arXiv:2508.15031cs.CRcs.AI2025-08综述被引 10

系统梳理模型提取攻击与防御,揭示云端模型安全风险。

A Systematic Survey of Model Extraction Attacks and Defenses: State-of-the-Art and Perspectives

  • 按攻击机制、防御方法和计算环境构建新分类体系
  • 分析多种攻击有效性,指出安全与性能的权衡难题
  • 适合关注AI安全、隐私保护的研究者与从业者

机器学习模型日益复杂且应用广泛,推动多领域发展。但训练成本高、专业门槛大,限制了其普及。Machine-Learning-as-a-Service(MLaaS)平台通过友好的API提供高效、低成本的模型服务,提升了可访问性,也带来了模型提取攻击(MEA)风险。研究显示,攻击者可通过公开接口系统性复制目标模型功能,威胁知识产权、隐私和系统安全。本文系统综述当前主流的模型提取攻击与防御策略,提出涵盖攻击机制、防御手段和计算环境的新分类框架。分析多种攻击技术的有效性,评估现有防御措施的局限性,尤其强调在保持模型可用性与保障安全性之间的关键权衡。进一步探讨不同计算范式下的攻击影响,讨论其技术、伦理、法律及社会意义,并展望未来研究方向。本综述旨在为从事人工智能安全与隐私研究的学者、实践者及政策制定者提供参考。相关文献持续更新于GitHub仓库:https://github.com/kzhao5/ModelExtractionPapers。

原文摘要 · Abstract (English)

Machine learning (ML) models have significantly grown in complexity and utility, driving advances across multiple domains. However, substantial computational resources and specialized expertise have historically restricted their wide adoption. Machine-Learning-as-a-Service (MLaaS) platforms have addressed these barriers by providing scalable, convenient, and affordable access to sophisticated ML models through user-friendly APIs. While this accessibility promotes widespread use of advanced ML capabilities, it also introduces vulnerabilities exploited through Model Extraction Attacks (MEAs). Recent studies have demonstrated that adversaries can systematically replicate a target model's functionality by interacting with publicly exposed interfaces, posing threats to intellectual property, privacy, and system security. In this paper, we offer a comprehensive survey of MEAs and corresponding defense strategies. We propose a novel taxonomy that classifies MEAs according to attack mechanisms, defense approaches, and computing environments. Our analysis covers various attack techniques, evaluates their effectiveness, and highlights challenges faced by existing defenses, particularly the critical trade-off between preserving model utility and ensuring security. We further assess MEAs within different computing paradigms and discuss their technical, ethical, legal, and societal implications, along with promising directions for future research. This systematic survey aims to serve as a valuable reference for researchers, practitioners, and policymakers engaged in AI security and privacy. Additionally, we maintain an online repository continuously updated with related literature at https://github.com/kzhao5/ModelExtractionPapers.

模型安全攻击防御AI隐私综述

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。