paper-with-me

홈 › Papers

A Framework for Understanding Model Extraction Attack and Defense

2022-06-23 · Xun Xian, Mingyi Hong, Jie Ding

The privacy of machine learning models has become a significant concern in many emerging Machine-Learning-as-a-Service applications, where prediction services based on well-trained models are offered to users via pay-per-query. The lack of a defense mechanism can impose a high risk on the privacy of the server's model since an adversary could efficiently steal the model by querying only a few good' data points. The interplay between a server's defense and an adversary's attack inevitably leads to an arms race dilemma, as commonly seen in Adversarial Machine Learning. To study the fundamental tradeoffs between model utility from a benign user's view and privacy from an adversary's view, we develop new metrics to quantify such tradeoffs, analyze their theoretical properties, and develop an optimization problem to understand the optimal adversarial attack and defense strategies. The developed concepts and theory match the empirical findings on the equilibrium' between privacy and utility. In terms of optimization, the key ingredient that enables our results is a unified representation of the attack-defense problem as a min-max bi-level problem. The developed results will be demonstrated by examples and experiments.

📄 PDF Abstract BibTeX arXiv:2206.11480

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial AttackBIG-bench Machine LearningModel extraction

Similar Papers 제목 키워드 기반

Exploring Connections Between Active Learning and Model Extraction

2018-11-05 · Varun Chandrasekaran, Kamalika Chaudhuri, Irene Giacomelli, Somesh Jha 외

Machine learning is being increasingly used by individuals, research institutions, and corporations. This has resulted in the surge of Machine Learning-as-a-Service (MLaaS) - cloud services that provide (a) tools and res…

Active LearningBIG-bench Machine LearningmodelModel extraction

An APT Event Extraction Method Based on BERT-BiGRU-CRF for APT Attack Detection

2023-08-04 · Electronics 2023 8 · Ga Xiang, Chen Shi, Yangsen Zhang

Advanced Persistent Threat (APT) seriously threatens a nation’s cyberspace security. Current defense technologies are typically unable to detect it effectively since APT attack is complex and the signatures for detection…

Event Extraction

Train to Defend: First Defense Against Cryptanalytic Neural Network Parameter Extraction Attacks

2025-09-20 · Ashley Kurian, Aydin Aysu arxiv

Neural networks are valuable intellectual property due to the significant computational cost, expert labor, and proprietary data involved in their development. Consequently, protecting their parameters is critical not on…

Thief, Beware of What Get You There: Towards Understanding Model Extraction Attack

2021-04-13 · Xinyi Zhang, Chengfang Fang, Jie Shi

Model extraction increasingly attracts research attentions as keeping commercial AI models private can retain a competitive advantage. In some scenarios, AI models are trained proprietarily, where neither pre-trained mod…

Deep Reinforcement LearningModel extraction

Raccoon: Prompt Extraction Benchmark of LLM-Integrated Applications

2024-06-10 · Junlin Wang, Tianyi Yang, Roy Xie, Bhuwan Dhingra

With the proliferation of LLM-integrated applications such as GPT-s, millions are deployed, offering valuable services through proprietary instruction prompts. These systems, however, are prone to prompt extraction attac…