A Model Stealing Attack Against Multi-Exit Networks

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Pan, Li, Peizhuo, Lv, Kai, Chen, Shengzhi, Zhang, Yuling, Cai, Fan, Xiang
Natura: Preprint
Pubblicazione: 2023
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866915198669946880
author Pan, Li
Peizhuo, Lv
Kai, Chen
Shengzhi, Zhang
Yuling, Cai
Fan, Xiang
author_facet Pan, Li
Peizhuo, Lv
Kai, Chen
Shengzhi, Zhang
Yuling, Cai
Fan, Xiang
contents Compared to traditional neural networks with a single output channel, a multi-exit network has multiple exits that allow for early outputs from the model's intermediate layers, thus significantly improving computational efficiency while maintaining similar main task accuracy. Existing model stealing attacks can only steal the model's utility while failing to capture its output strategy, i.e., a set of thresholds used to determine from which exit to output. This leads to a significant decrease in computational efficiency for the extracted model, thereby losing the advantage of multi-exit networks. In this paper, we propose the first model stealing attack against multi-exit networks to extract both the model utility and the output strategy. We employ Kernel Density Estimation to analyze the target model's output strategy and use performance loss and strategy loss to guide the training of the extracted model. Furthermore, we design a novel output strategy search algorithm to maximize the consistency between the victim model and the extracted model's output behaviors. In experiments across multiple multi-exit networks and benchmark datasets, our method always achieves accuracy and efficiency closest to the victim models.
format Preprint
id arxiv_https___arxiv_org_abs_2305_13584
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle A Model Stealing Attack Against Multi-Exit Networks
Pan, Li
Peizhuo, Lv
Kai, Chen
Shengzhi, Zhang
Yuling, Cai
Fan, Xiang
Cryptography and Security
Artificial Intelligence
Compared to traditional neural networks with a single output channel, a multi-exit network has multiple exits that allow for early outputs from the model's intermediate layers, thus significantly improving computational efficiency while maintaining similar main task accuracy. Existing model stealing attacks can only steal the model's utility while failing to capture its output strategy, i.e., a set of thresholds used to determine from which exit to output. This leads to a significant decrease in computational efficiency for the extracted model, thereby losing the advantage of multi-exit networks. In this paper, we propose the first model stealing attack against multi-exit networks to extract both the model utility and the output strategy. We employ Kernel Density Estimation to analyze the target model's output strategy and use performance loss and strategy loss to guide the training of the extracted model. Furthermore, we design a novel output strategy search algorithm to maximize the consistency between the victim model and the extracted model's output behaviors. In experiments across multiple multi-exit networks and benchmark datasets, our method always achieves accuracy and efficiency closest to the victim models.
title A Model Stealing Attack Against Multi-Exit Networks
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2305.13584