Model Stealing Attack Based on Sampling and Weighting

Yixu WANG,Jie LI,Hong LIU,Yan WANG,Mingliang XU,Yongjian WU,Rongrong JI
DOI: https://doi.org/10.1360/ssi-2022-0029
2023-01-01
Abstract:A model stealing attack aims to create a substitute model that steals the task completion ability of the target victim model. Popular approaches have used data generation/selection and entropy loss to achieve promising attack performance. In this paper, we explore two overlooked yet effective components of the attack,data sampling and weighting. We propose a novel method named S&W that provides a sampling scheme and a softlabel weighted loss function. First, we propose a data selection strategy that pays more attention to important samples for stealing more information from the victim model. Then, we introduce the k-Center algorithm to guarantee the selected subset’s diversity, aiming to make the core-set selection tractable. Second, we propose a weighted entropy loss inspired by the focal loss that mainly focuses on the difference in outputs of the victim and the stealing models, allowing the substitute model to better simulate the victim model. Extensive experiments on four widely used datasets consistently show that our proposed method outperforms state-of-the-art methods,with a maximum improvement of 5.03% over the next best method.
What problem does this paper attempt to address?