arrow
Return

Making models more secure: An efficient model stealing detection method

delete2024-07-01
delete1
PRE
AI
C
Chenlong Zhang
S
Senlin Luo
潘丽敏 (Limin Pan) *
C
Chuan Lü
张昭 cover
张昭 (Zhao Zhang)
DOI:10.1016/j.compeleceng.2024.109266delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Reduced distinguishability significantly challenges the detection of Model Stealing (MS). Existing methods for identifying MS attacks exhibit key limitations: (1) Sample -level detection methods that use fixed feature thresholds often inadvertently include benign samples or overlook malicious ones; (2) Distribution -level detection methods with static divergence benchmarks may misclassify benign query samples that deviate from these benchmarks This paper introduces GuardNet, an innovative model stealing detection method. By combining boundary features with inter-sample distance features, GuardNet more precisely identifies malicious sample pairs and employs distribution divergences to adjust decision thresholds, thus enhancing its detection capabilities. The method incorporates a variational autoencoder to reconstruct query samples and uses the Wasserstein distance between pre- and post-reconstruction samples as a measure of distribution divergences, effectively minimizing the influence of distribution shifts on benign query samples. Experimental results indicate that this approach significantly reduces the number of adversarial queries and markedly decreases false positives.
Keywords:
Model stealing detection
Model stealing attack
Security and privacy
Machine Learning asa Service

Journal

C
Computers and Electrical Engineering
IF:
4.9
Papers:
6.7K
Citations:
1.3W

Organization

B
beijing institute of technology
Scholars:
5.4W
Papers: 4.0W
Citations: 63