Source author record

Yujin Huang

Yujin Huang appears in the imported research catalog. Authorship, coauthor and topic links are available while profile ownership is still unclaimed.

ResearcherUnclaimed source record

Catalog footprint

What is connected

4works
4topics
4close collaborators

Actions

Connect this record

Log in to claim

Research graph

See the researcher in context

Open full explorer

Inspect adjacent papers, topics, institutions and collaborators without losing the researcher page.

Building this map preview

BZPEER is loading the nearby papers, people, topics and institutions for this page.

Published work

4 published item(s)

preprint2022arXiv

Smart App Attack: Hacking Deep Learning Models in Android Apps

On-device deep learning is rapidly gaining popularity in mobile applications. Compared to offloading deep learning from smartphones to the cloud, on-device deep learning enables offline model inference while preserving user privacy. However, such mechanisms inevitably store models on users' smartphones and may invite adversarial attacks as they are accessible to attackers. Due to the characteristic of the on-device model, most existing adversarial attacks cannot be directly applied for on-device models. In this paper, we introduce a grey-box adversarial attack framework to hack on-device models by crafting highly similar binary classification models based on identified transfer learning approaches and pre-trained models from TensorFlow Hub. We evaluate the attack effectiveness and generality in terms of four different settings including pre-trained models, datasets, transfer learning approaches and adversarial attack algorithms. The results demonstrate that the proposed attacks remain effective regardless of different settings, and significantly outperform state-of-the-art baselines. We further conduct an empirical study on real-world deep learning mobile apps collected from Google Play. Among 53 apps adopting transfer learning, we find that 71.7\% of them can be successfully attacked, which includes popular ones in medicine, automation, and finance categories with critical usage scenarios. The results call for the awareness and actions of deep learning mobile app developers to secure the on-device models. The code of this work is available at https://github.com/Jinxhy/SmartAppAttack

preprint2021arXiv

Robustness of on-device Models: Adversarial Attack to Deep Learning Models on Android Apps

Deep learning has shown its power in many applications, including object detection in images, natural-language understanding, and speech recognition. To make it more accessible to end users, many deep learning models are now embedded in mobile apps. Compared to offloading deep learning from smartphones to the cloud, performing machine learning on-device can help improve latency, connectivity, and power consumption. However, most deep learning models within Android apps can easily be obtained via mature reverse engineering, while the models' exposure may invite adversarial attacks. In this study, we propose a simple but effective approach to hacking deep learning models using adversarial attacks by identifying highly similar pre-trained models from TensorFlow Hub. All 10 real-world Android apps in the experiment are successfully attacked by our approach. Apart from the feasibility of the model attack, we also carry out an empirical study that investigates the characteristics of deep learning models used by hundreds of Android apps on Google Play. The results show that many of them are similar to each other and widely use fine-tuning techniques to pre-trained models on the Internet.

preprint2016arXiv

Direct Measure of Giant Magnetocaloric Entropy Contributions in Ni-Mn-In

Off-stoichiometric alloys based on Ni 2 MnIn have drawn attention due to the coupled first order magnetic and structural transformations, and the large magnetocaloric entropy associated with the transformations. Here we describe calorimetric and magnetic studies of four compositions. The results provide a direct measure of entropy changes contributions including at the first-order phase transitions, and thereby a determination of the maximum field-induced entropy change corresponding to the giant magnetocaloric effect. We find a large excess entropy change, attributed to magneto-elastic coupling, but only in compositions with no ferromagnetic order in the high-temperature austenite phase. Furthermore, a molecular field model corresponding to antiferromagnetism of the low-temperature phases is in good agreement, and nearly independent of composition, despite significant differences in overall magnetic response of these materials.

preprint2015arXiv

Calorimetric and magnetic study for Ni$_{50}$Mn$_{36}$In$_{14}$ and relative cooling power in paramagnetic inverse magnetocaloric systems

The non-stoichiometric Heusler alloy Ni$_{50}$Mn$_{36}$In$_{14}$ undergoes a martensitic phase transformation in the vicinity of 345 K, with the high temperature austenite phase exhibiting paramagnetic rather than ferromagnetic behavior, as shown in similar alloys with lower-temperature transformations. Suitably prepared samples are shown to exhibit a sharp transformation, a relatively small thermal hysteresis, and a large field-induced entropy change. We analyzed the magnetocaloric behavior both through magnetization and direct field-dependent calorimetry measurements. For measurements passing through the first-order transformation, an improved method for heat-pulse relaxation calorimetry was designed. The results provide a firm basis for the analytic evaluation of field-induced entropy changes in related materials. An analysis of the relative cooling power (RCP), based on the integrated field-induced entropy change and magnetizing behavior of the Mn spin system with ferromagnetic correlations, shows that a significant RCP may be obtained in these materials by tuning the magnetic and structural transformation temperatures through minor compositional changes or local order changes.