Pith. sign in

REVIEW 4 cited by

A Panda? No, It's a Sloth: Slowdown Attacks on Adaptive Multi-Exit Neural Network Inference

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2010.02432 v2 pith:3TTXWAPM submitted 2020-10-06 cs.LG cs.CR

classification cs.LGcs.CR
keywords multi-exitdnnsarchitecturesslowdownadaptiveadversarialthreatattack
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

Recent increases in the computational demands of deep neural networks (DNNs), combined with the observation that most input samples require only simple models, have sparked interest in $input$-$adaptive$ multi-exit architectures, such as MSDNets or Shallow-Deep Networks. These architectures enable faster inferences and could bring DNNs to low-power devices, e.g., in the Internet of Things (IoT). However, it is unknown if the computational savings provided by this approach are robust against adversarial pressure. In particular, an adversary may aim to slowdown adaptive DNNs by increasing their average inference time$-$a threat analogous to the $denial$-$of$-$service$ attacks from the Internet. In this paper, we conduct a systematic evaluation of this threat by experimenting with three generic multi-exit DNNs (based on VGG16, MobileNet, and ResNet56) and a custom multi-exit architecture, on two popular image classification benchmarks (CIFAR-10 and Tiny ImageNet). To this end, we show that adversarial example-crafting techniques can be modified to cause slowdown, and we propose a metric for comparing their impact on different architectures. We show that a slowdown attack reduces the efficacy of multi-exit DNNs by 90-100%, and it amplifies the latency by 1.5-5$\times$ in a typical IoT deployment. We also show that it is possible to craft universal, reusable perturbations and that the attack can be effective in realistic black-box scenarios, where the attacker has limited knowledge about the victim. Finally, we show that adversarial training provides limited protection against slowdowns. These results suggest that further research is needed for defending multi-exit architectures against this emerging threat. Our code is available at https://github.com/sanghyun-hong/deepsloth.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. MOAT: Model-Agnostic Randomized Transformations for preventing Efficiency Degradation Attacks on ViTs

    cs.CR 2026-08 conditional novelty 5.0 of 10

    A model-agnostic input preprocessing pipeline of random resizing, median filtering, and JPEG compression limits adversarial efficiency-degradation attacks on token-pruning Vision Transformers to within 3.4% of unattac...

  2. When Efficiency Becomes Fragility: Exploiting Dynamic Routing Vulnerabilities in Adaptive UAV Tracking

    cs.AI 2026-08 conditional novelty 5.0 of 10

    The paper claims that hard layer-skipping decisions in adaptive trackers create discontinuities (unbounded local Lipschitz constants) that an attacker can exploit by flipping gating decisions with imperceptible perturbations.

  3. Exploiting Efficiency Vulnerabilities in Dynamic Deep Learning Systems

    cs.LG 2025-06 conditional novelty 4.0 of 10

    Small adversarial perturbations can substantially inflate the latency, FLOPs, and energy of dynamic deep learning systems, as demonstrated on LLaMA 3B and reviewed across early-exit, generation, and detection architectures.

  4. A Survey of Adversarial Efficiency Degradation for Vision Transformer by Exploiting Input-adaptive Optimization

    cs.CR 2026-08 reject novelty 3.0 of 10

    A review that unifies and compares two efficiency-degradation attacks on token-pruning vision transformers, but its synthesized tables are internally inconsistent and should not be cited for quantitative claims.

Pith tools