I Know What You Trained Last Summer: A Survey on Stealing Machine Learning Models and Defences
Oliynyk, Daryna, Mayer, Rudolf, Rauber, Andreas
–arXiv.org Artificial Intelligence
Machine Learning-as-a-Service (MLaaS) has become a widespread paradigm, making even the most complex machine learning models available for clients via e.g. a pay-per-query principle. This allows users to avoid time-consuming processes of data collection, hyperparameter tuning, and model training. However, by giving their customers access to the (predictions of their) models, MLaaS providers endanger their intellectual property, such as sensitive training data, optimised hyperparameters, or learned model parameters. Adversaries can create a copy of the model with (almost) identical behavior using the the prediction labels only. While many variants of this attack have been described, only scattered defence strategies have been proposed, addressing isolated threats. This raises the necessity for a thorough systematisation of the field of model stealing, to arrive at a comprehensive understanding why these attacks are successful, and how they could be holistically defended against. We address this by categorising and comparing model stealing attacks, assessing their performance, and exploring corresponding defence techniques in different settings. We propose a taxonomy for attack and defence approaches, and provide guidelines on how to select the right attack or defence strategy based on the goal and available resources. Finally, we analyse which defences are rendered less effective by current attack strategies.
arXiv.org Artificial Intelligence
Jun-6-2023
- Country:
- South America > Brazil
- Rio de Janeiro > Rio de Janeiro (0.04)
- North America
- United States
- Maryland > Baltimore (0.04)
- Texas > Travis County
- Austin (0.04)
- New York
- New York County > New York City (0.14)
- Richmond County > New York City (0.04)
- Queens County > New York City (0.04)
- Kings County > New York City (0.04)
- Bronx County > New York City (0.04)
- Louisiana > Orleans Parish
- New Orleans (0.04)
- Pennsylvania > Philadelphia County
- Philadelphia (0.04)
- Massachusetts > Middlesex County
- Illinois > Cook County
- Chicago (0.04)
- Tennessee
- Davidson County > Nashville (0.04)
- Putnam County > Cookeville (0.04)
- Wisconsin > Dane County
- Madison (0.04)
- Kentucky > Jefferson County
- Louisville (0.04)
- Georgia > Fulton County
- Atlanta (0.04)
- Washington > King County
- Seattle (0.04)
- California
- San Francisco County > San Francisco (0.14)
- San Diego County > San Diego (0.04)
- Santa Clara County
- Santa Clara (0.04)
- San Jose (0.04)
- Stanford (0.04)
- Los Angeles County
- Los Angeles (0.14)
- Long Beach (0.04)
- Puerto Rico > San Juan
- San Juan (0.04)
- Canada
- Quebec > Montreal (0.04)
- British Columbia > Metro Vancouver Regional District
- Vancouver (0.04)
- Alberta > Census Division No. 15
- Improvement District No. 9 > Banff (0.04)
- United States
- Europe
- Austria > Vienna (0.14)
- France (0.04)
- Sweden > Stockholm
- Stockholm (0.04)
- Netherlands > North Holland
- Amsterdam (0.04)
- Switzerland > Vaud
- Lausanne (0.04)
- Hungary > Budapest
- Budapest (0.04)
- Middle East > Malta
- Port Region > Southern Harbour District > Valletta (0.04)
- United Kingdom > England
- Greater London > London (0.04)
- Italy
- Veneto > Venice (0.04)
- Calabria > Catanzaro Province
- Catanzaro (0.04)
- Asia
- Singapore (0.04)
- Taiwan > Taiwan Province
- Taipei (0.04)
- South Korea
- Middle East
- Japan > Kyūshū & Okinawa
- Kyūshū > Nagasaki Prefecture > Nagasaki (0.04)
- India > NCT
- China
- Shanghai > Shanghai (0.04)
- Shaanxi Province > Xi'an (0.04)
- Hong Kong (0.04)
- South America > Brazil
- Genre:
- Research Report (1.00)
- Overview (1.00)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Government (1.00)
- Technology:
- Information Technology > Artificial Intelligence > Machine Learning
- Statistical Learning (1.00)
- Reinforcement Learning (1.00)
- Neural Networks > Deep Learning (1.00)
- Performance Analysis > Accuracy (0.92)
- Information Technology > Artificial Intelligence > Machine Learning