arrow
返回

A Comprehensive Defense Framework Against Model Extraction Attacks

delete2024-03-01
delete10
PRE
AI
W
Wenbo Jiang
H
Hongwei Li *
G
Guowen Xu
T
Tianwei Zhang
Rongxing Lu 封面图
Rongxing Lu (Rongxing Lu)
DOI:10.1109/TDSC.2023.3261327delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
As a promising service, Machine Learning as a Service (MLaaS) provides personalized inference functions for clients through paid APIs. Nevertheless, it is vulnerable to model extraction attacks, in which an attacker can extract a functionally-equivalent model by repeatedly querying the APIs with crafted samples. While numerous works have been proposed to defend against model extraction attacks, existing efforts are accompanied by limitations and low comprehensiveness. In this article, we propose AMAO, a comprehensive defense framework against model extraction attacks. Specifically, AMAO consists of four interlinked successive phases: adversarial training is first exploited to weaken the effectiveness of model extraction attacks. Then, malicious query detection is used to detect malicious queries and mark malicious users. After that, we develop a label-flipping poisoning attack to instruct the adaptive query responses to malicious users. Besides, the image pHash algorithm is employed to ensure the indistinguishability of the query responses. Finally, the perturbed results are served as a backdoor to verify the ownership of any suspicious model. Extensive experiments demonstrate that AMAO outperforms existing defenses in defending against model extraction attacks and is also robust against the adaptive adversary who is aware of the defense.
Keyword:
Data models
Deep learning
machine-learning-as-a-service
model extraction attacks

期刊

IEEE Transactions on Dependable and Secure Computing 封面图
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
论文数:
2.5K
被引数:
9.6K

机构

U
University of New Brunswick
学者数:
4.0K
论文数: 4.2K
被引数: 6.3K
N
Nanyang Technological University
学者数:
4.9W
论文数: 4.8W
被引数: 8.1W
引用论文

引用论文

Long-QT-Syndrom als Differenzialdiagnose einer Grand-Mal-Epilepsie
err2006-10-01
err0
PREAI
errS. Betge; E. Schulze-Bahr; C. Fitzek; R. Pfeifer; H.-R. Figulla; O. W. Witte; S. Isenmann
err分享
err收藏
err
IF0
err
err0
PREAI
err
err分享
err收藏
Label flipping attacks against Naive Bayes on spam filtering systems
err2021-01-04
err27
PREAI
errZhang, Hongpo; Cheng, Ning; Zhang, Yang; Li, Zhanbo
err分享
err收藏
Comparison of depot tetracosactrin and corticotrophin gel
errBMJ
IF0
err1969-12-20
err0
errOAAI
errB. L. J. Treadwell; P. M. Dennis
err分享
err收藏
学者 查看更多内容