Marich: A Query-efficient Distributionally Equivalent Model Extraction Attack
Pratik Karmakar, Debabrota Basu
Abstract
We study design of black-box model extraction attacks that can send minimal number of queries from a publicly available dataset to a target ML model through a predictive API with an aim to create an informative and distributionally equivalent replica of the target. First, we define distributionally equivalent and Max-Information model extraction attacks, and reduce them into a variational optimisation problem. The attacker sequentially solves this optimisation problem to select the most informative queries that simultaneously maximise the entropy and reduce the mismatch between the target and the stolen models. This leads to an active sampling-based query selection algorithm, MARICH, which is model-oblivious. Then, we evaluate MARICH on different text and image data sets, and different models, including CNNs and BERT. MARICH extracts models that achieve ∼ 60 -95% of true model's accuracy and uses ∼ 1, 000 -8, 500 queries from the publicly available datasets, which are different from the private training datasets. Models extracted by MARICH yield prediction distributions, which are ∼ 2 -4× closer to the target's distribution in comparison to the existing active sampling-based attacks. The extracted models also lead to 84-96% accuracy under membership inference attacks. Experimental results validate that MARICH is query-efficient, and capable of performing task-accurate, high-fidelity, and informative model extraction. * A significant portion of the work has been done as a part of P. Karmakar's masters in Ramakrishna Mission
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3cf6f930-17fc-4774-bdb0-0eb8ce477a63Cited by top-tier papers1
Ask how each one uses itBuilds on16
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter et al.USENIX Security 2016 · 2,088 citations
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 1,778 citations
- Coresets for Data-efficient Training of Machine Learning ModelsBaharan Mirzasoleiman, Jeff A. Bilmes, Jure LeskovecICML 2020 · 494 citations
Related papers
- MeaeQ: Mount Model Extraction Attacks with Efficient QueriesChengwei Dai, Minxuan Lv, Kun Li, Wei ZhouEMNLP 2023 · 4 citations
- ActiveThief: Model Extraction Using Active Learning and Unannotated Public DataSoham Pal, Yash Gupta, Aditya Shukla, Aditya Kanade et al.AAAI 2020 · 164 citations
- Thieves on Sesame Street! Model Extraction of BERT-based APIsKalpesh Krishna, Gaurav Singh Tomar, Ankur P. Parikh, Nicolas Papernot et al.ICLR 2020 · 244 citations
- DRMI: A Dataset Reduction Technology based on Mutual Information for Black-box AttacksYingzhe He, Guozhu Meng, Kai Chen, Xingbo Hu et al.USENIX Security 2021 · 28 citations
- MExMI: Pool-based Active Model Extraction Crossover Membership InferenceYaxin Xiao, Qingqing Ye, Haibo Hu, Huadi Zheng et al.NeurIPS 2022 · 17 citations
