arXiv:2502.16065cs.CRcs.AI2025-02综述被引 10

系统梳理分布式环境下的模型窃取攻击与防御方法

A Survey of Model Extraction Attacks and Defenses in Distributed Computing Environments

  • 从云、边缘、联邦学习三类环境出发,分析攻击路径差异
  • 指出当前评估方法存在局限,易低估真实威胁风险
  • 适合关注AI安全的工程师与决策者阅读

模型提取攻击(MEAs)正威胁现代机器学习系统,使攻击者能窃取模型,暴露知识产权和训练数据。随着机器学习模型在云、边缘及联邦学习等分布式计算环境中的广泛应用,各类部署模式带来独特的漏洞与挑战。缺乏对这些环境中MEAs的统一视角,将导致防御碎片化、风险评估不足,造成重大经济与隐私损失。本文系统梳理了不同分布式环境下攻击方法与防御机制的演进,揭示环境特征如何影响关键领域(如自动驾驶、医疗、金融)的安全策略。通过整合最新研究成果,分析现有评估方法的局限性,为构建鲁棒且自适应的防御体系提供关键洞见。强调需在整个分布式计算生态中集成防护措施,以保障模型的安全部署。

原文摘要 · Abstract (English)

Model Extraction Attacks (MEAs) threaten modern machine learning systems by enabling adversaries to steal models, exposing intellectual property and training data. With the increasing deployment of machine learning models in distributed computing environments, including cloud, edge, and federated learning settings, each paradigm introduces distinct vulnerabilities and challenges. Without a unified perspective on MEAs across these distributed environments, organizations risk fragmented defenses, inadequate risk assessments, and substantial economic and privacy losses. This survey is motivated by the urgent need to understand how the unique characteristics of cloud, edge, and federated deployments shape attack vectors and defense requirements. We systematically examine the evolution of attack methodologies and defense mechanisms across these environments, demonstrating how environmental factors influence security strategies in critical sectors such as autonomous vehicles, healthcare, and financial services. By synthesizing recent advances in MEAs research and discussing the limitations of current evaluation practices, this survey provides essential insights for developing robust and adaptive defense strategies. Our comprehensive approach highlights the importance of integrating protective measures across the entire distributed computing landscape to ensure the secure deployment of machine learning models.

模型安全攻击防御联邦学习分布式

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。