Abstract
Generative Adversarial Networks (GANs), as a cornerstone of artificial intelligence (AI), are widely recognized as the intellectual property (IP) of their owners, given the sensitivity of the training data and the commercial value tied to the models. Model extraction attacks, which aim to steal well-trained proprietary models, pose a significant threat to model IP. Nevertheless, current research predominately focuses on the context of machine learning as a service (MLaaS), where the emphasis lies in understanding the attack knowledge acquired through black-box API queries. This restricted perspective exposes a critical gap in investigating model extraction attacks within realistic distributed settings for generative tasks. In this work, we present the first investigation into model extraction attacks against GANs in distributed settings. We provide a comprehensive attack taxonomy, considering three different levels of knowledge the adversary can obtain in practice. Based on it, we introduce a novel model extraction attack named MoEx, which focuses on the GAN-based distributed learning scenario, i.e., Multi-Discriminator GANs, a typical asymmetric distributed setting. MoEx uses the objective function simulation, leveraging data exchanged during the learning process, to approximate the GAN generator owned by the server. We define two attack goals for MoEx, fidelity extraction and accuracy extraction. Then we comprehensively evaluate the effectiveness of MoEx's two goals with real-world datasets. Our results demonstrate its robust capabilities in extracting generators with high fidelity and accuracy compared with existing methods. © 2024 Copyright held by the owner/author(s).
| Original language | English |
|---|---|
| Title of host publication | CIKM '24 |
| Subtitle of host publication | Proceedings of the 33rd ACM International Conference on Information and Knowledge Management |
| Publisher | Association for Computing Machinery |
| Pages | 1617-1626 |
| Number of pages | 11 |
| ISBN (Print) | 9798400704369 |
| DOIs | |
| Publication status | Published - Oct 2024 |
| Externally published | Yes |
| Event | 33rd ACM International Conference on Information and Knowledge Management (CIKM 2024) - Boise Centre, Boise, United States Duration: 21 Oct 2024 → 25 Oct 2024 https://cikm2024.org/ |
Publication series
| Name | International Conference on Information and Knowledge Management, Proceedings |
|---|---|
| ISSN (Print) | 2155-0751 |
Conference
| Conference | 33rd ACM International Conference on Information and Knowledge Management (CIKM 2024) |
|---|---|
| Abbreviated title | CIKM '24 |
| Place | United States |
| City | Boise |
| Period | 21/10/24 → 25/10/24 |
| Internet address |
Funding
Mengyao Ma is supported by the University of Queensland and CSIRO's Data61 PhD scholarship. This work is partially supported by Australian Research Council Discovery Projects (DP230101196, DP240103068).
Research Keywords
- distributed learning
- generative adversarial network
- model extraction attack
Fingerprint
Dive into the research topics of 'Unveiling Intellectual Property Vulnerabilities of GAN-Based Distributed Machine Learning through Model Extraction Attacks'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver