Stolen Subwords: Importance of Vocabularies for Machine Translation Model Stealing

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autor principal: Zouhar, Vilém
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866909085814751232
author Zouhar, Vilém
author_facet Zouhar, Vilém
contents In learning-based functionality stealing, the attacker is trying to build a local model based on the victim's outputs. The attacker has to make choices regarding the local model's architecture, optimization method and, specifically for NLP models, subword vocabulary, such as BPE. On the machine translation task, we explore (1) whether the choice of the vocabulary plays a role in model stealing scenarios and (2) if it is possible to extract the victim's vocabulary. We find that the vocabulary itself does not have a large effect on the local model's performance. Given gray-box model access, it is possible to collect the victim's vocabulary by collecting the outputs (detokenized subwords on the output). The results of the minimum effect of vocabulary choice are important more broadly for black-box knowledge distillation.
format Preprint
id arxiv_https___arxiv_org_abs_2401_16055
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Stolen Subwords: Importance of Vocabularies for Machine Translation Model Stealing
Zouhar, Vilém
Computation and Language
In learning-based functionality stealing, the attacker is trying to build a local model based on the victim's outputs. The attacker has to make choices regarding the local model's architecture, optimization method and, specifically for NLP models, subword vocabulary, such as BPE. On the machine translation task, we explore (1) whether the choice of the vocabulary plays a role in model stealing scenarios and (2) if it is possible to extract the victim's vocabulary. We find that the vocabulary itself does not have a large effect on the local model's performance. Given gray-box model access, it is possible to collect the victim's vocabulary by collecting the outputs (detokenized subwords on the output). The results of the minimum effect of vocabulary choice are important more broadly for black-box knowledge distillation.
title Stolen Subwords: Importance of Vocabularies for Machine Translation Model Stealing
topic Computation and Language
url https://arxiv.org/abs/2401.16055