ES Attack: Model Stealing Against Deep Neural Networks Without Data Hurdles

ES Attack: Model Stealing Against Deep Neural Networks Without Data Hurdles
复制标题

DOI:
10.1109/tetci.2022.3147508
复制
发表时间:
2020-09
影响因子:
5.3
通讯作者:
Xiaoyong Yuan;Lei Ding;Lan Zhang;Xiaolin Li;D. Wu
Xiaoyong Yuan;Lei Ding;Lan Zhang;Xiaolin Li;D. Wu
中科院分区:
计算机科学2区
文献类型:
--
作者:
Xiaoyong Yuan;Lei Ding;Lan Zhang;Xiaolin Li;D. Wu

文献摘要

被引文献

相似文献

深度神经网络(DNN)已经成为各种商业化机器学习服务的重要组成部分,如机器学习即服务(MLaaS)。最近的研究表明,机器学习服务面临着严重的隐私威胁--MLaaS提供商拥有的训练有素的DNN可以通过公共API被窃取,即模型窃取攻击。然而,大多数现有的工作低估了这种攻击的影响,在这种攻击中,成功的攻击必须获得关于受害者DNN的机密训练数据或辅助数据。在本文中,我们提出了一种新的无数据障碍的盗窃攻击模型ES攻击。通过使用启发式生成的合成数据,ES攻击迭代地训练替代模型,最终获得受害者DNN的功能等价副本。实验结果揭示了ES攻击的严重性:i)ES攻击在没有数据障碍的情况下成功窃取了受害者模型,在模型准确性方面甚至超过了现有的大多数使用辅助数据的模型窃取攻击;ii)大多数对策对ES攻击的防御都是无效的;iii)ES攻击为依赖于被盗模型的进一步攻击提供了便利。
Deep neural networks (DNNs) have become the essential components for various commercialized machine learning services, such as Machine Learning as a Service (MLaaS). Recent studies show that machine learning services face severe privacy threats - well-trained DNNs owned by MLaaS providers can be stolen through public APIs, namely model stealing attacks. However, most existing works undervalued the impact of such attacks, where a successful attack has to acquire confidential training data or auxiliary data regarding the victim DNN. In this paper, we propose ES Attack, a novel model stealing attack without any data hurdles. By using heuristically generated synthetic data, ES Attack iteratively trains a substitute model and eventually achieves a functionally equivalent copy of the victim DNN. The experimental results reveal the severity of ES Attack: i) ES Attack successfully steals the victim model without data hurdles, and ES Attack even outperforms most existing model stealing attacks using auxiliary data in terms of model accuracy; ii) most countermeasures are ineffective in defending ES Attack; iii) ES Attack facilitates further attacks relying on the stolen model.