错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Model Extraction Attack Without Natural Images

  • Kota Yoshida,
  • Takeshi Fujino

摘要

Model extraction attacks are one of the threats to machine learning as a service (MLaaS). An adversary’s objective is to steal the ML model provided on the MLaaS through application programming interfaces (APIs). The adversary is motivated because the attack avoids various costs for training deep neural networks (DNNs) and infringes on the competitive features of the services. It is important to clarify possible attacks on these systems. Model extraction attacks have faced trade-offs between the domain knowledge in the extraction image sets and the query efficiency. This paper introduces a formula-driven model extraction attack that does NOT use natural images. Our extraction image sets consist of fractal images that represent patterns effectively on natural objects and scenes around us and are generated using mathematical formulas from fractal geometry. We expect the fractal image sets to reduce costs for acquiring images for attack and effectively extract features from the target DNN model.