Towards Model Extraction Attacks in GAN-Based Image Translation via Domain Shift Mitigation

被引:0
|
作者
Mi, Di [1 ]
Zhang, Yanjun [2 ]
Zhang, Leo Yu [3 ]
Hu, Shengshan [4 ]
Zhong, Qi [5 ]
Yuan, Haizhuan [1 ]
Pan, Shirui [3 ]
机构
[1] Xiangtan Univ, Xiangtan, Peoples R China
[2] Univ Technol Sydney, Ultimo, NSW, Australia
[3] Griffith Univ, Brisbane, Qld, Australia
[4] Huazhong Univ Sci & Technol, Wuhan, Peoples R China
[5] City Univ Macau, Macau, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Model extraction attacks (MEAs) enable an attacker to replicate the functionality of a victim deep neural network (DNN) model by only querying its API service remotely, posing a severe threat to the security and integrity of pay-per-query DNN-based services. Although the majority of current research on MEAs has primarily concentrated on neural classifiers, there is a growing prevalence of image-to-image translation (I2IT) tasks in our everyday activities. However, techniques developed for MEA of DNN classifiers cannot be directly transferred to the case of I2IT, rendering the vulnerability of I2IT models to MEA attacks often underestimated. This paper unveils the threat of MEA in I2IT tasks from a new perspective. Diverging from the traditional approach of bridging the distribution gap between attacker queries and victim training samples, we opt to mitigate the effect caused by the different distributions, known as the domain shift. This is achieved by introducing a new regularization term that penalizes high-frequency noise, and seeking a flatter minimum to avoid overfitting to the shifted distribution. Extensive experiments on different image translation tasks, including image super-resolution and style transfer, are performed on different backbone victim models, and the new design consistently outperforms the baseline by a large margin across all metrics. A few real-life I2IT APIs are also verified to be extremely vulnerable to our attack, emphasizing the need for enhanced defenses and potentially revised API publishing policies.
引用
收藏
页码:19902 / 19910
页数:9
相关论文
共 50 条
  • [1] Adversarial attacks on GAN-based image fusion
    Sun, Hui
    Wu, Siman
    Ma, Lijun
    INFORMATION FUSION, 2024, 108
  • [2] GAN-based unpaired image-to-image translation for maritime imagery
    Mediavilla, Chelsea
    Sato, Jonathan
    Manzanares, Mitch
    Dotter, Marissa
    Parameswaran, Shibin
    GEOSPATIAL INFORMATICS X, 2020, 11398
  • [3] GAN-Based Unpaired Chinese Character Image Translation via Skeleton Transformation and Stroke Rendering
    Gao, Yiming
    Wu, Jiangqin
    THIRTY-FOURTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THE THIRTY-SECOND INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE AND THE TENTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2020, 34 : 646 - 653
  • [4] Prevention of GAN-Based Privacy Inferring Attacks Towards Federated Learning
    Cao, Hongbo
    Zhu, Yongsheng
    Ren, Yuange
    Wang, Bin
    Hu, Mingqing
    Wang, Wanqi
    Wang, Wei
    COLLABORATIVE COMPUTING: NETWORKING, APPLICATIONS AND WORKSHARING, COLLABORATECOM 2022, PT II, 2022, 461 : 39 - 54
  • [5] Multimodal Satellite Image Time Series Analysis Using GAN-Based Domain Translation and Matrix Profile
    Radoi, Anamaria
    REMOTE SENSING, 2022, 14 (15)
  • [6] A GAN-Based Defense Framework Against Model Inversion Attacks
    Gong, Xueluan
    Wang, Ziyao
    Li, Shuaike
    Chen, Yanjiao
    Wang, Qian
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 4475 - 4487
  • [7] GAN-based Image Translation Model with Self-Attention for Nighttime Dashcam Data Augmentation
    Sultana, Rebeka
    Ohashi, Gosuke
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2023, E106A (09) : 1202 - 1210
  • [8] GAN-BASED SAR-TO-OPTICAL IMAGE TRANSLATION WITH REGION INFORMATION
    Doi, Kento
    Sakurada, Ken
    Onishi, Masaki
    Iwasaki, Akira
    IGARSS 2020 - 2020 IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM, 2020, : 2069 - 2072
  • [9] Latent Transformations via NeuralODEs for GAN-based Image Editing
    Khrulkov, Valentin
    Mirvakhabova, Leyla
    Oseledets, Ivan
    Babenko, Artem
    2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 14408 - 14417
  • [10] GAN-Based Stroke Extraction Model with Attention and Stroke Grouping
    Liu, Haotian
    Zhong, Yixin
    Chen, Yuehui
    Cao, Yi
    Zhao, Yaou
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT VI, ICIC 2024, 2024, 14880 : 373 - 384