但可用性是一个日益重要的补充。延迟攻击(也称为能量-延迟攻击)增加推理时间的工作量、能量或响应时间,导致车辆控制器、交互式服务或电池供电传感器中的截止时间错过、吞吐量崩溃或资源耗尽,有时同时保持名义预测。本综述统一了分散的文献,涵盖感知流水线(包括对自动驾驶检测和跟踪的物理攻击)、输入自适应神经推理(海绵样本、动态网络)以及自回归和智能体系统(对LLM、VLM、混合专家模型和工具使用智能体的输出长度、冗长图像和推理拒绝服务攻击)。我们按利用的计算瓶颈而非公式化来组织攻击,区分什么使计算昂贵与攻击者如何触发它;传递渠道(输入、提示或检索内容、消息、投毒或权重篡改)是一个正交属性。许多攻击共享一种机制,即中间工作放大,激励工作预算防御抽象;我们区分进入昂贵阶段的工作上限与离开它的结果上限。我们进一步分析模型级成本增加何时成为系统级可用性故障,这取决于关键路径份额、松弛、现有上限、累积、资源共享和回退策略,而非仅放大因子。我们还提供威胁模型分类、整合的定量比较、按控制机制的防御审查以及开放挑战,如标准化评估、物理可实现性和全系统可用性。配套网站:此https URL。

英文摘要

Adversarial machine learning has focused mainly on integrity, but availability is an increasingly consequential complement. Latency attacks (also energy-latency attacks) increase inference-time work, energy, or response time, causing deadline misses, throughput collapse, or resource exhaustion in vehicle controllers, interactive services, or battery-powered sensors, sometimes while preserving the nominal prediction. This survey unifies a fragmented literature spanning perception pipelines (including physical attacks on autonomous-driving detection and tracking), input-adaptive neural inference (sponge examples, dynamic networks), and autoregressive and agentic systems (output-length, verbose-image, and reasoning denial-of-service attacks on LLMs, VLMs, mixture-of-experts models, and tool-using agents). We organize attacks by exploited computational bottleneck rather than formulation, separating what makes a computation expensive from how the attacker triggers it; the delivery channel (input, prompt or retrieved content, message, poisoning, or weight tampering) is an orthogonal attribute. Many attacks share one mechanism, intermediate-work amplification, motivating a work-budget defense abstraction; we distinguish caps on the work entering an expensive stage from caps on the results leaving it. We further analyze when a model-level cost increase becomes a system-level availability failure, which depends on critical-path share, slack, existing ceilings, accumulation, resource sharing, and fallback policy, not on the amplification factor alone. We also provide a threat-model taxonomy, consolidated quantitative comparisons, a defense review by control mechanism, and open challenges such as standardized evaluation, physical realizability, and whole-system availability. Companion website: https://github.com/guzonghua/awesome-latency-attacks.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑