Assessing Risk of Stealing Proprietary Models for Medical Imaging Tasks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Raj, Ankita, Swaika, Harsh, Varma, Deepankar, Arora, Chetan
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913910188146688
author Raj, Ankita
Swaika, Harsh
Varma, Deepankar
Arora, Chetan
author_facet Raj, Ankita
Swaika, Harsh
Varma, Deepankar
Arora, Chetan
contents The success of deep learning in medical imaging applications has led several companies to deploy proprietary models in diagnostic workflows, offering monetized services. Even though model weights are hidden to protect the intellectual property of the service provider, these models are exposed to model stealing (MS) attacks, where adversaries can clone the model's functionality by querying it with a proxy dataset and training a thief model on the acquired predictions. While extensively studied on general vision tasks, the susceptibility of medical imaging models to MS attacks remains inadequately explored. This paper investigates the vulnerability of black-box medical imaging models to MS attacks under realistic conditions where the adversary lacks access to the victim model's training data and operates with limited query budgets. We demonstrate that adversaries can effectively execute MS attacks by using publicly available datasets. To further enhance MS capabilities with limited query budgets, we propose a two-step model stealing approach termed QueryWise. This method capitalizes on unlabeled data obtained from a proxy distribution to train the thief model without incurring additional queries. Evaluation on two medical imaging models for Gallbladder Cancer and COVID-19 classification substantiates the effectiveness of the proposed attack. The source code is available at https://github.com/rajankita/QueryWise.
format Preprint
id arxiv_https___arxiv_org_abs_2506_19464
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Assessing Risk of Stealing Proprietary Models for Medical Imaging Tasks
Raj, Ankita
Swaika, Harsh
Varma, Deepankar
Arora, Chetan
Image and Video Processing
Cryptography and Security
Computer Vision and Pattern Recognition
The success of deep learning in medical imaging applications has led several companies to deploy proprietary models in diagnostic workflows, offering monetized services. Even though model weights are hidden to protect the intellectual property of the service provider, these models are exposed to model stealing (MS) attacks, where adversaries can clone the model's functionality by querying it with a proxy dataset and training a thief model on the acquired predictions. While extensively studied on general vision tasks, the susceptibility of medical imaging models to MS attacks remains inadequately explored. This paper investigates the vulnerability of black-box medical imaging models to MS attacks under realistic conditions where the adversary lacks access to the victim model's training data and operates with limited query budgets. We demonstrate that adversaries can effectively execute MS attacks by using publicly available datasets. To further enhance MS capabilities with limited query budgets, we propose a two-step model stealing approach termed QueryWise. This method capitalizes on unlabeled data obtained from a proxy distribution to train the thief model without incurring additional queries. Evaluation on two medical imaging models for Gallbladder Cancer and COVID-19 classification substantiates the effectiveness of the proposed attack. The source code is available at https://github.com/rajankita/QueryWise.
title Assessing Risk of Stealing Proprietary Models for Medical Imaging Tasks
topic Image and Video Processing
Cryptography and Security
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2506.19464