Skip to main navigation Skip to search Skip to main content

Unlocking High-Fidelity Learning: Towards Neuron-Grained Model Extraction

Research output: Journal article publicationJournal articleAcademic researchpeer-review

Abstract

Model extraction (ME) attacks replicate valuable closed-box machine learning (ML) models via malicious query interactions. Cutting-edge attacks focus on actively designing query samples to enhance model fidelity and imprudently adhere to the standard ML training approach. This causes a deviation from the true objective of learning a model over a task. In this article, we innovatively shift our focus from query selection to training process optimization, aiming to boost the similarity of the copy model with the victim model from neuron to model level. We leverage neuron matching theory to attain this objective and develop a general training booster framework, MEBooster, to fully exploit this theory. MEBooster comprises an initial bootstrapping phase that furnishes initial parameters and an optimal model architecture, followed by a post-processing phase that employs fine-tuning for enhanced neuron matching. Notably, MEBooster can seamlessly integrate with all existing model extraction attacks, enhancing their overall performance. Performance evaluation shows up to 58.10% fidelity gain in image classification. From a defender's perspective, we introduce a novel defensive strategy called Stochastic Norm Enlargement (SNE) to mitigate the risk of such attacks by enlarging the model parameters' norm property in training. Performance evaluation shows up to 58.81% extractability (i.e., fidelity) reduction.

Original languageEnglish
Pages (from-to)6622-6635
Number of pages14
JournalIEEE Transactions on Dependable and Secure Computing
Volume22
Issue number6
DOIs
Publication statusPublished - Jul 2025

Keywords

  • Machine learning privacy (ML)
  • defense against model extraction
  • model extraction attack

ASJC Scopus subject areas

  • General Computer Science
  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'Unlocking High-Fidelity Learning: Towards Neuron-Grained Model Extraction'. Together they form a unique fingerprint.

Cite this