This technology introduces a method for enhancing the security of neural networks by applying weight perturbations during training to prevent unauthorized access and attacks.
Background :
Neural networks are increasingly deployed in mobile, edge, and IoT devices, as well as through machine learning service APIs, raising concerns about their vulnerability to various attacks such as snooping and cryptanalysis. Traditional protection methods often fail to comprehensively secure all layers of the network, leaving models at risk. This need for robust security measures to safeguard neural networks in diverse environments led to the development of a novel training approach that strengthens model integrity from the initial layer forward. This technology also helps eliminate feature encryption, thereby significantly improving the energy efficiency of battery-constrained mobile, edge, and IoT devices.
Technology Overview :
This technology employs a specialized regularizer during neural network training that injects deliberate weight perturbations, effectively disrupting the mathematical dependencies between layers. By targeting the first layer, this method propagates security protections across all subsequent layers, ensuring the entire model remains safeguarded against potential attacks. This approach differs from conventional techniques by embedding security features directly into the training process rather than relying on external protective measures. The core innovation lies in how these controlled perturbations create unpredictable model behavior that deters malicious access and manipulation while preserving the network's overall performance. It is particularly designed for environments with limited computational resources, such as mobile and edge devices, where conventional heavy security protocols may be impractical. Additionally, this method enhances the security of neural networks delivered as services via APIs, which are common targets for adversarial attacks. By integrating this approach into training, developers can create neural models that are inherently resistant to a range of threats, providing a valuable solution for securing sensitive machine learning applications in modern interconnected systems.
Advantages :
• Comprehensive security: Protects all neural network layers by securing the first layer, ensuring holistic model protection.
• Efficient integration: Embeds security measures directly within the training process without significant performance loss.
• Resource-friendly: Suitable for deployment on mobile, edge, and IoT devices with limited computational capacity.
• Enhanced protection for services: Secures neural networks accessed via APIs, mitigating risks associated with remote attacks.
• Robust against diverse attack vectors: Effective against snooping, cryptanalytic, and other common neural network attacks.
Applications :
• Mobile and edge device neural network models requiring enhanced security.
• Internet of Things (IoT) devices utilizing machine learning components vulnerable to external threats.
• Machine learning services provided through APIs that require protection from adversarial attacks.
• Any artificial intelligence systems where safeguarding neural network integrity is critical for functional reliability.
Intellectual Property Summary : Patent Pending
Stage of Development : TRL = 3
Licensing Status : This technology is available for licensing.
About the Research Foundation for the State University of New York:
As the nation's largest research foundation supporting the nation's largest public university system, The Research Foundation for SUNY powers research and innovation to address today's most pressing problems and shape a better future for generations to come. The Research Foundations supports SUNY researchers leading the way globally in AI for the public good, quantum technologies, next-generation semiconductors, biotech and medicine, energy and climate solutions, and more. The Research Foundation for SUNY is a private, nonprofit educational corporation that is tax-exempt under Internal Revenue Code (IRC) Section 501(c)(3). To learn more, please visit us online at rfsuny.org .
About the State University of New York
The State University of New York is the largest comprehensive system of higher education in the United States, and more than 95 percent of all New Yorkers live within 30 miles of any one of SUNY’s 64 colleges and universities. Across the system, SUNY has four academic health centers, five hospitals, four medical schools, two dental schools, a law school, the country’s oldest school of maritime, the state's only college of optometry, 12 Educational Opportunity Centers, over 30 ATTAIN digital literacy labs, and manages one US Department of Energy National Laboratory. In total, SUNY serves about 1.7 million students across its portfolio of credit- and non-credit-bearing courses and programs, continuing education, and community outreach programs. SUNY oversees nearly a quarter of academic research in New York. Research expenditures system-wide are nearly $1.5 billion in fiscal year 2025, including significant contributions from students and faculty. There are more than three million SUNY alumni worldwide, and annually one in three New Yorkers who earn a college degree is a SUNY alum. To learn more about how SUNY creates opportunities, visit suny.edu .