Skip to main navigation Skip to search Skip to main content

DeMistify: Identifying On-device Machine Learning Models Stealing and Reuse Vulnerabilities in Mobile Apps

  • Pengcheng Ren
  • , Chaoshun Zuo
  • , Xiaofeng Liu
  • , Wenrui Diao
  • , Qingchuan Zhao*
  • , Shanqing Guo*
  • *Corresponding author for this work

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

Abstract

Mobile apps have become popular for providing artificial intelligence (AI) services via on-device machine learning (ML) techniques. Unlike accomplishing these AI services on remote servers traditionally, these on-device techniques process sensitive information required by AI services locally, which can mitigate the severe concerns of the sensitive data collection on the remote side. However, these on-device techniques have to push the core of ML expertise (e.g., models) to smartphones locally, which are still subject to similar vulnerabilities on the remote clouds and servers, especially when facing the model stealing attack. To defend against these attacks, developers have taken various protective measures. Unfortunately, we have found that these protections are still insufficient, and on-device ML models in mobile apps could be extracted and reused without limitation. To better demonstrate its inadequate protection and the feasibility of this attack, this paper presents DeMistify, which statically locates ML models within an app, slices relevant execution components, and finally generates scripts automatically to instrument mobile apps to successfully steal and reuse target ML models freely. To evaluate DeMistify and demonstrate its applicability, we apply it on 1,511 top mobile apps using on-device ML expertise for several ML services based on their install numbers from Google Play and DeMistify can successfully execute 1250 of them (82.73%). In addition, an in-depth study is conducted to understand the on-device ML ecosystem in the mobile application. © 2024 IEEE Computer Society. All rights reserved.
Original languageEnglish
Title of host publicationICSE '24: Proceedings of the IEEE/ACM 46th International Conference on Software Engineering
PublisherAssociation for Computing Machinery
ISBN (Electronic)9798400702174
DOIs
Publication statusPublished - Feb 2024
Event46th IEEE/ACM International Conference on Software Engineering (ICSE 2024) - Centro Cultural de Belém, Lisbon, Portugal
Duration: 14 Apr 202420 Apr 2024
https://conf.researchr.org/home/icse-2024

Publication series

NameProceedings - International Conference on Software Engineering
ISSN (Print)0270-5257

Conference

Conference46th IEEE/ACM International Conference on Software Engineering (ICSE 2024)
PlacePortugal
CityLisbon
Period14/04/2420/04/24
Internet address

Funding

We sincerely thank all anonymous reviewers for their constructive feedback. This work was partly supported by CityU APRC grant 9610563, the Research Grants Council of Hong Kong (CityU 21219223, C1029-22G), National Natural Science Foundation of China under Grant No.62372268, Shandong Provincial Natural Science Foundation (No. ZR2020MF055, No.ZR2021LZH007, No.ZR202- 2LZH013 and No.ZR2020QF045), and Jinan City “20 New Universities” Funding Project (2021GXRC084). Any opinions, findings, and conclusions in this paper are those of the authors and do not necessarily of supported organizations.

Research Keywords

  • Android App
  • Machine Learning
  • On-device Model Reuse
  • Program Analysis

RGC Funding Information

  • RGC-funded

Fingerprint

Dive into the research topics of 'DeMistify: Identifying On-device Machine Learning Models Stealing and Reuse Vulnerabilities in Mobile Apps'. Together they form a unique fingerprint.

Cite this