Model Extraction Attacks and Defenses on Cloud-Based Machine Learning Models

被引:28
|
作者
Gong, Xueluan [1 ]
Wang, Qian [2 ]
Chen, Yanjiao [3 ]
Yang, Wang [4 ]
Jiang, Xinchang [1 ]
机构
[1] Wuhan Univ, Comp Sci, Wuhan, Peoples R China
[2] Wuhan Univ, Sch Comp Sci, Wuhan, Peoples R China
[3] Wuhan Univ, Wuhan, Peoples R China
[4] Wuhan Univ, Cyber Sci & Engn, Wuhan, Peoples R China
基金
中国国家自然科学基金;
关键词
Computational modeling; Training data; Machine learning; Speech recognition; Propulsion; Internet; Security;
D O I
10.1109/MCOM.001.2000196
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Machine learning models have achieved state-of-the-art performance in various fields, from image classification to speech recognition. However, such models are trained with a large amount of sensitive training data, and are typically computationally expensive to build. As a result, many cloud providers (e.g., Google) have launched machine-learning-as-a-service, which helps clients benefit from the sophisticated cloud-based machine learning models via accessing public APIs. Such a business paradigm significantly expedites and simplifies the development circles. Unfortunately, the commercial value of such cloud-based machine learning models motivates attackers to conduct model extraction attacks for free use or as a springboard to conduct other attacks (e.g., craft adversarial examples in black-box settings). In this article, we conduct a thorough investigation of existing approaches to model extraction attacks and defenses on cloud-based models. We classify the state-of-the-art attack schemes into two categories based on whether the attacker aims to steal the property (i.e., parameters, hyperparameters, and architecture) or the functionality of the model. We also categorize defending schemes into two groups based on whether the scheme relies on output disturbance or query observation. We not only present a detailed survey of each method, but also demonstrate the comparison of both attack and defense approaches via experiments. We highlight several future directions in both model extraction attacks and its defenses, which shed light on possible avenues for further studies.
引用
收藏
页码:83 / 89
页数:7
相关论文
共 50 条
  • [31] Cloud-based Machine Learning Framework for Residential HVAC Control System
    Issaraviriyakul, Atthawut
    Pora, Wanchalerm
    Panitantum, Napong
    2021 13TH INTERNATIONAL CONFERENCE ON KNOWLEDGE AND SMART TECHNOLOGY (KST-2021), 2021, : 18 - 22
  • [32] Cloud-Based Machine Learning Methods for Parameter Prediction in Textile Manufacturing
    Chang, Ray-, I
    Lin, Jia-Ying
    Hung, Yu-Hsin
    SENSORS, 2024, 24 (04)
  • [33] Machine Learning Attacks and Defenses for Vehicular Cyber Physical Systems
    Richards, Lance
    Rodriguez, Alondra
    Johnson, Dawn
    Rawal, Atul
    ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING FOR MULTI-DOMAIN OPERATIONS APPLICATIONS VI, 2024, 13051
  • [34] Kernel-Based Machine Learning Models to Predict Mitigation Time During Cloud Security Attacks
    Kadiri, Padmaja
    Ravala, Seshadri
    INTERNATIONAL JOURNAL OF E-COLLABORATION, 2021, 17 (04) : 75 - 88
  • [35] Adversarial Machine Learning for Image-Based Radio Frequency Fingerprinting: Attacks and Defenses
    Papangelo L.
    Pistilli M.
    Sciancalepore S.
    Oligeri G.
    Piro G.
    Boggia G.
    IEEE Communications Magazine, 2024, 62 (11) : 1 - 7
  • [36] Countering Statistical Attacks in Cloud-Based Searchable Encryption
    Ahsan, M. A. Manazir
    Ali, Ihsan
    Bin Idris, Mohd Yamani Idna
    Imran, Muhammad
    Shoaib, Muhammad
    INTERNATIONAL JOURNAL OF PARALLEL PROGRAMMING, 2020, 48 (03) : 470 - 495
  • [37] Countering Statistical Attacks in Cloud-Based Searchable Encryption
    M. A. Manazir Ahsan
    Ihsan Ali
    Mohd Yamani Idna Bin Idris
    Muhammad Imran
    Muhammad Shoaib
    International Journal of Parallel Programming, 2020, 48 : 470 - 495
  • [38] Probability machine-learning-based communication and operation optimization for cloud-based UAVs
    Jeong, Hyeok-June
    Choi, Suh-Yong
    Jang, Sung-Su
    Ha, Young-Guk
    JOURNAL OF SUPERCOMPUTING, 2020, 76 (10): : 8101 - 8117
  • [39] A filter-based machine learning classification framework for cloud-based medical databases
    Sri, V. Devi Satya
    Vemuru, Srikanth
    INTERNATIONAL JOURNAL OF AD HOC AND UBIQUITOUS COMPUTING, 2022, 40 (1-3) : 94 - 105
  • [40] Probability machine-learning-based communication and operation optimization for cloud-based UAVs
    Hyeok-June Jeong
    Suh-Yong Choi
    Sung-Su Jang
    Young-Guk Ha
    The Journal of Supercomputing, 2020, 76 : 8101 - 8117