• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
成果搜索

author:

Ma, Zhuo (Ma, Zhuo.) [1] | Liu, Xinjing (Liu, Xinjing.) [2] | Liu, Yang (Liu, Yang.) [3] | Liu, Ximeng (Liu, Ximeng.) [4] | Qin, Zhan (Qin, Zhan.) [5] | Ren, Kui (Ren, Kui.) [6]

Indexed by:

EI

Abstract:

Recently, model stealing attacks are widely studied but most of them are focused on stealing a single non-discrete model, e.g., neural networks. For ensemble models, these attacks are either non-executable or suffer from intolerant performance degradation due to the complex model structure (multiple sub-models) and the discreteness possessed by the sub-model (e.g., decision trees). To overcome the bottleneck, this paper proposes a divide-and-conquer strategy called DivTheft to formulate the model stealing attack to common ensemble models by combining active learning (AL). Specifically, based on the boosting learning concept, we divide a hard ensemble model stealing task into multiple simpler ones about single sub-model stealing. Then, we adopt AL to conquer the data-free sub-model stealing task. During the process, the current AL algorithm easily causes the stolen model to be biased because of ignoring the past useful memories. Thus, DivTheft involves a newly designed uncertainty sampling scheme to filter reusable samples from the previously used ones. Experiments show that compared with the prior work, DivTheft can save almost 50% queries while ensuring a competitive agreement rate to the victim model. © 2004-2012 IEEE.

Keyword:

Decision trees Learning systems

Community:

  • [ 1 ] [Ma, Zhuo]Xidian University, School of Cyber Engineering, Shaanxi, Xi'an; 710071, China
  • [ 2 ] [Liu, Xinjing]Xidian University, School of Cyber Engineering, Shaanxi, Xi'an; 710071, China
  • [ 3 ] [Liu, Yang]Xidian University, School of Cyber Engineering, Shaanxi, Xi'an; 710071, China
  • [ 4 ] [Liu, Ximeng]Fuzhou University, College of Mathematics and Computer Science, Fujian, Fuzhou; 350025, China
  • [ 5 ] [Liu, Ximeng]Peng Cheng Laboratory, Cyberspace Security Research Center, Guangdong Province, Shenzhen; 518066, China
  • [ 6 ] [Qin, Zhan]Zhejiang University, Institute of Cyberspace Research, Zhejiang, Hangzhou; 310027, China
  • [ 7 ] [Ren, Kui]Zhejiang University, Institute of Cyberspace Research, Zhejiang, Hangzhou; 310027, China

Reprint 's Address:

Email:

Show more details

Related Keywords:

Related Article:

Source :

IEEE Transactions on Dependable and Secure Computing

ISSN: 1545-5971

Year: 2023

Issue: 6

Volume: 20

Page: 4810-4822

7 . 0

JCR@2023

7 . 0 0 0

JCR@2023

JCR Journal Grade:1

CAS Journal Grade:1

Cited Count:

WoS CC Cited Count:

SCOPUS Cited Count:

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 1

Affiliated Colleges:

Online/Total:537/10925848
Address:FZU Library(No.2 Xuyuan Road, Fuzhou, Fujian, PRC Post Code:350116) Contact Us:0591-22865326
Copyright:FZU Library Technical Support:Beijing Aegean Software Co., Ltd. 闽ICP备05005463号-1