Explanation-based data-free model extraction attacks

被引:3
|
作者
Yan, Anli [1 ,2 ]
Hou, Ruitao [2 ]
Yan, Hongyang [2 ]
Liu, Xiaozhang [3 ]
机构
[1] Hainan Univ, Sch Cyberspace Secur, Sch Cryptol, Haikou, Peoples R China
[2] Guangzhou Univ, Inst Artificial Intelligence & Blockchain, Guangzhou, Peoples R China
[3] Hainan Univ, Sch Comp Sci & Technol, Haikou, Peoples R China
基金
中国国家自然科学基金;
关键词
Deep neural network; Model explanation; Black-box; Model extraction attack; FRAMEWORK; EFFICIENT;
D O I
10.1007/s11280-023-01150-6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Deep learning (DL) has dramatically pushed the previous limits of various tasks, ranging from computer vision to natural language processing. Despite its success, the lack of model explanations thwarts the usage of these techniques in life-critical domains, e.g., medical diagnosis and self-driving systems. To date, the core technology to solve the explainable issue is explainable artificial intelligence (XAI). XAI methods have been developed to produce human-understandable explanations by leveraging intermediate results of the DL models, e.g., gradients and model parameters. While the effectiveness of XAI methods has been demonstrated in benign environments, their privacy against model extraction attacks (i.e., attacks at the model confidentially) requires to be studied. To this end, this paper proposes DMEAE, a data-free model extraction attack using explanation-guided, to explore XAI privacy threats. Compared with previous works, DMEAE does not require collecting any data and utilizes model explanation loss. Specifically, DMEAE creates synthetic data using a generative model with model explanation loss items. Extensive evaluations verify the effectiveness and efficiency of the proposed attack strategy on SVHN and CIFAR-10 datasets. We hope that our research can provide insights for the development of practical tools to trade off the relationship between privacy and model explanations.
引用
收藏
页码:3081 / 3092
页数:12
相关论文
共 50 条
  • [41] INVESTIGATING EXPLANATION-BASED LEARNING - DEJONG,G
    GEORGE, C
    ANNEE PSYCHOLOGIQUE, 1994, 94 (03): : 492 - 493
  • [42] The Complexity of Data-Free Nfer
    Kauffman, Sean
    Larsen, Kim Guldstrand
    Zimmermann, Martin
    RUNTIME VERIFICATION, RV 2024, 2025, 15191 : 174 - 191
  • [43] Data-Free Backdoor Removal Based on Channel Lipschitzness
    Zheng, Runkai
    Tang, Rongjun
    Li, Jianze
    Liu, Li
    COMPUTER VISION - ECCV 2022, PT V, 2022, 13665 : 175 - 191
  • [44] Explanation-based learning with analogy for impasse resolution
    Timperley, Matt
    Mokhtar, Maizura
    Bellaby, Gareth
    Howe, Joe
    EXPERT SYSTEMS WITH APPLICATIONS, 2016, 61 : 181 - 191
  • [45] EXPLANATION-BASED LEARNING FOR INTELLIGENT PROCESS PLANNING
    PARK, SC
    GERVASIO, MT
    SHAW, MJ
    DEJONG, GF
    IEEE TRANSACTIONS ON SYSTEMS MAN AND CYBERNETICS, 1993, 23 (06): : 1597 - 1616
  • [46] SCME: A Self-contrastive Method for Data-Free and Query-Limited Model Extraction Attack
    Liu, Renyang
    Zhang, Jinhong
    Lam, Kwok-Yan
    Zhao, Jun
    Zhou, Wei
    NEURAL INFORMATION PROCESSING, ICONIP 2023, PT V, 2024, 14451 : 370 - 382
  • [47] Data-Free Sketch-Based Image Retrieval
    Chaudhuri, Abhra
    Bhunia, Ayan Kumar
    Song, Yi-Zhe
    Dutta, Anjan
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 12084 - 12093
  • [48] EXPLANATION-BASED LEARNING FOR KNOWLEDGE-BASED SYSTEMS
    PAZZANI, MJ
    INTERNATIONAL JOURNAL OF MAN-MACHINE STUDIES, 1987, 26 (04): : 413 - 433
  • [49] EXPLANATION-BASED LEARNING - A SURVEY OF PROGRAMS AND PERSPECTIVES
    ELLMAN, T
    COMPUTING SURVEYS, 1989, 21 (02) : 163 - 221
  • [50] Acquiring recursive concepts with explanation-based learning
    1600, Morgan Kaufmann Publ Inc, San Mateo, CA, USA (01):