Model Stealing Detection for IoT Services Based on Multi-Dimensional Features

Xinjing Liu,Taifeng Liu,Hao Yang,Jiakang Dong,Zuobin Ying,Zhuo Ma
DOI: https://doi.org/10.1109/JIOT.2024.3386670
IF: 10.6
2024-01-01
IEEE Internet of Things Journal
Abstract:Model stealing (MS) attacks pose a significant security concern for machine learning models on cloud platforms, as they can reconstruct a substitute model with limited effort to evade ownership. While detection-based methods show promise in preventing MS attacks, they often face practical challenges. Specifically, setting an appropriate threshold to distinguish malicious features from benign ones is a difficult task, often leading to a trade-off between false alarm rates and detection accuracy. To address this challenge, we design a multi-dimensional feature extraction-and-distinction scheme called MED. It is achieved through a two-layer optimization: 1) the inner layer of extraction to maximize the difference of extracted multi-dimensional features between attack and benign samples; 2) the outer layer of distinction to maximize the accuracy of distinguishing malicious features automatically. Recognizing that different MS attacks result in varied features, we design a group of feature extraction functions in the inner layer optimization, which addresses the limitations of single-feature based detection methods. Further, we employ three differently characterized models for distinction, enabling MED to distinguish different types of malicious features. Comprehensive experiments are conducted to evaluate the effectiveness of the proposed scheme: MED can detect all types of MS attacks with no more than 100 samples, with an average detection rate greater than 0.99.
What problem does this paper attempt to address?