Zero-Shot Knowledge Distillation from a Decision-Based Black-Box Model
Zi Wang
摘要
Knowledge distillation (KD) is a successful approach for deep neural network acceleration, with which a compact network (student) is trained by mimicking the softmax output of a pre-trained high-capacity network (teacher). In tradition, KD usually relies on access to the training samples and the parameters of the white-box teacher to acquire the transferred knowledge. However, these prerequisites are not always realistic due to storage costs or privacy issues in real-world applications. Here we propose the concept of decisionbased black-box (DB3) knowledge distillation, with which the student is trained by distilling the knowledge from a black-box teacher (parameters are not accessible) that only returns classes rather than softmax outputs. We start with the scenario when the training set is accessible. We represent a sample's robustness against other classes by computing its distances to the teacher's decision boundaries and use it to construct the soft label for each training sample. After that, the student can be trained via standard KD. We then extend this approach to a more challenging scenario in which even accessing the training data is not feasible. We propose to generate pseudo samples distinguished by the teacher's decision boundaries to the largest extent and construct soft labels for them, which are used as the transfer set. We evaluate our approaches on various benchmark networks and datasets and experiment results demonstrate their effectiveness. Codes are available at: https://github.com/zwang84/zsdb3kd .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- Towards Data-Free Model Stealing in a Hard Label SettingSunandini Sanyal, Sravanti Addepalli, R. Venkatesh BabuCVPR 2022 · 被引用 76 次
- Defending against Data-Free Model Extraction by Distributionally Robust Defensive TrainingZhenyi Wang, Li Shen, Tongliang Liu, Tiehang Duan 等NeurIPS 2023 · 被引用 26 次
- Defense against Model Extraction Attack by Bayesian Active WatermarkingZhenyi Wang, Yihan Wu, Heng HuangICML 2024 · 被引用 10 次
- Language Modelling via Learning to RankArvid Frydenlund, Gagandeep Singh, Frank RudziczAAAI 2022 · 被引用 9 次
- Fully Exploiting Every Real Sample: SuperPixel Sample Gradient Model StealingYunlong Zhao, Xiaoheng Deng, Yijing Liu, Xinjun Pei 等CVPR 2024 · 被引用 6 次
它引用的顶会 Paper12
- Data-Free Learning of Student NetworksHanting Chen, Yunhe Wang, Chang Xu, Zhaohui Yang 等ICCV 2019 · 被引用 427 次
- Sign-OPT: A Query-Efficient Hard-label Adversarial AttackMinhao Cheng, Simranjit Singh, Patrick H. Chen, Pin-Yu Chen 等ICLR 2020 · 被引用 256 次
- Uncertainty-Aware Multi-Shot Knowledge Distillation for Image-Based Object Re-IdentificationXin Jin, Cuiling Lan, Wenjun Zeng, Zhibo ChenAAAI 2020 · 被引用 122 次
- A Geometry-Inspired Decision-Based AttackYujia Liu, Seyed-Mohsen Moosavi-Dezfooli, Pascal FrossardICCV 2019 · 被引用 55 次
- Data-Free Knowledge Distillation with Soft Targeted Transfer Set SynthesisZi WangAAAI 2021 · 被引用 35 次
相关 Paper
- GrayKD: Distilling Better Knowledge from Black-box LLM via Multi-rationale InjectionHyeongsoo Lim, Hyung Yong Kim, Jin Young Kim, Min Ho Jang 等AAAI 2026
- IDEAL: Query-Efficient Data-Free Learning from Black-Box ModelsJie Zhang, Chen Chen, Lingjuan LyuICLR 2023 · 被引用 5 次
- Aligning Logits Generatively for Principled Black-Box Knowledge DistillationJing Ma, Xiang Xiang, Ke Wang, Yuchuan Wu 等CVPR 2024 · 被引用 1 次
- Medium-Difficulty Samples Constitute Smoothed Decision Boundary for Knowledge Distillation on Pruned DatasetsYudong Chen, Xuwei Xu, Frank de Hoog, Jiajun Liu 等ICLR 2025
- Safe Distillation BoxJingwen Ye, Yining Mao, Jie Song, Xinchao Wang 等AAAI 2022 · 被引用 14 次
