Deep learning as a service (DLaaS) has become an effective business solution in numerous domains. Nevertheless, its service form has been proven vulnerable to model inference by previous research. Existing work on model inference attack relies on strong assumptions, such as the attacker knows the sample variance and model structure, which may not thoroughly reflect the attack’s potential threats. In this paper, we propose MC-infer, a zero-knowledge, real-data-free, and black-box model inference method inspired by Monte-Carlo sampling. In particular, MC-infer feeds random noises obtained from different distributions to the target model, and sniffs the corresponding target distributions according to its feedback. Then many samples are taken in these distributions to obtain enough robust noises. Finally, the distribution represented by the target model is fitted through these noises to perform model inference. Our extensive evaluations demonstrate that MC-infer can effectively infer the target model with less information, and general noise perturbation on the model’s outputs cannot defend against MC-infer.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Model Inference Attack Based on Random Sampling in DLaaS

  • Feng Wu,
  • Shouyue Sun,
  • Jiaxun Yang,
  • Liwen Wu,
  • Lei Cui,
  • Youyang Qu,
  • Shaowen Yao

摘要

Deep learning as a service (DLaaS) has become an effective business solution in numerous domains. Nevertheless, its service form has been proven vulnerable to model inference by previous research. Existing work on model inference attack relies on strong assumptions, such as the attacker knows the sample variance and model structure, which may not thoroughly reflect the attack’s potential threats. In this paper, we propose MC-infer, a zero-knowledge, real-data-free, and black-box model inference method inspired by Monte-Carlo sampling. In particular, MC-infer feeds random noises obtained from different distributions to the target model, and sniffs the corresponding target distributions according to its feedback. Then many samples are taken in these distributions to obtain enough robust noises. Finally, the distribution represented by the target model is fitted through these noises to perform model inference. Our extensive evaluations demonstrate that MC-infer can effectively infer the target model with less information, and general noise perturbation on the model’s outputs cannot defend against MC-infer.