Torna ai risultati
Scheda bibliografica · Consultazione e accesso
Artículo

SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference

Yuling Cai et al · SpringerOpen · 2026

Accesso aperto disponibile
Lettura rapida. Controlla i dati essenziali della risorsa e accedi al contenuto con il pulsante principale. La scheda mostra solo le informazioni necessarie per identificare, citare e aprire l’opera.

Accesso alla risorsa

Apri il contenuto dall’opzione principale o scegli un’altra fonte disponibile.

DOAJ DOAJ Articles
Entrar por DOAJ
Accesso principale

Accesso aperto disponibile

Recurso identificado como acceso abierto, sin confirmar automáticamente si es texto completo directo.
Apri risorsa

Riepilogo

Descripción general del contenido del recurso.

Abstract Training deep learning models requires substantial financial and human resources, so once deployed in untrusted environments, these models immediately attract the attention of attackers who seek to steal and misuse them. Traditional model protection methods are ineffective in addressing model accuracy, performance, and proactive defense. To this end, we present an active defensive approach SwitchNet by obfuscating model structure and proposing a switch-controlled mechanism to manage model inference. Specifically, SwitchNet learns the weight distribution of the original model and then constructs confusion layers that are strategically inserted into the original model for structure obfuscation. Each of the model layers is equipped with a switch, which is controlled by a switching policy network. We train this policy network with an adaptive pattern as a “secret key” that can accurately control the switch states, and thereby the model inference process. We conduct a comprehensive theoretical analysis of the perturbation boundary and certify that SwitchNet maintains high robustness under $$\ell _\infty$$ ℓ ∞ perturbations, with certified accuracy exceeding 80% at $$\epsilon = 0.0048$$ ϵ = 0.0048 (CROWN). In addition, we perform extensive experiments on both classical convolutional networks and Vision Transformers. The results show that SwitchNet effectively preserves model accuracy for legitimate users (with only a 0.35% drop), while reducing the accuracy for unauthorized users to near-random guessing. Compared to the state-of-the-art, our approach reduces inference and construction overhead by 20.89% and 12.08%, respectively. Furthermore, SwitchNet proves to be stealthy and resilient against various attacks aimed at detecting or compromising the protection mechanism.

Come citare

Elegí el formato que necesitás y copiá la referencia al portapapeles.

APA 7

al, Y. C. E. (2026). SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference. https://doi.org/10.1186/s42400-025-00408-y

MLA

al, Yuling Cai et. "SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference." 2026. https://doi.org/10.1186/s42400-025-00408-y.

Chicago

al, Yuling Cai et. 2026. "SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference.". https://doi.org/10.1186/s42400-025-00408-y.

Harvard

al, Y. C. E. 2026, SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference, SpringerOpen, available at: https://doi.org/10.1186/s42400-025-00408-y [Accessed 9 Aug. 2026].

Condividi e stampa

Salva la scheda, copia il link permanente o stampala in PDF.

Esporta riferimento

Esporta il record nei formati più comuni per usarlo con un gestore bibliografico.

Dettagli della risorsa

Informazioni bibliografiche utili per verificare che sia il materiale corretto.

Titolo
SwitchNet: protecting neural networks by structure obfuscation and switch-controlled inference
Autore / collaboratori
Yuling Cai et al
Editore
SpringerOpen
Anno di pubblicazione
2026
ISSN
2523-3246
ISSN
2523-3246
Lingua
Inglés

Soggetti

Esplora risorse correlate a partire da questi soggetti.

Copiato