USENIX Security2021Top-tier venue
DRMI: A Dataset Reduction Technology based on Mutual Information for Black-box Attacks
Yingzhe He, Guozhu Meng, Kai Chen, Xingbo Hu, Jinwen He
Abstract
It is non-trivial to attack deep neural networks in black-box settings without any model detail disclosed. Prior studies on black-box attacks leverage a number of queries to the target model for probing the target model or generating adversarial examples. Queries are usually limited and costly so that the adversary probably fails to mount an effective attack. However, not all the queries have to be made since there exist repetitions or redundancies that induce many inefficient queries. Therefore, it leaves a lot of room for data reduction and more efficient queries. To this end, we first propose to use mutual information to measure the data redundancy between two data samples, and then develop a data reduction technique based on mutual information, termed as DRMI. We implement an efficient optimization algorithm in DRMI, so as to obtain a particular subset of data samples, of which the mutual information in between is minimized. We conduct extensive experiments on MNIST, CIFAR10, and ImageNet, and six types of deep neural networks, and evaluate DRMI in model extraction and adversarial attacks. The results demonstrate its high effectiveness in these attacks, surpassing a state-of-the-art approach by raising 7% of model accuracy and two times more transferability of adversarial examples. Through the comparison experiments with other three strategies, we identify what properties of data have been preserved and removed, to some extent reveal the essences of deep neural networks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b2c26d39-49e4-4c68-b7a4-dd70af6503c3Cited by top-tier papers8
- Understanding Real-world Threats to Deep Learning Models in Android AppsZizhuang Deng, Kai Chen, Guozhu Meng, Xiaodong Zhang et al.CCS 2022 · 29 citations
- Demystifying RCE Vulnerabilities in LLM-Integrated AppsTong Liu, Zizhuang Deng, Guozhu Meng, Yuekang Li et al.CCS 2024 · 19 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- BadPart: Unified Black-box Adversarial Patch Attacks against Pixel-wise Regression TasksZhiyuan Cheng, Zhaoyi Liu, Tengda Guo, Shiwei Feng et al.ICML 2024 · 10 citations
- MeaeQ: Mount Model Extraction Attacks with Efficient QueriesChengwei Dai, Minxuan Lv, Kun Li, Wei ZhouEMNLP 2023 · 4 citations
Builds on14
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter et al.USENIX Security 2016 · 2,088 citations
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu et al.S&P 2018 · 867 citations
- Property Inference Attacks on Fully Connected Neural Networks using Permutation Invariant RepresentationsKaran Ganju, Qi Wang, Wei Yang, Carl A. Gunter et al.CCS 2018 · 574 citations
Related papers
- Query-efficient Meta Attack to Deep Neural NetworksJiawei Du, Hu Zhang, Joey Tianyi Zhou, Yi Yang et al.ICLR 2020 · 87 citations
- Black-Box Adversarial Attack with Transferable Model-based EmbeddingZhichao Huang, Tong ZhangICLR 2020 · 131 citations
- MGAAttack: Toward More Query-efficient Black-box Attack by Microbial Genetic AlgorithmLina Wang, Kang Yang, Wenqi Wang, Run Wang et al.ACM MM 2020 · 9 citations
- Data-Free Model ExtractionJean-Baptiste Truong, Pratyush Maini, Robert J. Walls, Nicolas PapernotCVPR 2021
- Blurred-Dilated Method for Adversarial AttacksYang Deng, Weibin Wu, Jianping Zhang, Zibin ZhengNeurIPS 2023 · 10 citations
