Back to results
Bibliographic record · Consultation and access
Artículo

SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference

Yuling Cai et al · SpringerOpen · 2026

Open access available
Quick overview. Review the resource’s basic details, then access the content using the main button. This page shows only the information needed to identify, cite, and open the work.

Resource access

Open the content from the main option or choose another available source.

DOAJ DOAJ Articles
Entrar por DOAJ
Main access

Open access available

Recurso identificado como acceso abierto, sin confirmar automáticamente si es texto completo directo.
Open resource

Summary

Descripción general del contenido del recurso.

Abstract Training deep learning models requires substantial financial and human resources, so once deployed in untrusted environments, these models immediately attract the attention of attackers who seek to steal and misuse them. Traditional model protection methods are ineffective in addressing model accuracy, performance, and proactive defense. To this end, we present an active defensive approach SwitchNet by obfuscating model structure and proposing a switch-controlled mechanism to manage model inference. Specifically, SwitchNet learns the weight distribution of the original model and then constructs confusion layers that are strategically inserted into the original model for structure obfuscation. Each of the model layers is equipped with a switch, which is controlled by a switching policy network. We train this policy network with an adaptive pattern as a “secret key” that can accurately control the switch states, and thereby the model inference process. We conduct a comprehensive theoretical analysis of the perturbation boundary and certify that SwitchNet maintains high robustness under $$\ell _\infty$$ ℓ ∞ perturbations, with certified accuracy exceeding 80% at $$\epsilon = 0.0048$$ ϵ = 0.0048 (CROWN). In addition, we perform extensive experiments on both classical convolutional networks and Vision Transformers. The results show that SwitchNet effectively preserves model accuracy for legitimate users (with only a 0.35% drop), while reducing the accuracy for unauthorized users to near-random guessing. Compared to the state-of-the-art, our approach reduces inference and construction overhead by 20.89% and 12.08%, respectively. Furthermore, SwitchNet proves to be stealthy and resilient against various attacks aimed at detecting or compromising the protection mechanism.

How to cite

Elegí el formato que necesitás y copiá la referencia al portapapeles.

APA 7

al, Y. C. E. (2026). SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference. https://doi.org/10.1186/s42400-025-00408-y

MLA

al, Yuling Cai et. "SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference." 2026. https://doi.org/10.1186/s42400-025-00408-y.

Chicago

al, Yuling Cai et. 2026. "SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference.". https://doi.org/10.1186/s42400-025-00408-y.

Harvard

al, Y. C. E. 2026, SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference, SpringerOpen, available at: https://doi.org/10.1186/s42400-025-00408-y [Accessed 6 Aug. 2026].

Share and print

Save the record, copy its permanent link, or print it as a PDF.

Export reference

You can export the record in common formats for use in a reference manager.

Resource details

Bibliographic information to help confirm that this is the correct material.

Title
SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference
Author / contributors
Yuling Cai et al
Publisher
SpringerOpen
Publication year
2026
ISSN
2523-3246
ISSN
2523-3246
Language
English

Subjects

Explore related resources through these subjects.

Copied