Detection of Cloned Recognizers: A Defending Method against Recognizer Cloning Attack
Detection of Cloned Recognizers: A Defending Method against Recognizer Cloning Attack
复制标题
DOI:
--
复制
发表时间:
2020-12
期刊:
影响因子:
--
通讯作者:
Y. Mori;Kazuaki Nakamura;Naoko Nitta;N. Babaguchi
中科院分区:
文献类型:
--
作者:
Y. Mori;Kazuaki Nakamura;Naoko Nitta;N. Babaguchi
With the development of machine learning technologies and the spread of mobile terminals, cloud-based image recognition services are getting popular in recent years. However, these services might suffer from a new type of attack called “recognizer cloning attack” (RCA), in which an attacker sends a lot of images to a recognition server and receives their recognition results to train a new recognizer that mimics the function of the server’s original recognizer. We refer to the recognizers trained by RCA as “cloned recognizers” (CR). CRs allow attackers to analyze the weakness of their original recognizer and cause serious damage to the providers of the original service. To defend against RCA, we propose a method for detecting CRs in this paper. Our proposed method receives two recognizers as input and discriminates whether one of them is a CR of the other or not. We experimentally analyzed the properties of CRs and got the following two findings. First, CR and its original recognizer have the almost same recognition boundary. Second, CR provides a recognition confidence score that is almost same or quite higher than that provided by the original recognizer. Using these properties as clues, the proposed method was able to detect CRs with an accuracy of more than 80% in our experiments.