Model Extraction Attacks and Defenses on Cloud-Based Machine Learning Models

被引:39
作者
Gong, Xueluan [1 ]
Wang, Qian [2 ]
Chen, Yanjiao [3 ]
Yang, Wang [4 ]
Jiang, Xinchang [1 ]
机构
[1] Wuhan Univ, Comp Sci, Wuhan, Peoples R China
[2] Wuhan Univ, Sch Comp Sci, Wuhan, Peoples R China
[3] Wuhan Univ, Wuhan, Peoples R China
[4] Wuhan Univ, Cyber Sci & Engn, Wuhan, Peoples R China
基金
中国国家自然科学基金;
关键词
Computational modeling; Training data; Machine learning; Speech recognition; Propulsion; Internet; Security;
D O I
10.1109/MCOM.001.2000196
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Machine learning models have achieved state-of-the-art performance in various fields, from image classification to speech recognition. However, such models are trained with a large amount of sensitive training data, and are typically computationally expensive to build. As a result, many cloud providers (e.g., Google) have launched machine-learning-as-a-service, which helps clients benefit from the sophisticated cloud-based machine learning models via accessing public APIs. Such a business paradigm significantly expedites and simplifies the development circles. Unfortunately, the commercial value of such cloud-based machine learning models motivates attackers to conduct model extraction attacks for free use or as a springboard to conduct other attacks (e.g., craft adversarial examples in black-box settings). In this article, we conduct a thorough investigation of existing approaches to model extraction attacks and defenses on cloud-based models. We classify the state-of-the-art attack schemes into two categories based on whether the attacker aims to steal the property (i.e., parameters, hyperparameters, and architecture) or the functionality of the model. We also categorize defending schemes into two groups based on whether the scheme relies on output disturbance or query observation. We not only present a detailed survey of each method, but also demonstrate the comparison of both attack and defense approaches via experiments. We highlight several future directions in both model extraction attacks and its defenses, which shed light on possible avenues for further studies.
引用
收藏
页码:83 / 89
页数:7
相关论文
共 50 条
[31]   Membership Inference Attacks Against Machine Learning Models via Prediction Sensitivity [J].
Liu, Lan ;
Wang, Yi ;
Liu, Gaoyang ;
Peng, Kai ;
Wang, Chen .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (03) :2341-2347
[32]   Novel Building Management System based on Machine Learning and a Cloud-based SOA for Ambient Living [J].
Kyriazakos, Sofoklis ;
Labropoulos, George ;
Zonidis, Nikos ;
Foti, Magda .
2014 4TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, VEHICULAR TECHNOLOGY, INFORMATION THEORY AND AEROSPACE & ELECTRONIC SYSTEMS (VITAE), 2014,
[33]   Deep learning model inversion attacks and defenses: a comprehensive survey [J].
Yang, Wencheng ;
Wang, Song ;
Wu, Di ;
Cai, Taotao ;
Zhu, Yanming ;
Wei, Shicheng ;
Zhang, Yiying ;
Yang, Xu ;
Tang, Zhaohui ;
Li, Yan .
ARTIFICIAL INTELLIGENCE REVIEW, 2025, 58 (08)
[34]   Robust Malware Detection Models: Learning from Adversarial Attacks and Defenses [J].
Rathore, Hemant ;
Samavedhi, Adithya ;
Sahay, Sanjay K. ;
Sewak, Mohit .
FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION, 2021, 37
[35]   Cloud-based Machine Learning Techniques Implemented by Microsoft Azure for Designing Power Amplifiers [J].
Jamshidi, Mohammad Behdad ;
Roshani, Saeed ;
Talla, Jakub ;
Sharifi-Atashgah, Maryam S. ;
Roshani, Sobhan ;
Peroutka, Zdenek .
2021 IEEE 12TH ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2021, :41-44
[36]   Cloud-based disaster management architecture using hybrid machine learning approach in IoT [J].
Ozen, Figen ;
Souri, Alireza .
MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (29) :72357-72370
[37]   Governance Factors Influencing Financial Performance in Cloud-Based Enterprises: A Machine Learning Analysis [J].
Huang, Ziling ;
Lin, Lichao ;
Jia, Xiaofei .
COMPUTATIONAL ECONOMICS, 2025,
[38]   Cloud-based in-situ battery life prediction and classification using machine learning [J].
Zhang, Yongzhi ;
Zhao, Mingyuan .
ENERGY STORAGE MATERIALS, 2023, 57 :346-359
[39]   Cloud-Based Machine Learning Application for Predicting Energy Consumption in Automotive Spot Welding [J].
Freitas, Nelson ;
Araujo, Sara Oleiro ;
Alemao, Duarte ;
Ramos, Joao ;
Guedes, Magno ;
Goncalves, Jose ;
Peres, Ricardo Silva ;
Rocha, Andre Dionisio ;
Barata, Jose .
PROCESSES, 2023, 11 (01)
[40]   A Hybrid Machine Learning Approach for Performance Modeling of Cloud-Based Big Data Applications [J].
Ataie, Ehsan ;
Evangelinou, Athanasia ;
Gianniti, Eugenio ;
Ardagna, Danilo .
COMPUTER JOURNAL, 2022, 65 (12) :3123-3140