arrow
Return

Towards explainable model extraction attacks

delete2022-09-08
delete4
PRE
AI
A
Anli Yan
R
Ruitao Hou
X
Xiaozhang Liu *
H
Hongyang Yan
T
Teng Huang
X
Xianmin Wang
DOI:10.1002/int.23022delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
One key factor able to boost the applications of artificial intelligence (AI) in security-sensitive domains is to leverage them responsibly, which is engaged in providing explanations for AI. To date, a plethora of explainable artificial intelligence (XAI) has been proposed to help users interpret model decisions. However, given its data-driven nature, the explanation itself is potentially susceptible to a high risk of exposing privacy. In this paper, we first show that the existing XAI is vulnerable to model extraction attacks and then present an XAI-aware dual-task model extraction attack (DTMEA). DTMEA can attack a target model with explanation services, that is, it can extract both the classification and explanation tasks of the target model. More specifically, the substitution model extracted by DTMEA is a multitask learning architecture, consisting of a sharing layer and two task-specific layers for classification and explanation. To reveal which explanation technologies are more vulnerable to expose privacy information, we conduct an empirical evaluation of four major explanation types in the benchmark data set. Experimental results show that the attack accuracy of DTMEA outperforms the predicted-only method with up to 1.25%, 1.53%, 9.25%, and 7.45% in MNIST, Fashion-MNIST, CIFAR-10, and CIFAR-100, respectively. By exposing the potential threats on explanation technologies, our research offers the insights to develop effective tools that are able to trade off security-sensitive relationships.
Keywords:
black box
explainable artificial intelligence
label-only
model extraction attack

Journal

International Journal of Intelligent Systems cover
International Journal of Intelligent Systems
IF:
3.7
Papers:
3.1K
Citations:
8.1K

Organization

G
Guangzhou University
Scholars:
1.8W
Papers: 1.3W
Citations: 1.8W
H
Hainan University
Scholars:
2.0W
Papers: 1.2W
Citations: 1.9W
Cited Papers

Cited Papers

The oxygen effect and fractionated radiotherapy
err2012-12-20
err0
PREAI
errMichael Horsman; Bradly Wouters; Michael Joiner; Jens Overgaard
errShare
errSave
Resource Allocation in IoT Edge Computing via Concurrent Federated Reinforcement Learning
err2022-01-15
err64
PREAI
errTianqing Zhu; Zhou, Wei; Ye, Dayong; Cheng, Zishuo; Li, Jin
errShare
errSave
Intuitive Welding Robot Programming via Motion Capture and Augmented Reality
err2019-01-01
err0
errOAAI
errFabian Mueller; Christian Deuerlein; Michael Koch
errShare
errSave
Cell-free Protein Synthesis in an Autoinduction System for NMR Studies of Protein–Protein Interactions
err2005-07-01
err0
PREAI
errKiyoshi Ozawa; Slobodan Jergic; Jeffrey A. Crowther; Phillip R. Thompson; Gene Wijffels; Gottfried Otting; Nicholas A. Dixon
errShare
errSave
err
IF0
err2022-12-02
err0
PREAI
err
errShare
errSave
researcher View more