<p>MLaaS (Machine Learning as a Service) platforms provide convenient and scalable options for deploying machine learning models. Nevertheless, these offerings are becoming more vulnerable to model theft attacks, in which enemies can withdraw exclusive models by requesting information from the service. This review evaluates the present status of protections against model theft attacks in MLaaS. At times, someone working with machine learning is either highly knowledgeable in the field or needs to utilize costly resources to manage the vast amount of data. Individuals utilize MLaaS (Machine Learning as a Service) to avoid these problems by accessing various services. We start by classifying the different ways attacks can happen, focusing on the methods adversaries use to create accurate models. Next, we will examine the defensive tactics suggested in the literature, such as detection mechanisms, response plans, and preventive actions. The effectiveness and feasibility of key methods such as limiting queries, altering query responses, and using strong watermarks are assessed. This review aims to offer a thorough comprehension of the threat landscape and provide practitioners with insights into the current best practices for securing machine learning models in a service-oriented setting. Exactly, this study focuses on a specific service - classification - where MLaaS offers customers a black-box model. The predictions are generated by the model in response to API queries. Regrettably, these forecasts are utilized by malicious customers to either gain access to private data or develop a replacement model. Model theft attacks, also known as model extraction attacks, pose a threat to the confidentiality of machine learning models and need to be safeguarded against. Different suggestions and countermeasures are classified in response to this threat.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Defenses against model stealing attacks in MLaaS: literature review and challenges

  • Aouatef Mahani,
  • Okba Kazar

摘要

MLaaS (Machine Learning as a Service) platforms provide convenient and scalable options for deploying machine learning models. Nevertheless, these offerings are becoming more vulnerable to model theft attacks, in which enemies can withdraw exclusive models by requesting information from the service. This review evaluates the present status of protections against model theft attacks in MLaaS. At times, someone working with machine learning is either highly knowledgeable in the field or needs to utilize costly resources to manage the vast amount of data. Individuals utilize MLaaS (Machine Learning as a Service) to avoid these problems by accessing various services. We start by classifying the different ways attacks can happen, focusing on the methods adversaries use to create accurate models. Next, we will examine the defensive tactics suggested in the literature, such as detection mechanisms, response plans, and preventive actions. The effectiveness and feasibility of key methods such as limiting queries, altering query responses, and using strong watermarks are assessed. This review aims to offer a thorough comprehension of the threat landscape and provide practitioners with insights into the current best practices for securing machine learning models in a service-oriented setting. Exactly, this study focuses on a specific service - classification - where MLaaS offers customers a black-box model. The predictions are generated by the model in response to API queries. Regrettably, these forecasts are utilized by malicious customers to either gain access to private data or develop a replacement model. Model theft attacks, also known as model extraction attacks, pose a threat to the confidentiality of machine learning models and need to be safeguarded against. Different suggestions and countermeasures are classified in response to this threat.