Analyzing the Confidentiality of Undistillable Teachers in Knowledge Distillation
Souvik Kundu, Qirui Sun, Yao Fu, Massoud Pedram, Peter A. Beerel
摘要
Knowledge distillation (KD) has recently been identified as a method that can unintentionally leak private information regarding the details of a teacher model to an unauthorized student. Recent research in developing undistillable nasty teachers that can protect model confidentiality has gained significant attention. However, the level of protection these nasty models offer has been largely untested. In this paper, we show that transferring knowledge to a shallow sub-section of a student can largely reduce a teacher's influence. By exploring the depth of the shallow subsection, we then present a distillation technique that enables a skeptical student model to learn even from a nasty teacher. To evaluate the efficacy of our skeptical students, we conducted experiments with several models with KD under both training data-available and data-free scenarios for various datasets. While distilling from nasty teachers, compared to the normal student models, skeptical students consistently provide superior classification performance of up to ∼59.5%. Moreover, similar to normal students, skeptical students maintain high classification accuracy when distilled from a normal teacher, showing their efficacy irrespective of the teacher being nasty or not. We believe the ability of skeptical students to largely diminish the KD-immunity of a potentially nasty teacher will motivate the research community to create more robust mechanisms for model confidentiality. We have open-sourced the code at github.com/ksouvik52/Skeptical2021.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Knowledge Diffusion for DistillationTao Huang, Yuan Zhang, Mingkai Zheng, Shan You 等NeurIPS 2023 · 被引用 125 次
- SAL-ViT: Towards Latency Efficient Private Inference on ViT using Selective Attention Search with a Learnable Softmax ApproximationYuke Zhang, Dake Chen, Souvik Kundu, Chenghao Li 等ICCV 2023 · 被引用 30 次
- FedDefender: Client-Side Attack-Tolerant Federated LearningSungwon Park, Sungwon Han, Fangzhao Wu, Sundong Kim 等KDD 2023 · 被引用 26 次
- C2PI: An Efficient Crypto-Clear Two-Party Neural Network Private InferenceYuke Zhang, Dake Chen, Souvik Kundu, Haomei Liu 等DAC 2023 · 被引用 7 次
- HYDRA-FL: Hybrid Knowledge Distillation for Robust and Accurate Federated LearningMomin Ahmad Khan, Yasra Chandio, Fatima M. AnwarNeurIPS 2024 · 被引用 5 次
它引用的顶会 Paper13
- Improved Knowledge Distillation via Teacher AssistantSeyed-Iman Mirzadeh, Mehrdad Farajtabar, Ang Li, Nir Levine 等AAAI 2020 · 被引用 1,361 次
- Be Your Own Teacher: Improve the Performance of Convolutional Neural Networks via Self DistillationLinfeng Zhang, Jiebo Song, Anni Gao, Jingwei Chen 等ICCV 2019 · 被引用 1,069 次
- Data-Free Learning of Student NetworksHanting Chen, Yunhe Wang, Chang Xu, Zhaohui Yang 等ICCV 2019 · 被引用 427 次
- Bit-Flip Attack: Crushing Neural Network With Progressive Bit SearchAdnan Siraj Rakin, Zhezhi He, Deliang FanICCV 2019 · 被引用 309 次
- HIRE-SNN: Harnessing the Inherent Robustness of Energy-Efficient Deep Spiking Neural Networks by Training with Crafted Input NoiseSouvik Kundu, Massoud Pedram, Peter A. BeerelICCV 2021 · 被引用 114 次
相关 Paper
- Undistillable: Making A Nasty Teacher That CANNOT teach studentsHaoyu Ma, Tianlong Chen, Ting-Kuei Hu, Chenyu You 等ICLR 2021 · 被引用 58 次
- Teach Less, Learn More: On the Undistillable Classes in Knowledge DistillationYichen Zhu, Ning Liu, Zhiyuan Xu, Xin Liu 等NeurIPS 2022 · 被引用 42 次
- On the Impact of Knowledge Distillation for Model InterpretabilityHyeongrok Han, Siwon Kim, Hyun-Soo Choi, Sungroh YoonICML 2023 · 被引用 13 次
- Knowledge Distillation as Decontamination? Revisiting the "Data Laundering" Concern in Classification TasksHengyu Luo, Raúl Vázquez, Timothee Mickus, Filip Ginter 等ICLR 2026
- Adversarially Robust DistillationMicah Goldblum, Liam Fowl, Soheil Feizi, Tom GoldsteinAAAI 2020 · 被引用 258 次
