arXiv:2602.09748math.OCcs.LG2026-02

通过事实与反事实查询,仅用少量数据即可提取线性模型参数。

Linear Model Extraction via Factual and Counterfactual Queries

  • 基于事实与反事实查询构建分类区域的数学模型。
  • 使用可微距离时,单次反事实查询即可还原完整模型。
  • 模型安全性受距离函数类型和鲁棒性影响显著,适合安全评估者阅读。

在模型提取攻击中,目标是通过向黑盒机器学习模型查询一组数据点来揭示其参数。随着对解释性的需求增加,此类查询可能不仅包含通常考虑的事实查询,还包含反事实查询。本文研究线性模型及三类查询:事实、反事实和鲁棒反事实。首先,针对任意查询集,我们推导出无需恢复任何模型参数即可确定未知模型决策区域的新型数学公式。其次,我们推导出在任意基于范数的距离下,提取(鲁棒)反事实查询模型参数所需查询次数的上界。结果表明,当采用可微距离度量时,仅需一次反事实查询即可完全恢复模型;而使用多面体距离时,所需查询次数随数据维度线性增长。对于鲁棒反事实查询,该数量翻倍。因此,所用距离函数及反事实的鲁棒性对模型安全性有显著影响。

原文摘要 · Abstract (English)

In model extraction attacks, the goal is to reveal the parameters of a black-box machine learning model by querying the model for a selected set of data points. Due to an increasing demand for explanations, this may involve counterfactual queries besides the typically considered factual queries. In this work, we consider linear models and three types of queries: factual, counterfactual, and robust counterfactual. First, for an arbitrary set of queries, we derive novel mathematical formulations for the classification regions for which the decision of the unknown model is known, without recovering any of the model parameters. Second, we derive bounds on the number of queries needed to extract the model's parameters for (robust) counterfactual queries under arbitrary norm-based distances. We show that the full model can be recovered using just a single counterfactual query when differentiable distance measures are employed. In contrast, when using polyhedral distances for instance, the number of required queries grows linearly with the dimension of the data space. For robust counterfactuals, the latter number of queries doubles. Consequently, the applied distance function and robustness of counterfactuals have a significant impact on the model's security.

模型提取反事实查询线性模型安全性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。