arXiv:2505.23791cs.CRcs.AI2025-05中稿 · IEEE IWCMC被引 1

研究联邦学习模型如何被高效提取,揭示预训练模型能显著降低攻击查询量。

Evaluating Query Efficiency and Accuracy of Transfer Learning-based Model Extraction Attack in Federated Learning

  • 用迁移学习初始化提取模型,减少所需查询次数。
  • 查询集越大,提取模型准确率和保真度越高,尤其在小查询集下优势明显。
  • 适合关注联邦学习安全性的研究人员和系统设计者。

联邦学习(FL)是一种旨在保护客户端数据的协作学习框架,但仍面临知识产权(IP)威胁。模型提取(ME)攻击对机器学习即服务(MLaaS)平台构成重大风险,攻击者可通过查询黑盒接口复制保密模型。尽管FL具有隐私保护目标,其分布式特性使其极易受到此类攻击。本文评估了基于FL的受害模型对两类模型提取攻击的脆弱性。针对在NVFlare平台上构建的不同联邦客户端,我们使用两种深度学习架构和三个图像数据集实施了ME攻击。通过准确率、保真度和KL散度等指标评估攻击性能。实验表明,不同FL客户端的提取模型准确率与保真度与其攻击查询集大小密切相关。此外,我们探索了一种基于迁移学习的方法,以预训练模型作为提取起点。结果表明,微调后的预训练提取模型准确率和保真度显著更高,尤其在较小查询集下表现突出,凸显了对攻击者的潜在优势。

原文摘要 · Abstract (English)

Federated Learning (FL) is a collaborative learning framework designed to protect client data, yet it remains highly vulnerable to Intellectual Property (IP) threats. Model extraction (ME) attacks pose a significant risk to Machine Learning as a Service (MLaaS) platforms, enabling attackers to replicate confidential models by querying black-box (without internal insight) APIs. Despite FL's privacy-preserving goals, its distributed nature makes it particularly susceptible to such attacks. This paper examines the vulnerability of FL-based victim models to two types of model extraction attacks. For various federated clients built under the NVFlare platform, we implemented ME attacks across two deep learning architectures and three image datasets. We evaluate the proposed ME attack performance using various metrics, including accuracy, fidelity, and KL divergence. The experiments show that for different FL clients, the accuracy and fidelity of the extracted model are closely related to the size of the attack query set. Additionally, we explore a transfer learning based approach where pretrained models serve as the starting point for the extraction process. The results indicate that the accuracy and fidelity of the fine-tuned pretrained extraction models are notably higher, particularly with smaller query sets, highlighting potential advantages for attackers.

联邦学习模型提取迁移学习安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。