ES Attack: Model Stealing Against Deep Neural Networks Without Data Hurdles

Xiaoyong Yuan, Lei Ding, Lan Zhang, Xiaolin Li, Dapeng Oliver Wu · IEEE Transactions on Emerging Topics in Computational Intelligence · 2022

Deep neural networks (DNNs) have become the essential components for various commercialized machine learning services, such as Machine Learning as a Service (MLaaS). Recent studies show that machine learning services face severe privacy threats - well-trained DNNs owned by MLaaS providers can be stolen through public APIs, namely model stealing attacks. However, most existing works undervalued the impact of such attacks, where a successful attack has to acquire confidential training data or auxiliary data regarding the victim DNN. In this paper, we proposeES Attack, a novel model stealing attack without any data hurdles. By using heuristically generated synthetic data,ES Attackiteratively trains a substitute model and eventually achieves a functionally equivalent copy of the victim DNN. The experimental results reveal the severity ofES Attack: i)ES Attacksuccessfully steals the victim model without data hurdles, andES Attackeven outperforms most existing model stealing attacks using auxiliary data in terms of model accuracy; ii) most countermeasures are ineffective in defendingES Attack; iii)ES Attackfacilitates further attacks relying on the stolen model.

Read the paper · More papers on PaperTik