Transfer Learning without Knowing: Reprogramming Black-box Machine Learning Models with Scarce Data and Limited Resources
Yun-Yun Tsai, Pin-Yu Chen, Tsung-Yi Ho
Abstract
Current transfer learning methods are mainly based on finetuning a pretrained model with target-domain data. Motivated by the techniques from adversarial machine learning (ML) that are capable of manipulating the model prediction via data perturbations, in this paper we propose a novel approach, black-box adversarial reprogramming (BAR), that repurposes a well-trained black-box ML model (e.g., a prediction API or a proprietary software) for solving different ML tasks, especially in the scenario with scarce data and constrained resources. The rationale lies in exploiting high-performance but unknown ML models to gain learning capability for transfer learning. Using zeroth order optimization and multi-label mapping techniques, BAR can reprogram a black-box ML model solely based on its input-output responses without knowing the model architecture or changing any parameter. More importantly, in the limited medical data setting, on autism spectrum disorder classification, diabetic retinopathy detection, and melanoma detection tasks, BAR outperforms state-of-the-art methods and yields comparable performance to the vanilla adversarial reprogramming method requiring complete knowledge of the target ML model. BAR also outperforms baseline transfer learning approaches by a significant margin, demonstrating cost-effective means and new insights for transfer learning.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9bf6c12e-5999-4845-beea-fe31f812cd21Cited by top-tier papers44
- Voice2Series: Reprogramming Acoustic Models for Time Series ClassificationChao-Han Huck Yang, Yun-Yun Tsai, Pin-Yu ChenICML 2021 · 150 citations
- Revisiting Zeroth-Order Optimization for Memory-Efficient LLM Fine-Tuning: A BenchmarkYihua Zhang, Pingzhi Li, Junyuan Hong, Jiaxiang Li et al.ICML 2024 · 134 citations
- DeepZero: Scaling Up Zeroth-Order Optimization for Deep Model TrainingAochuan Chen, Yimeng Zhang, Jinghan Jia, James Diffenderfer et al.ICLR 2024 · 88 citations
- Understanding and Mitigating the Label Noise in Pre-training on Downstream TasksHao Chen, Jindong Wang, Ankit Shah, Ran Tao et al.ICLR 2024 · 49 citations
- Fairness ReprogrammingGuanhua Zhang, Yihua Zhang, Yang Zhang, Wenqi Fan et al.NeurIPS 2022 · 46 citations
Builds on2
Related papers
- Few-Shot Learning via Repurposing Ensemble of Black-Box ModelsMinh Hoang, Trong Nghia HoangAAAI 2024 · 5 citations
- Black-Box Ripper: Copying black-box models using generative evolutionary algorithmsAntonio Barbalau, Adrian Cosma, Radu Tudor Ionescu, Marius PopescuNeurIPS 2020 · 54 citations
- WARP: Word-level Adversarial ReProgrammingKaren Hambardzumyan, Hrant Khachatrian, Jonathan MayACL 2021
- Training Spatial-Frequency Visual Prompts and Probabilistic Clusters for Accurate Black-Box Transfer LearningWonwoo Cho, Kangyeol Kim, Saemee Choi, Jaegul ChooACM MM 2024
- Black-Box Adversarial Attack with Transferable Model-based EmbeddingZhichao Huang, Tong ZhangICLR 2020 · 131 citations
