IJCAI 2024poster1 citations

Protecting Object Detection Models from Model Extraction Attack via Feature Space Coverage

Zeyu Li, Yuwen Pu, Xuhong Zhang, Yu Li, Jinbao Li, Shouling Ji

Abstract

The model extraction attack is an attack pattern aimed at stealing well-trained machine learning models' functionality or privacy information. With the gradual popularization of AI-related technologies in daily life, various well-trained models are being deployed. As a result, these models are considered valuable assets and attractive to model extraction attackers. Currently, the academic community primarily focuses on defense for model extraction attacks in the context of classification, with little attention to the more commonly used task scenario of object detection. Therefore, we propose a detection framework targeting model extraction attacks against object detection models in this paper. The framework first locates suspicious users based on feature coverage in query traffic and uses an active verification module to confirm whether the identified suspicious users are attackers. Through experiments conducted in multiple task scenarios, we validate the effectiveness and detection efficiency of the proposed method.

AI Ethics, Trust, Fairness: ETF: Safety and robustnessComputer Vision: CV: Recognition (object detection, categorization)
BibTeX
@inproceedings{ijcai2024p48,
  title     = {Protecting Object Detection Models from Model Extraction Attack via Feature Space Coverage},
  author    = {Li, Zeyu and Pu, Yuwen and Zhang, Xuhong and Li, Yu and Li, Jinbao and Ji, Shouling},
  booktitle = {Proceedings of the Thirty-Third International Joint Conference on
               Artificial Intelligence, {IJCAI-24}},
  publisher = {International Joint Conferences on Artificial Intelligence Organization},
  editor    = {Kate Larson},
  pages     = {431--439},
  year      = {2024},
  month     = {8},
  note      = {Main Track},
  doi       = {10.24963/ijcai.2024/48},
  url       = {https://doi.org/10.24963/ijcai.2024/48},
}
Protecting Object Detection Models from Model Extraction Attack via Feature Space Coverage · IJCAI 2024