Exploring Connections Between Active Learning and Model Extraction

Exploring Connections Between Active Learning and Model Extraction
复制标题

DOI:
--
复制
发表时间:
2018-11
期刊:
--
影响因子:
--
通讯作者:
Varun Chandrasekaran;Kamalika Chaudhuri;Irene Giacomelli;S. Jha;Songbai Yan
Varun Chandrasekaran;Kamalika Chaudhuri;Irene Giacomelli;S. Jha;Songbai Yan
中科院分区:
其他
文献类型:
--
作者:
Varun Chandrasekaran;Kamalika Chaudhuri;Irene Giacomelli;S. Jha;Songbai Yan

文献摘要

被引文献

相似文献

个人,研究机构和公司正在越来越多地使用机器学习。这导致了机器学习的激增-As-a-Service(MLAAS) - 提供(a)学习模型的工具和资源的云服务,以及(b)用户友好的查询接口以访问模型。但是,此类MLAAS系统引起了隐私问题,例如模型提取。在模型提取攻击中,对手恶意利用查询接口窃取模型。更确切地说,在模型提取攻击中,不诚实的用户仅通过查询接口与服务器进行交互,从而提取了服务器持有的敏感或专有模型的良好近似值(即学习)。 Tramer等人引入了这种攻击。在2016年USENIX安全研讨会上,显示了各种模型的实际攻击。我们认为,更好地了解模型提取攻击的功效对于设计安全的MLAAS系统至关重要。为此,我们迈出了(a)形式化模型提取并讨论可能的防御策略,以及(b)在模型提取和积极学习的既定领域之间进行相似之处。特别是,我们表明,活跃学习领域的最新进展可用于实施强大的模型提取攻击,并研究可能的防御策略。
Machine learning is being increasingly used by individuals, research institutions, and corporations. This has resulted in the surge of Machine Learning-as-a-Service (MLaaS) - cloud services that provide (a) tools and resources to learn the model, and (b) a user-friendly query interface to access the model. However, such MLaaS systems raise privacy concerns such as model extraction. In model extraction attacks, adversaries maliciously exploit the query interface to steal the model. More precisely, in a model extraction attack, a good approximation of a sensitive or proprietary model held by the server is extracted (i.e. learned) by a dishonest user who interacts with the server only via the query interface. This attack was introduced by Tramer et al. at the 2016 USENIX Security Symposium, where practical attacks for various models were shown. We believe that better understanding the efficacy of model extraction attacks is paramount to designing secure MLaaS systems. To that end, we take the first step by (a) formalizing model extraction and discussing possible defense strategies, and (b) drawing parallels between model extraction and established area of active learning. In particular, we show that recent advancements in the active learning domain can be used to implement powerful model extraction attacks, and investigate possible defense strategies.