Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

DT-DFRS: Enhanced Data-Free Robustness Stealing via Dual Teacher Guidance in Black-Box Settings

View through CrossRef
Abstract Model Stealing Attacks (MSAs) are identified as a significant privacy threat to Machine Learning as a Service (MLaaS). MSAs aim to craft a substitute model that has the same performance by just querying MLaaS. Various techniques have been proposed to steal the accuracy as well as the robustness of target models so that these models achieve not only the same performance as the victim model but also their robustness against adversarial attacks. Since the training data, architecture, and parameters of these models are inaccessible due to privacy issues, most approaches rely on distillation methods. In this process, a clone model is trained to imitate the behavior of the target model, effectively stealing its efficiency.Robustness Distillation (RD) addresses both the efficiency and robustness challenges of existing models. However, most existing approaches focus solely on distilling model accuracy while neglecting robustness, despite its importance in safety-critical scenarios. Additionally, many approaches rely on access to real or proxy datasets, which is often infeasible due to privacy constraints. Other approaches assume the availability of Soft-Label (SL) predictions, which requires retrieving the outputs from the softmax layer lying before the final classification.In this paper, we propose a novel Dual Teacher Data-Free Hard-Label Robustness Stealing attack (DT-DFRS) that enables robustness distillation without requiring real or proxy data while preserving the model's efficiency in hard-label settings.Our experiments demonstrate how our DT-DFRS is effective over existing state-of-the-art data-free hard-label methods. Our proposed model improves the baseline by 3.41% and 3.13% for CIFAR-10 and CIFAR-100 datasets, respectively.
Springer Science and Business Media LLC
Title: DT-DFRS: Enhanced Data-Free Robustness Stealing via Dual Teacher Guidance in Black-Box Settings
Description:
Abstract Model Stealing Attacks (MSAs) are identified as a significant privacy threat to Machine Learning as a Service (MLaaS).
MSAs aim to craft a substitute model that has the same performance by just querying MLaaS.
Various techniques have been proposed to steal the accuracy as well as the robustness of target models so that these models achieve not only the same performance as the victim model but also their robustness against adversarial attacks.
Since the training data, architecture, and parameters of these models are inaccessible due to privacy issues, most approaches rely on distillation methods.
In this process, a clone model is trained to imitate the behavior of the target model, effectively stealing its efficiency.
Robustness Distillation (RD) addresses both the efficiency and robustness challenges of existing models.
However, most existing approaches focus solely on distilling model accuracy while neglecting robustness, despite its importance in safety-critical scenarios.
Additionally, many approaches rely on access to real or proxy datasets, which is often infeasible due to privacy constraints.
Other approaches assume the availability of Soft-Label (SL) predictions, which requires retrieving the outputs from the softmax layer lying before the final classification.
In this paper, we propose a novel Dual Teacher Data-Free Hard-Label Robustness Stealing attack (DT-DFRS) that enables robustness distillation without requiring real or proxy data while preserving the model's efficiency in hard-label settings.
Our experiments demonstrate how our DT-DFRS is effective over existing state-of-the-art data-free hard-label methods.
Our proposed model improves the baseline by 3.
41% and 3.
13% for CIFAR-10 and CIFAR-100 datasets, respectively.

Related Results

On Flores Island, do "ape-men" still exist? https://www.sapiens.org/biology/flores-island-ape-men/
On Flores Island, do "ape-men" still exist? https://www.sapiens.org/biology/flores-island-ape-men/
<span style="font-size:11pt"><span style="background:#f9f9f4"><span style="line-height:normal"><span style="font-family:Calibri,sans-serif"><b><spa...
On the Limitations of Black-Box Constructions in Cryptography
On the Limitations of Black-Box Constructions in Cryptography
Cryptography is the science of secure communication. Originating as an esoteric discipline based on heuristics, it underwent a mayor paradigm shift in the past century. Modern cryp...
Mix En Meng It Op: Emile YX?'s Alternative Race and Language Politics in South African Hip-Hop
Mix En Meng It Op: Emile YX?'s Alternative Race and Language Politics in South African Hip-Hop
This paper explores South African hip-hop activist Emile YX?'s work to suggest that he presents an alternative take on mainstream US and South African hip-hop. While it is arguable...
Who Cares for Black Women in Health and Health Care
Who Cares for Black Women in Health and Health Care
Black women are often at the center of health disparities research. Black women face sociological, psychological, environmental, and political barriers to health and health care th...
When Does a Dual Matrix Have a Dual Generalized Inverse?
When Does a Dual Matrix Have a Dual Generalized Inverse?
This paper deals with the existence of various types of dual generalized inverses of dual matrices. New and foundational results on the necessary and sufficient conditions for vari...
Stealing
Stealing
Abstract This chapter argues that the norm against stealing is clearly an essential ingredient in a wide range of criminal law offenses, often combined with some oth...
Identification and bioinformatics analysis of MADS-box family genes containing K-box domain in maize
Identification and bioinformatics analysis of MADS-box family genes containing K-box domain in maize
The MADS-box family genes are involved in the development of plant roots, leaves, flowers, and fruits, and play a crucial role in plant growth and development. Studying MADS-box ge...
Teacher leadership and collective efficacy: teacher perceptions in three US school districts
Teacher leadership and collective efficacy: teacher perceptions in three US school districts
Purpose – Collective efficacy and teacher leadership, two constructs central to school reform, were examined in this quantitative study of three school districts. T...

Back to Top