Data-Free Model Stealing Attack Based on Denoising Diffusion Probabilistic Model

Guofeng Gao,Xiaodong Wang,Zhiqiang Wei,Jinghai Ai
DOI: https://doi.org/10.1109/swc57546.2023.10448559
2023-01-01
Abstract:Data-free model stealing (MS) attacks use synthetic samples to query a target model and train a substitute model to fit the target model’s predictions, avoiding strong dependence on real datasets used by model developers. However, the existing data-free MS attack methods still have a big gap in generating high-quality query samples for high-precision MS attacks. In this paper, we construct the DDPM-optimized generator to generate data, in which a residual network-like structure is designed to fuse data to synthesize query samples. Our method further improves the quantity and quality of synthetic query samples, and effectively reduces the number of queries to the target model. The results show that the proposed method achieves superior performance compared to state-of-the-art methods.
What problem does this paper attempt to address?