Skip to main navigation Skip to search Skip to main content

Unveiling Intellectual Property Vulnerabilities of GAN-Based Distributed Machine Learning through Model Extraction Attacks

  • Mengyao Ma
  • , Shuofeng Liu
  • , M.A.P. Chamikara
  • , Mohan Baruwal Chhetri
  • , Guangdong Bai

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

Abstract

Generative Adversarial Networks (GANs), as a cornerstone of artificial intelligence (AI), are widely recognized as the intellectual property (IP) of their owners, given the sensitivity of the training data and the commercial value tied to the models. Model extraction attacks, which aim to steal well-trained proprietary models, pose a significant threat to model IP. Nevertheless, current research predominately focuses on the context of machine learning as a service (MLaaS), where the emphasis lies in understanding the attack knowledge acquired through black-box API queries. This restricted perspective exposes a critical gap in investigating model extraction attacks within realistic distributed settings for generative tasks. In this work, we present the first investigation into model extraction attacks against GANs in distributed settings. We provide a comprehensive attack taxonomy, considering three different levels of knowledge the adversary can obtain in practice. Based on it, we introduce a novel model extraction attack named MoEx, which focuses on the GAN-based distributed learning scenario, i.e., Multi-Discriminator GANs, a typical asymmetric distributed setting. MoEx uses the objective function simulation, leveraging data exchanged during the learning process, to approximate the GAN generator owned by the server. We define two attack goals for MoEx, fidelity extraction and accuracy extraction. Then we comprehensively evaluate the effectiveness of MoEx's two goals with real-world datasets. Our results demonstrate its robust capabilities in extracting generators with high fidelity and accuracy compared with existing methods. © 2024 Copyright held by the owner/author(s).
Original languageEnglish
Title of host publicationCIKM '24
Subtitle of host publicationProceedings of the 33rd ACM International Conference on Information and Knowledge Management
PublisherAssociation for Computing Machinery
Pages1617-1626
Number of pages11
ISBN (Print)9798400704369
DOIs
Publication statusPublished - Oct 2024
Externally publishedYes
Event33rd ACM International Conference on Information and Knowledge Management (CIKM 2024) - Boise Centre, Boise, United States
Duration: 21 Oct 202425 Oct 2024
https://cikm2024.org/

Publication series

NameInternational Conference on Information and Knowledge Management, Proceedings
ISSN (Print)2155-0751

Conference

Conference33rd ACM International Conference on Information and Knowledge Management (CIKM 2024)
Abbreviated titleCIKM '24
PlaceUnited States
CityBoise
Period21/10/2425/10/24
Internet address

Funding

Mengyao Ma is supported by the University of Queensland and CSIRO's Data61 PhD scholarship. This work is partially supported by Australian Research Council Discovery Projects (DP230101196, DP240103068).

Research Keywords

  • distributed learning
  • generative adversarial network
  • model extraction attack

Fingerprint

Dive into the research topics of 'Unveiling Intellectual Property Vulnerabilities of GAN-Based Distributed Machine Learning through Model Extraction Attacks'. Together they form a unique fingerprint.

Cite this