Model Extraction Attacks and Defenses on Cloud-Based Machine Learning Models

被引:39
作者
Gong, Xueluan [1 ]
Wang, Qian [2 ]
Chen, Yanjiao [3 ]
Yang, Wang [4 ]
Jiang, Xinchang [1 ]
机构
[1] Wuhan Univ, Comp Sci, Wuhan, Peoples R China
[2] Wuhan Univ, Sch Comp Sci, Wuhan, Peoples R China
[3] Wuhan Univ, Wuhan, Peoples R China
[4] Wuhan Univ, Cyber Sci & Engn, Wuhan, Peoples R China
基金
中国国家自然科学基金;
关键词
Computational modeling; Training data; Machine learning; Speech recognition; Propulsion; Internet; Security;
D O I
10.1109/MCOM.001.2000196
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Machine learning models have achieved state-of-the-art performance in various fields, from image classification to speech recognition. However, such models are trained with a large amount of sensitive training data, and are typically computationally expensive to build. As a result, many cloud providers (e.g., Google) have launched machine-learning-as-a-service, which helps clients benefit from the sophisticated cloud-based machine learning models via accessing public APIs. Such a business paradigm significantly expedites and simplifies the development circles. Unfortunately, the commercial value of such cloud-based machine learning models motivates attackers to conduct model extraction attacks for free use or as a springboard to conduct other attacks (e.g., craft adversarial examples in black-box settings). In this article, we conduct a thorough investigation of existing approaches to model extraction attacks and defenses on cloud-based models. We classify the state-of-the-art attack schemes into two categories based on whether the attacker aims to steal the property (i.e., parameters, hyperparameters, and architecture) or the functionality of the model. We also categorize defending schemes into two groups based on whether the scheme relies on output disturbance or query observation. We not only present a detailed survey of each method, but also demonstrate the comparison of both attack and defense approaches via experiments. We highlight several future directions in both model extraction attacks and its defenses, which shed light on possible avenues for further studies.
引用
收藏
页码:83 / 89
页数:7
相关论文
共 50 条
[41]   A Cloud-Based Framework for Creating Scalable Machine Learning Models Predicting Building Energy Consumption from Digital Twin Data [J].
Mahamedi, Elham ;
Suliman, Alaeldin ;
Wonders, Martin .
ARCHITECTURE-SWITZERLAND, 2025, 5 (02)
[42]   Customer Lifetime Value and Defection Possibility Prediction Model Using Machine Learning: An Application to a Cloud-Based Software Company [J].
Prasasti, Niken ;
Okada, Masato ;
Kanamori, Katsutoshi ;
Ohwada, Hayato .
INTELLIGENT INFORMATION AND DATABASE SYSTEMS, PT II, 2014, 8398 :62-71
[43]   A cloud-based learning module for biomarker discovery [J].
Hemme, Christopher L. ;
Beaudry, Laura ;
Yosufzai, Zelaikha ;
Kim, Allen ;
Pan, Daniel ;
Campbell, Ross ;
Price, Marcia ;
Cho, Bongsup P. .
BRIEFINGS IN BIOINFORMATICS, 2024, 25
[44]   SECURITY ASPECTS OF CLOUD-BASED MOBILE LEARNING [J].
Velev, D. G. .
FINANCIAL AND CREDIT ACTIVITY-PROBLEMS OF THEORY AND PRACTICE, 2014, 2 (17) :240-251
[45]   Cloud-Based Fault Prediction for Real-Time Monitoring of Sensor Data in Hospital Environment Using Machine Learning [J].
Uppal, Mudita ;
Gupta, Deepali ;
Juneja, Sapna ;
Sulaiman, Adel ;
Rajab, Khairan ;
Rajab, Adel ;
Elmagzoub, M. A. ;
Shaikh, Asadullah .
SUSTAINABILITY, 2022, 14 (18)
[46]   Using machine learning for service candidate sets retrieval in service composition of cloud-based manufacturing [J].
Hamed Bouzary ;
F. Frank Chen ;
Mohammad Shahin .
The International Journal of Advanced Manufacturing Technology, 2021, 115 :941-948
[47]   A Comprehensive Machine Learning Framework for Robust Security Management in Cloud-based Internet of Things Systems [J].
Mohamed, Mahmoud ;
Alosman, Khaled .
JURNAL KEJURUTERAAN, 2024, 36 (03) :1055-1065
[48]   Design of a Cloud-Based Data Platform for Standardized Machine Learning Workflows with Applications to Transport Infrastructure [J].
Bartezzaghi, Andrea ;
Giurgiu, Ioana ;
Marchiori, Chiara ;
Rigotti, Mattia ;
Sebastian, Rizal ;
Malossi, Cristiano .
2022 IEEE 21ST MEDITERRANEAN ELECTROTECHNICAL CONFERENCE (IEEE MELECON 2022), 2022, :764-769
[49]   Cloud-Based Privacy-Preserving Medical Imaging System Using Machine Learning Tools [J].
Alves, Joao ;
Soares, Beatriz ;
Brito, Claudia ;
Sousa, Antonio .
PROGRESS IN ARTIFICIAL INTELLIGENCE, EPIA 2022, 2022, 13566 :195-206
[50]   Using machine learning for service candidate sets retrieval in service composition of cloud-based manufacturing [J].
Bouzary, Hamed ;
Chen, F. Frank ;
Shahin, Mohammad .
INTERNATIONAL JOURNAL OF ADVANCED MANUFACTURING TECHNOLOGY, 2021, 115 (03) :941-948