Detection of Cloned Recognizers: A Defending Method against Recognizer Cloning Attack

Detection of Cloned Recognizers: A Defending Method against Recognizer Cloning Attack
复制标题

DOI:
--
复制
发表时间:
2020-12
期刊:
2020 Asia-Pacific Signal and Information Processing Association Annual Summit and Conference (APSIPA ASC)
影响因子:
--
通讯作者:
Y. Mori;Kazuaki Nakamura;Naoko Nitta;N. Babaguchi
Y. Mori;Kazuaki Nakamura;Naoko Nitta;N. Babaguchi
中科院分区:
其他
文献类型:
--
作者:
Y. Mori;Kazuaki Nakamura;Naoko Nitta;N. Babaguchi

文献摘要

相似文献

随着机器学习技术的开发和移动终端的传播,基于云的图像识别服务近年来越来越受欢迎。攻击者将许多图像发送到识别服务器,并收到其识别结果,以训练一个模仿服务器原始识别器功能的新识别器允许攻击者分析其原始识别者的弱点,并对原始服务的提供者造成严重损害,以防止RCA,我们提出了一种检测CRS的方法。它们是另一个的CR,我们通过实验性地分析了CR的性质,并获得了以下两个发现。相同或相当高于原始识别器提供的线索,该方法在我们的实验中可以准确地检测到CRS的精度超过80%。
With the development of machine learning technologies and the spread of mobile terminals, cloud-based image recognition services are getting popular in recent years. However, these services might suffer from a new type of attack called “recognizer cloning attack” (RCA), in which an attacker sends a lot of images to a recognition server and receives their recognition results to train a new recognizer that mimics the function of the server’s original recognizer. We refer to the recognizers trained by RCA as “cloned recognizers” (CR). CRs allow attackers to analyze the weakness of their original recognizer and cause serious damage to the providers of the original service. To defend against RCA, we propose a method for detecting CRs in this paper. Our proposed method receives two recognizers as input and discriminates whether one of them is a CR of the other or not. We experimentally analyzed the properties of CRs and got the following two findings. First, CR and its original recognizer have the almost same recognition boundary. Second, CR provides a recognition confidence score that is almost same or quite higher than that provided by the original recognizer. Using these properties as clues, the proposed method was able to detect CRs with an accuracy of more than 80% in our experiments.