paper-with-me

홈 › Papers

Teacher Model Fingerprinting Attacks Against Transfer Learning

2021-06-23 · Yufei Chen, Chao Shen, Cong Wang, Yang Zhang

Transfer learning has become a common solution to address training data scarcity in practice. It trains a specified student model by reusing or fine-tuning early layers of a well-trained teacher model that is usually publicly available. However, besides utility improvement, the transferred public knowledge also brings potential threats to model confidentiality, and even further raises other security and privacy issues. In this paper, we present the first comprehensive investigation of the teacher model exposure threat in the transfer learning context, aiming to gain a deeper insight into the tension between public knowledge and model confidentiality. To this end, we propose a teacher model fingerprinting attack to infer the origin of a student model, i.e., the teacher model it transfers from. Specifically, we propose a novel optimization-based method to carefully generate queries to probe the student model to realize our attack. Unlike existing model reverse engineering approaches, our proposed fingerprinting method neither relies on fine-grained model outputs, e.g., posteriors, nor auxiliary information of the model architecture or training dataset. We systematically evaluate the effectiveness of our proposed attack. The empirical results demonstrate that our attack can accurately identify the model origin with few probing queries. Moreover, we show that the proposed attack can serve as a stepping stone to facilitating other attacks against machine learning models, such as model stealing.

📄 PDF Abstract BibTeX arXiv:2106.12478

Code (2)

yfchen1994/teacher-fingerprinting 공식 구현 pytorch
yaoplusplus/Teacher-Model-fingerprint pytorch

Tasks

modelTransfer Learning

Similar Papers 제목 키워드 기반

Attacks and Defenses Against LLM Fingerprinting

2025-08-12 · Kevin Kurian, Ethan Holland, Sean Oesch arxiv

As large language models are increasingly deployed in sensitive environments, fingerprinting attacks pose significant privacy and security risks. We present a study of LLM fingerprinting from both offensive and defensive…

Reinforcement Learning

Deep Neural Network Fingerprinting by Conferrable Adversarial Examples

2019-12-02 · ICLR 2021 1 · Nils Lukas, Yuxuan Zhang, Florian Kerschbaum

In Machine Learning as a Service, a provider trains a deep neural network and gives many users access. The hosted (source) model is susceptible to model stealing attacks, where an adversary derives a surrogate model from…

Model extractionTransfer Learning

Rethinking Membership Inference Attacks Against Transfer Learning

2025-01-20 · Cong Wu, Jing Chen, Qianru Fang, Kun He 외

Transfer learning, successful in knowledge translation across related tasks, faces a substantial privacy threat from membership inference attacks (MIAs). These attacks, despite posing significant risk to ML model's train…

Transfer Learning

Model Inversion Attack against Transfer Learning: Inverting a Model without Accessing It

2022-03-13 · Dayong Ye, Huiqiang Chen, Shuai Zhou, Tianqing Zhu 외

Transfer learning is an important approach that produces pre-trained teacher models which can be used to quickly build specialized student models. However, recent research on transfer learning has found that it is vulner…

modelTransfer Learning

Robust Eavesdropping in the Presence of Adversarial Communications for RF Fingerprinting

2025-03-06 · Andrew Yuan, Rajeev Sahay

Deep learning is an effective approach for performing radio frequency (RF) fingerprinting, which aims to identify the transmitter corresponding to received RF signals. However, beyond the intended receiver, malicious eav…

Deep Learning