Analyzing the Confidentiality of Undistillable Teachers in Knowledge Distillation
Souvik Kundu, Qirui Sun, Yao Fu, Massoud Pedram, Peter A. Beerel
Abstract
Knowledge distillation (KD) has recently been identified as a method that can unintentionally leak private information regarding the details of a teacher model to an unauthorized student. Recent research in developing undistillable nasty teachers that can protect model confidentiality has gained significant attention. However, the level of protection these nasty models offer has been largely untested. In this paper, we show that transferring knowledge to a shallow sub-section of a student can largely reduce a teacher's influence. By exploring the depth of the shallow subsection, we then present a distillation technique that enables a skeptical student model to learn even from a nasty teacher. To evaluate the efficacy of our skeptical students, we conducted experiments with several models with KD under both training data-available and data-free scenarios for various datasets. While distilling from nasty teachers, compared to the normal student models, skeptical students consistently provide superior classification performance of up to ∼59.5%. Moreover, similar to normal students, skeptical students maintain high classification accuracy when distilled from a normal teacher, showing their efficacy irrespective of the teacher being nasty or not. We believe the ability of skeptical students to largely diminish the KD-immunity of a potentially nasty teacher will motivate the research community to create more robust mechanisms for model confidentiality. We have open-sourced the code at github.com/ksouvik52/Skeptical2021.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f4e26728-bb52-42ac-b60a-c33515ec824bCited by top-tier papers9
- Knowledge Diffusion for DistillationTao Huang, Yuan Zhang, Mingkai Zheng, Shan You et al.NeurIPS 2023 · 125 citations
- SAL-ViT: Towards Latency Efficient Private Inference on ViT using Selective Attention Search with a Learnable Softmax ApproximationYuke Zhang, Dake Chen, Souvik Kundu, Chenghao Li et al.ICCV 2023 · 30 citations
- FedDefender: Client-Side Attack-Tolerant Federated LearningSungwon Park, Sungwon Han, Fangzhao Wu, Sundong Kim et al.KDD 2023 · 26 citations
- C2PI: An Efficient Crypto-Clear Two-Party Neural Network Private InferenceYuke Zhang, Dake Chen, Souvik Kundu, Haomei Liu et al.DAC 2023 · 7 citations
- HYDRA-FL: Hybrid Knowledge Distillation for Robust and Accurate Federated LearningMomin Ahmad Khan, Yasra Chandio, Fatima M. AnwarNeurIPS 2024 · 5 citations
Builds on13
- Improved Knowledge Distillation via Teacher AssistantSeyed-Iman Mirzadeh, Mehrdad Farajtabar, Ang Li, Nir Levine et al.AAAI 2020 · 1,361 citations
- Be Your Own Teacher: Improve the Performance of Convolutional Neural Networks via Self DistillationLinfeng Zhang, Jiebo Song, Anni Gao, Jingwei Chen et al.ICCV 2019 · 1,069 citations
- Data-Free Learning of Student NetworksHanting Chen, Yunhe Wang, Chang Xu, Zhaohui Yang et al.ICCV 2019 · 427 citations
- Bit-Flip Attack: Crushing Neural Network With Progressive Bit SearchAdnan Siraj Rakin, Zhezhi He, Deliang FanICCV 2019 · 309 citations
- HIRE-SNN: Harnessing the Inherent Robustness of Energy-Efficient Deep Spiking Neural Networks by Training with Crafted Input NoiseSouvik Kundu, Massoud Pedram, Peter A. BeerelICCV 2021 · 114 citations
Related papers
- Undistillable: Making A Nasty Teacher That CANNOT teach studentsHaoyu Ma, Tianlong Chen, Ting-Kuei Hu, Chenyu You et al.ICLR 2021 · 58 citations
- Teach Less, Learn More: On the Undistillable Classes in Knowledge DistillationYichen Zhu, Ning Liu, Zhiyuan Xu, Xin Liu et al.NeurIPS 2022 · 42 citations
- On the Impact of Knowledge Distillation for Model InterpretabilityHyeongrok Han, Siwon Kim, Hyun-Soo Choi, Sungroh YoonICML 2023 · 13 citations
- Knowledge Distillation as Decontamination? Revisiting the "Data Laundering" Concern in Classification TasksHengyu Luo, Raúl Vázquez, Timothee Mickus, Filip Ginter et al.ICLR 2026
- Adversarially Robust DistillationMicah Goldblum, Liam Fowl, Soheil Feizi, Tom GoldsteinAAAI 2020 · 258 citations
