Zurück zu den Ergebnissen
Bibliografischer Datensatz · Ansicht und Zugriff
Artículo

SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference

Yuling Cai et al · SpringerOpen · 2026

Open Access verfügbar
Schnellübersicht. Prüfen Sie die grundlegenden Angaben und öffnen Sie den Inhalt über die Hauptschaltfläche. Die Seite zeigt nur die Informationen, die zum Identifizieren, Zitieren und Öffnen des Werks nötig sind.

Zugriff auf die Ressource

Öffnen Sie den Inhalt über die Hauptoption oder wählen Sie eine andere verfügbare Quelle.

DOAJ DOAJ Articles
Entrar por DOAJ
Hauptzugriff

Open Access verfügbar

Recurso identificado como acceso abierto, sin confirmar automáticamente si es texto completo directo.
Ressource öffnen

Übersicht

Descripción general del contenido del recurso.

Abstract Training deep learning models requires substantial financial and human resources, so once deployed in untrusted environments, these models immediately attract the attention of attackers who seek to steal and misuse them. Traditional model protection methods are ineffective in addressing model accuracy, performance, and proactive defense. To this end, we present an active defensive approach SwitchNet by obfuscating model structure and proposing a switch-controlled mechanism to manage model inference. Specifically, SwitchNet learns the weight distribution of the original model and then constructs confusion layers that are strategically inserted into the original model for structure obfuscation. Each of the model layers is equipped with a switch, which is controlled by a switching policy network. We train this policy network with an adaptive pattern as a “secret key” that can accurately control the switch states, and thereby the model inference process. We conduct a comprehensive theoretical analysis of the perturbation boundary and certify that SwitchNet maintains high robustness under $$\ell _\infty$$ ℓ ∞ perturbations, with certified accuracy exceeding 80% at $$\epsilon = 0.0048$$ ϵ = 0.0048 (CROWN). In addition, we perform extensive experiments on both classical convolutional networks and Vision Transformers. The results show that SwitchNet effectively preserves model accuracy for legitimate users (with only a 0.35% drop), while reducing the accuracy for unauthorized users to near-random guessing. Compared to the state-of-the-art, our approach reduces inference and construction overhead by 20.89% and 12.08%, respectively. Furthermore, SwitchNet proves to be stealthy and resilient against various attacks aimed at detecting or compromising the protection mechanism.

Zitieren

Elegí el formato que necesitás y copiá la referencia al portapapeles.

APA 7

al, Y. C. E. (2026). SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference. https://doi.org/10.1186/s42400-025-00408-y

MLA

al, Yuling Cai et. "SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference." 2026. https://doi.org/10.1186/s42400-025-00408-y.

Chicago

al, Yuling Cai et. 2026. "SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference.". https://doi.org/10.1186/s42400-025-00408-y.

Harvard

al, Y. C. E. 2026, SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference, SpringerOpen, available at: https://doi.org/10.1186/s42400-025-00408-y [Accessed 7 Aug. 2026].

Teilen und drucken

Speichern Sie den Datensatz, kopieren Sie den Permalink oder drucken Sie ihn als PDF.

Referenz exportieren

Exportieren Sie den Datensatz in gängigen Formaten für Literaturverwaltungsprogramme.

Ressourcendetails

Bibliografische Angaben zur Prüfung, ob es sich um das richtige Material handelt.

Titel
SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference
Autor / Mitwirkende
Yuling Cai et al
Verlag
SpringerOpen
Erscheinungsjahr
2026
ISSN
2523-3246
ISSN
2523-3246
Sprache
Inglés

Schlagwörter

Entdecken Sie über diese Schlagwörter weitere verwandte Ressourcen.

Kopiert