paper-with-me

홈 › Papers

Army of Thieves: Enhancing Black-Box Model Extraction via Ensemble based sample selection

2023-11-08 · Akshit Jindal, Vikram Goyal, Saket Anand, Chetan Arora

Machine Learning (ML) models become vulnerable to Model Stealing Attacks (MSA) when they are deployed as a service. In such attacks, the deployed model is queried repeatedly to build a labelled dataset. This dataset allows the attacker to train a thief model that mimics the original model. To maximize query efficiency, the attacker has to select the most informative subset of data points from the pool of available data. Existing attack strategies utilize approaches like Active Learning and Semi-Supervised learning to minimize costs. However, in the black-box setting, these approaches may select sub-optimal samples as they train only one thief model. Depending on the thief model's capacity and the data it was pretrained on, the model might even select noisy samples that harm the learning process. In this work, we explore the usage of an ensemble of deep learning models as our thief model. We call our attack Army of Thieves(AOT) as we train multiple models with varying complexities to leverage the crowd's wisdom. Based on the ensemble's collective decision, uncertain samples are selected for querying, while the most confident samples are directly included in the training data. Our approach is the first one to utilize an ensemble of thief models to perform model extraction. We outperform the base approaches of existing state-of-the-art methods by at least 3% and achieve a 21% higher adversarial sample transferability than previous work for models trained on the CIFAR-10 dataset.

📄 PDF Abstract BibTeX arXiv:2311.04588

Code (1)

akshitjindal1/aot_wacv 공식 구현 pytorch

Tasks

Active LearningAdversarial AttackModel extraction

Methods 이 논문이 사용한 방법론

Golden Queue Managers 설명 없음
BASE 설명 없음

Similar Papers 제목 키워드 기반

Mechanism Design meets Priority Design: Redesigning the US Army's Branching Process

2021-06-11 · Kyle Greenberg, Parag A. Pathak, Tayfun Sonmez

Army cadets obtain occupations through a centralized process. Three objectives -- increasing retention, aligning talent, and enhancing trust -- have guided reforms to this process since 2006. West Point's mechanism for t…

Redesigning the US Army's Branching Process: A Case Study in Minimalist Market Design

2023-03-12 · Kyle Greenberg, Parag A. Pathak, Tayfun Sönmez

We present the proof-of-concept for minimalist market design (S\"{o}nmez, 2023) as an effective methodology to enhance an institution based on the desiderata of stakeholders with minimal interference. Four objectives-res…

Watercraft as Overwater Ambulance Exchange Points to Enhance Aeromedical Evacuation

2024-08-25 · Mahdi Al-Husseini, Kyle H. Wray, Mykel J. Kochenderfer

Ambulance exchange points are preidentified sites where patients are transferred between evacuation platforms while en route to enhanced medical care. We propose a new capability for maritime medical evacuation, which in…

The Thieves on Sesame Street are Polyglots - Extracting Multilingual Models from Monolingual APIs

2020-11-01 · EMNLP 2020 11 · Nitish Shirish Keskar, Bryan McCann, Caiming Xiong, Richard Socher

Pre-training in natural language processing makes it easier for an adversary with only query access to a victim model to reconstruct a local copy of the victim by training with gibberish input data paired with the victim…

Thieves on Sesame Street! Model Extraction of BERT-based APIs

2019-10-27 · ICLR 2020 1 · Kalpesh Krishna, Gaurav Singh Tomar, Ankur P. Parikh, Nicolas Papernot 외

We study the problem of model extraction in natural language processing, in which an adversary with only query access to a victim model attempts to reconstruct a local copy of that model. Assuming that both the adversary…

Language ModelingLanguage ModellingModel extractionNatural Language Inference+2