A First Look at On-device Models in iOS Apps

被引:3
|
作者
Hu, Han [1 ]
Huang, Yujin [1 ]
Chen, Qiuyuan [2 ]
Zhuo, Terry Yue [1 ]
Chen, Chunyang [1 ]
机构
[1] Monash Univ, Fac Informat Technol, 25 Exhibit Walk, Clayton, Vic 3800, Australia
[2] Tencent Bldg,Zhongqu First Rd,Hi Tech Pk, Shenzhen 518054, Guangdong, Peoples R China
关键词
On-device models; iOS; adversarial attack; mobile; iPhone; MACHINE;
D O I
10.1145/3617177
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Powered by the rising popularity of deep learning techniques on smartphones, on-device deep learning models are being used in vital fields such as finance, social media, and driving assistance. Because of the transparency of the Android platform and the on-device models inside, on-device models on Android smartphones have been proven to be extremely vulnerable. However, due to the challenge in accessing and analyzing iOS app files, despite iOS being a mobile platform as popular as Android, there are no relevant works on on-device models in iOS apps. Since the functionalities of the same app on Android and iOS platforms are similar, the same vulnerabilities may exist on both platforms. In this article, we present the first empirical study about on-device models in iOS apps, including their adoption of deep learning frameworks, structure, functionality, and potential security issues. We study why current developers use different on-device models for one app between iOS and Android. We propose a more general attack against white-box models that does not rely on pre-trained models and a new adversarial attack approach based on our findings to target iOS's gray-box on-device models. Our results show the effectiveness of our approaches. Finally, we successfully exploit the vulnerabilities of on-device models to attack real-world iOS apps.
引用
收藏
页数:30
相关论文
共 50 条
  • [1] Robustness of on-device Models: Adversarial Attack to Deep Learning Models on Android Apps
    Huang, Yujin
    Hu, Han
    Chen, Chunyang
    2021 IEEE/ACM 43RD INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: SOFTWARE ENGINEERING IN PRACTICE (ICSE-SEIP 2021), 2021, : 101 - 110
  • [2] Towards Preserving Server-Side Privacy of On-Device Models
    Atrey, Akanksha
    Sinha, Ritwik
    Sarkhel, Somdeb
    Mitra, Saayan
    Arbour, David
    Maharaj, Akash V.
    Shenoy, Prashant
    COMPANION PROCEEDINGS OF THE WEB CONFERENCE 2022, WWW 2022 COMPANION, 2022, : 282 - 285
  • [3] Cider: Native Execution of iOS Apps on Android
    Andrus, Jeremy
    Van't Hof, Alexander
    AlDuaij, Naser
    Dall, Christoffer
    Viennot, Nicolas
    Nieh, Jason
    ACM SIGPLAN NOTICES, 2014, 49 (04) : 367 - 381
  • [4] Divergent deceptions: comparative analysis of Deceptive Patterns in iOS and Android apps
    Li, Wanda
    Flatla, David R.
    Arndt, Felix
    BEHAVIOUR & INFORMATION TECHNOLOGY, 2025,
  • [5] A Longitudinal Study of Removed Apps in iOS App Store
    Lin, Fuqi
    Wang, Haoyu
    Wang, Liu
    Liu, Xuanzhe
    PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE 2021 (WWW 2021), 2021, : 1435 - 1446
  • [6] Protecting Million-User iOS Apps with Obfuscation: Motivations, Pitfalls, and Experience
    Wang, Pei
    Wu, Dinghao
    Chen, Zhaofeng
    Wei, Tao
    2018 IEEE/ACM 40TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING - SOFTWARE ENGINEERING IN PRACTICE TRACK (ICSE-SEIP 2018), 2018, : 235 - 244
  • [7] AI on the Move: From On-Device to On-Multi-Device
    Flores, Huber
    Nurmi, Petteri
    Hui, Pan
    2019 IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS WORKSHOPS (PERCOM WORKSHOPS), 2019, : 310 - 315
  • [8] CydiOS: A Model-Based Testing Framework for iOS Apps
    Wu, Shuohan
    Li, Jianfeng
    Zhou, Hao
    Fang, Yongsheng
    Zhao, Kaifa
    Wang, Haoyu
    Qian, Chenxiong
    Luo, Xiapu
    PROCEEDINGS OF THE 32ND ACM SIGSOFT INTERNATIONAL SYMPOSIUM ON SOFTWARE TESTING AND ANALYSIS, ISSTA 2023, 2023, : 1 - 13
  • [9] LibKit: Detecting Third-Party Libraries in iOS Apps
    Dominguez-Alvarez, Daniel
    de la Cruz, Alejandro
    Gorla, Alessandra
    Caballero, Juan
    PROCEEDINGS OF THE 31ST ACM JOINT MEETING EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING, ESEC/FSE 2023, 2023, : 1407 - 1418
  • [10] Integrating YOLO Object Detection with Augmented Reality for iOS Apps
    Mahurkar, Sagar
    2018 9TH IEEE ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2018, : 585 - 589