paper-with-me

홈 › Papers

Pareto-Secure Machine Learning (PSML): Fingerprinting and Securing Inference Serving Systems

2023-07-03 · Debopam Sanyal, Jui-Tse Hung, Manav Agrawal, Prahlad Jasti, Shahab Nikkhoo, Somesh Jha, Tianhao Wang, Sibin Mohan, Alexey Tumanov

Model-serving systems have become increasingly popular, especially in real-time web applications. In such systems, users send queries to the server and specify the desired performance metrics (e.g., desired accuracy, latency). The server maintains a set of models (model zoo) in the back-end and serves the queries based on the specified metrics. This paper examines the security, specifically robustness against model extraction attacks, of such systems. Existing black-box attacks assume a single model can be repeatedly selected for serving inference requests. Modern inference serving systems break this assumption. Thus, they cannot be directly applied to extract a victim model, as models are hidden behind a layer of abstraction exposed by the serving system. An attacker can no longer identify which model she is interacting with. To this end, we first propose a query-efficient fingerprinting algorithm to enable the attacker to trigger any desired model consistently. We show that by using our fingerprinting algorithm, model extraction can have fidelity and accuracy scores within $1\%$ of the scores obtained when attacking a single, explicitly specified model, as well as up to $14.6\%$ gain in accuracy and up to $7.7\%$ gain in fidelity compared to the naive attack. Second, we counter the proposed attack with a noise-based defense mechanism that thwarts fingerprinting by adding noise to the specified performance metrics. The proposed defense strategy reduces the attack's accuracy and fidelity by up to $9.8\%$ and $4.8\%$, respectively (on medium-sized model extraction). Third, we show that the proposed defense induces a fundamental trade-off between the level of protection and system goodput, achieving configurable and significant victim model extraction protection while maintaining acceptable goodput ($>80\%$). We implement the proposed defense in a real system with plans to open source.

📄 PDF Abstract BibTeX arXiv:2307.01292

Code (0)

등록된 구현이 없습니다.

Tasks

Model extraction

Similar Papers 제목 키워드 기반

EuroCropsML: A Time Series Benchmark Dataset For Few-Shot Crop Type Classification

2024-07-24 · Joana Reuss, Jan Macdonald, Simon Becker, Lorenz Richter 외

We introduce EuroCropsML, an analysis-ready remote sensing machine learning dataset for time series crop type classification of agricultural parcels in Europe. It is the first dataset designed to benchmark transnational …

ClassificationTime Series

A Multi-scale Time-series Dataset with Benchmark for Machine Learning in Decarbonized Energy Grids

2021-10-12 · Xiangtian Zheng, Nan Xu, Loc Trinh, Dongqi Wu 외

The electric grid is a key enabling infrastructure for the ambitious transition towards carbon neutrality as we grapple with climate change. With deepening penetration of renewable energy resources and electrified transp…

Time SeriesTime Series Analysis

Reconfigurable Intelligent Surfaces and Machine Learning for Wireless Fingerprinting Localization

2020-10-07 · Cam Ly Nguyen, Orestis Georgiou, Gabriele Gradoni

Reconfigurable Intelligent Surfaces (RISs) promise improved, secure and more efficient wireless communications. We propose and demonstrate how to exploit the diversity offered by RISs to generate and select easily differ…

BIG-bench Machine LearningDiversityfeature selectionPosition

Low-Complexity Methods for Estimation After Parameter Selection

2020-01-28

Statistical inference of multiple parameters often involves a preliminary parameter selection stage. The selection stage has an impact on subsequent estimation, for example by introducing a selection bias. The post-selec…

Selection bias

Parallel Stroked Multi Line: a model-based method for compressing large fingerprint databases

2016-01-10 · Hamid Mansouri, Hamid-Reza Pourreza

With increasing usage of fingerprints as an important biometric data, the need to compress the large fingerprint databases has become essential. The most recommended compression algorithm, even by standards, is JPEG2K. B…