A First Look at On-device Models in iOS Apps

Author:

Hu Han1ORCID,Huang Yujin1ORCID,Chen Qiuyuan2ORCID,Zhuo Terry Yue1ORCID,Chen Chunyang1ORCID

Affiliation:

1. Monash University, Australia

2. Tencent, China

Abstract

Powered by the rising popularity of deep learning techniques on smartphones, on-device deep learning models are being used in vital fields such as finance, social media, and driving assistance. Because of the transparency of the Android platform and the on-device models inside, on-device models on Android smartphones have been proven to be extremely vulnerable. However, due to the challenge in accessing and analyzing iOS app files, despite iOS being a mobile platform as popular as Android, there are no relevant works on on-device models in iOS apps. Since the functionalities of the same app on Android and iOS platforms are similar, the same vulnerabilities may exist on both platforms. In this article, we present the first empirical study about on-device models in iOS apps, including their adoption of deep learning frameworks, structure, functionality, and potential security issues. We study why current developers use different on-device models for one app between iOS and Android. We propose a more general attack against white-box models that does not rely on pre-trained models and a new adversarial attack approach based on our findings to target iOS’s gray-box on-device models. Our results show the effectiveness of our approaches. Finally, we successfully exploit the vulnerabilities of on-device models to attack real-world iOS apps.

Publisher

Association for Computing Machinery (ACM)

Subject

Software

Reference104 articles.

1. OpenCV Team. 2023. Open Source Computer Vision Library. Retrieved from https://opencv.org/

2. Google Brain Team. 2023. TensorFlow. Retrieved from https://www.tensorflow.org/

3. J. Brownlee. 2023. Activation Function. Retrieved from https://machinelearningmastery.com/choose-an-activation-function-for-deep-learning/

4. Wikipedia contributors. 2023. Android Operation System. Retrieved from https://en.wikipedia.org/wiki/Android_(operating_system)

5. Wikipedia contributors. 2023. Apple. Retrieved from https://en.wikipedia.org/wiki/Apple_Inc

Cited by 3 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Towards Protecting On-Device Machine Learning with RISC-V based Multi-Enclave TEE;2024 33rd International Conference on Computer Communications and Networks (ICCCN);2024-07-29

2. Enhancing GUI Exploration Coverage of Android Apps with Deep Link-Integrated Monkey;ACM Transactions on Software Engineering and Methodology;2024-06-27

3. Integrated Attendance System using NFC Technology;2023 5th International Conference on Cybernetics and Intelligent System (ICORIS);2023-10-06

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3