arXiv:2509.11159cs.LG2025-09

用元学习稳定生成数据分布,让盗取模型更可靠。

Stabilizing Data-Free Model Extraction

  • 用元学习让生成数据逐步适应目标模型特征
  • 在多个图像数据集上准确率更稳且更高
  • 适合研究模型安全与对抗攻击的学者

模型提取对机器学习即服务系统构成严重威胁,尤其在无数据方法下,恶意用户可无需真实数据复制黑盒目标模型功能。现有方法存在替代模型准确率波动问题,源于攻击过程中生成数据分布持续变化,导致无法确定最优模型。为此,我们提出MetaDFME,通过在生成器训练中引入元学习,减少分布偏移,缓解替代模型准确率震荡。具体而言,生成器迭代捕捉合成数据的元表征,仅需少量步骤即可适配,生成利于替代模型学习目标模型特征的数据,同时降低分布偏移影响。在MNIST、SVHN、CIFAR-10和CIFAR-100等主流图像数据集上的实验表明,MetaDFME优于当前最先进方法,且在攻击过程中替代模型准确率更稳定。

原文摘要 · Abstract (English)

Model extraction is a severe threat to Machine Learning-as-a-Service systems, especially through data-free approaches, where dishonest users can replicate the functionality of a black-box target model without access to realistic data. Despite recent advancements, existing data-free model extraction methods suffer from the oscillating accuracy of the substitute model. This oscillation, which could be attributed to the constant shift in the generated data distribution during the attack, makes the attack impractical since the optimal substitute model cannot be determined without access to the target model's in-distribution data. Hence, we propose MetaDFME, a novel data-free model extraction method that employs meta-learning in the generator training to reduce the distribution shift, aiming to mitigate the substitute model's accuracy oscillation. In detail, we train our generator to iteratively capture the meta-representations of the synthetic data during the attack. These meta-representations can be adapted with a few steps to produce data that facilitates the substitute model to learn from the target model while reducing the effect of distribution shifts. Our experiments on popular baseline image datasets, MNIST, SVHN, CIFAR-10, and CIFAR-100, demonstrate that MetaDFME outperforms the current state-of-the-art data-free model extraction method while exhibiting a more stable substitute model's accuracy during the attack.

模型提取元学习安全攻防生成模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。