SAME: Sample Reconstruction against Model Extraction Attacks

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Xie, Yi, Zhang, Jie, Zhao, Shiqian, Zhang, Tianwei, Chen, Xiaofeng
Natura: Preprint
Pubblicazione: 2023
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866909064111325184
author Xie, Yi
Zhang, Jie
Zhao, Shiqian
Zhang, Tianwei
Chen, Xiaofeng
author_facet Xie, Yi
Zhang, Jie
Zhao, Shiqian
Zhang, Tianwei
Chen, Xiaofeng
contents While deep learning models have shown significant performance across various domains, their deployment needs extensive resources and advanced computing infrastructure. As a solution, Machine Learning as a Service (MLaaS) has emerged, lowering the barriers for users to release or productize their deep learning models. However, previous studies have highlighted potential privacy and security concerns associated with MLaaS, and one primary threat is model extraction attacks. To address this, there are many defense solutions but they suffer from unrealistic assumptions and generalization issues, making them less practical for reliable protection. Driven by these limitations, we introduce a novel defense mechanism, SAME, based on the concept of sample reconstruction. This strategy imposes minimal prerequisites on the defender's capabilities, eliminating the need for auxiliary Out-of-Distribution (OOD) datasets, user query history, white-box model access, and additional intervention during model training. It is compatible with existing active defense methods. Our extensive experiments corroborate the superior efficacy of SAME over state-of-the-art solutions. Our code is available at https://github.com/xythink/SAME.
format Preprint
id arxiv_https___arxiv_org_abs_2312_10578
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle SAME: Sample Reconstruction against Model Extraction Attacks
Xie, Yi
Zhang, Jie
Zhao, Shiqian
Zhang, Tianwei
Chen, Xiaofeng
Cryptography and Security
Artificial Intelligence
Computer Vision and Pattern Recognition
Machine Learning
While deep learning models have shown significant performance across various domains, their deployment needs extensive resources and advanced computing infrastructure. As a solution, Machine Learning as a Service (MLaaS) has emerged, lowering the barriers for users to release or productize their deep learning models. However, previous studies have highlighted potential privacy and security concerns associated with MLaaS, and one primary threat is model extraction attacks. To address this, there are many defense solutions but they suffer from unrealistic assumptions and generalization issues, making them less practical for reliable protection. Driven by these limitations, we introduce a novel defense mechanism, SAME, based on the concept of sample reconstruction. This strategy imposes minimal prerequisites on the defender's capabilities, eliminating the need for auxiliary Out-of-Distribution (OOD) datasets, user query history, white-box model access, and additional intervention during model training. It is compatible with existing active defense methods. Our extensive experiments corroborate the superior efficacy of SAME over state-of-the-art solutions. Our code is available at https://github.com/xythink/SAME.
title SAME: Sample Reconstruction against Model Extraction Attacks
topic Cryptography and Security
Artificial Intelligence
Computer Vision and Pattern Recognition
Machine Learning
url https://arxiv.org/abs/2312.10578