Lune

NeurIPS2023顶会

Marich: A Query-efficient Distributionally Equivalent Model Extraction Attack

Pratik Karmakar, Debabrota Basu

2023年份
11被引次数
1顶会引用

摘要

We study design of black-box model extraction attacks that can send minimal number of queries from a publicly available dataset to a target ML model through a predictive API with an aim to create an informative and distributionally equivalent replica of the target. First, we define distributionally equivalent and Max-Information model extraction attacks, and reduce them into a variational optimisation problem. The attacker sequentially solves this optimisation problem to select the most informative queries that simultaneously maximise the entropy and reduce the mismatch between the target and the stolen models. This leads to an active sampling-based query selection algorithm, MARICH, which is model-oblivious. Then, we evaluate MARICH on different text and image data sets, and different models, including CNNs and BERT. MARICH extracts models that achieve ∼ 60 -95% of true model's accuracy and uses ∼ 1, 000 -8, 500 queries from the publicly available datasets, which are different from the private training datasets. Models extracted by MARICH yield prediction distributions, which are ∼ 2 -4× closer to the target's distribution in comparison to the existing active sampling-based attacks. The extracted models also lead to 84-96% accuracy under membership inference attacks. Experimental results validate that MARICH is query-efficient, and capable of performing task-accurate, high-fidelity, and informative model extraction. * A significant portion of the work has been done as a part of P. Karmakar's masters in Ramakrishna Mission

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper1

问问它们各自怎么用它

它引用的顶会 Paper16

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖