Model Extraction Attack Without Natural Images
摘要
Model extraction attacks are one of the threats to machine learning as a service (MLaaS). An adversary’s objective is to steal the ML model provided on the MLaaS through application programming interfaces (APIs). The adversary is motivated because the attack avoids various costs for training deep neural networks (DNNs) and infringes on the competitive features of the services. It is important to clarify possible attacks on these systems. Model extraction attacks have faced trade-offs between the domain knowledge in the extraction image sets and the query efficiency. This paper introduces a formula-driven model extraction attack that does NOT use natural images. Our extraction image sets consist of fractal images that represent patterns effectively on natural objects and scenes around us and are generated using mathematical formulas from fractal geometry. We expect the fractal image sets to reduce costs for acquiring images for attack and effectively extract features from the target DNN model.