<div class="csl-bib-body">
<div class="csl-entry">Oliynyk, D. (2023). <i>Man of steal: Exploring model stealing attacks against image classifiers</i> [Diploma Thesis, Technische Universität Wien]. reposiTUm. https://doi.org/10.34726/hss.2023.102080</div>
</div>
-
dc.identifier.uri
https://doi.org/10.34726/hss.2023.102080
-
dc.identifier.uri
http://hdl.handle.net/20.500.12708/189365
-
dc.description.abstract
Machine learning models offered as a service are the most common targets for a model stealing attack that aims to reproduce a model's behaviour without its owner's consent. Such attacks lead to intellectual property violations and unfair competition, bringing more attention to the topic. This work analyses the most significant group of model stealing attacks against black-box image classifiers. We categorise relevant work based on the considered attacker's profile, and highlight inconsistencies in experiment design and attack evaluation that lead to comparability issues. Further, we conduct experiments against CNN image classifiers and investigate how different attacker's capabilities and attack optimisation techniques impact the attack's performance. In particular, we propose a novel data-free attack, which is significantly more efficient while having comparable performance with the state-of-the-art. Subsequently, we study three data-perturbation defences as countermeasures against model stealing attacks and investigate how they affect the utility of the target model. Finally, we re-visit the related work issues and propose solutions for each to ensure comparability in future work.
en
dc.language
English
-
dc.language.iso
en
-
dc.rights.uri
http://rightsstatements.org/vocab/InC/1.0/
-
dc.subject
Machine Learning
en
dc.subject
Model Stealing
en
dc.subject
Convolutional Neural Networks
en
dc.title
Man of steal: Exploring model stealing attacks against image classifiers
en
dc.type
Thesis
en
dc.type
Hochschulschrift
de
dc.rights.license
In Copyright
en
dc.rights.license
Urheberrechtsschutz
de
dc.identifier.doi
10.34726/hss.2023.102080
-
dc.contributor.affiliation
TU Wien, Österreich
-
dc.rights.holder
Daryna Oliynyk
-
dc.publisher.place
Wien
-
tuw.version
vor
-
tuw.thesisinformation
Technische Universität Wien
-
dc.contributor.assistant
Mayer, Rudolf
-
tuw.publication.orgunit
E194 - Institut für Information Systems Engineering