返回
Taking Away Both Model and Data: Remember Training Data by Parameter Combinations
DOI:10.1109/TETCI.2022.3182415.png)
摘要
En 中文
Machine Learning (ML) model hatcheries have emerged to help ML model producers. The only thing that the ML model producer needs to do is upload the untrained ML model to the hatchery with a specific task and deploy the returned trained ML model into real-world applications. Although the local private data of the hatchery are not directly accessed by the ML model producer, some backdoor attacks can still steal the private data. These attacks add malicious backdoor codes into the untrained benign ML model and recover the private data in some specific operations after training. However, existing attacks more or less have some disadvantages, such as the limited quality of the stolen private data, seriously affecting the original model performance, and being easy to defend. To address these disadvantages, we propose a novel efficient white-box backdoor attack method called Parameter Combination Encoding Attack (PCEA), which leverages the linear combinations of parameters to remember the private data during training. We evaluate the performance of the proposed method on stolen image quality, testing accuracy, and sensitivity. The experimental results show that PCEA has a much higher quality of the stolen data and robustness while keeping the testing accuracy.
Keyword:
Data models
Training
Encoding
Data mining
Computational modeling
Correlation
Testing
Backdoor attack
data privacy
machine learning
white-box attack
期刊
I
IF:
6.5
论文数:
1.4K
被引数:
4.5K
机构
暂无机构信息
引用论文
Current controlled voltage source inverter using Hysteresis controller and PI controller采用滞环控制器和PI控制器的电流控制电压源逆变器
Mass-spectrometric characterization of cisplatin binding sites on native and denatured ubiquitin天然和变性泛素上顺铂结合位点的质谱表征
BadNets: Evaluating Backdooring Attacks on Deep Neural NetworksBadNets: 评估对深度神经网络的后台攻击
IEEE ACCESS
IF3.6

