Beowulf: Mitigating Model Extraction Attacks Via Reshaping Decision Regions
Xueluan Gong, Rubin Wei, Ziyao Wang, Yuchen Sun, Jiawen Peng, Yanjiao Chen, Qian Wang
Abstract
Machine Learning as a Service (MLaaS) enables resource-constrained users to access well-trained models through a publicly accessible Application Programming Interface (API) on a pay-per-query basis.Nevertheless, model owners may face the potential threats of model extraction attacks where malicious users replicate valuable commercial models based on query results.Existing defenses against model extraction attacks, however, either sacrifice prediction accuracy or fail to thwart more advanced attacks.In this paper, we propose a novel model extraction defense, dubbed Beowulf 1 , which draws inspiration from theoretical findings that models with complex and narrow decision regions are difficult to be reproduced.Rather than arbitrarily altering decision regions, which may jeopardize the predictive capacity of the victim model, we introduce a dummy class, carefully synthesized using both random and adversarial noises.The random noise broadens the coverage of the dummy class, and the adversarial noise impacts decision regions near decision boundaries with normal classes.To further improve the model utility, we propose to employ data augmentation methods to seamlessly integrate the dummy class and the normal classes.Extensive evaluations on CIFAR-10, GTSRB, CIFAR-100, and ImageNette datasets * Yanjiao Chen and Qian Wang are corresponding authors. 1 In Anglo-Saxon literature and mythology, "Beowulf" is a heroic figure known for his strength and bravery, defending the kingdom against monsters in an epic tale.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 52eb3eae-0e32-4d95-a2d6-bdabdb3d1facCited by top-tier papers2
- TensorShield: Safeguarding On-Device Inference by Shielding Critical DNN Tensors with TEETong Sun, Bowen Jiang, Hailong Lin, Borui Li et al.CCS 2025 · 3 citations
- Dataset Reduction and Watermark Removal via Self-supervised Learning for Model Extraction AttackHao Luan, Xue Tan, Zhiheng Li, Jun Dai et al.NDSS 2026 · 1 citation
Related papers
- ModelGuard: Information-Theoretic Defense Against Model Extraction AttacksMinxue Tang, Anna Dai, Louis DiValentin, Aolin Ding et al.USENIX Security 2024 · 28 citations
- SAME: Sample Reconstruction against Model Extraction AttacksYi Xie, Jie Zhang, Shiqian Zhao, Tianwei Zhang et al.AAAI 2024 · 6 citations
- Exploring Connections Between Active Learning and Model ExtractionVarun Chandrasekaran, Kamalika Chaudhuri, Irene Giacomelli, Somesh Jha et al.USENIX Security 2020
- Extracting Robust Models with Uncertain ExamplesGuanlin Li, Guowen Xu, Shangwei Guo, Han Qiu et al.ICLR 2023
- D-DAE: Defense-Penetrating Model Extraction AttacksYanjiao Chen, Rui Guan, Xueluan Gong, Jianshuo Dong et al.S&P 2023
