跳到主要导航 跳到搜索 跳到主要内容

BESA: Boosting Encoder Stealing Attack With Perturbation Recovery

  • Xuhao Ren
  • , Haotian Liang
  • , Yajie Wang
  • , Chuan Zhang*
  • , Zehui Xiong
  • , Liehuang Zhu
  • *此作品的通讯作者
  • Beijing Institute of Technology
  • Beijing Economic Information Centre
  • Ministry of Education in China
  • Singapore University of Technology and Design

科研成果: 期刊稿件文章同行评审

摘要

To boost the encoder stealing attack under the perturbation-based defense that hinders the attack performance, we propose a boosting encoder stealing attack with perturbation recovery named BESA. It aims to overcome perturbation-based defenses. The core of BESA consists of two modules: perturbation detection and perturbation recovery, which can be combined with canonical encoder stealing attacks. The perturbation detection module utilizes the feature vectors obtained from the target encoder to infer the defense mechanism employed by the service provider. Once the defense mechanism is detected, the perturbation recovery module leverages the well-designed generative model to restore a clean feature vector from the perturbed one. Through extensive evaluations based on various datasets, we demonstrate that BESA significantly enhances the surrogate encoder accuracy of existing encoder stealing attacks by up to 24.63% when facing state-of-the-art defenses and combinations of multiple defenses.

源语言英语
页(从-至)10007-10018
页数12
期刊IEEE Transactions on Information Forensics and Security
20
DOI
出版状态已出版 - 2025
已对外发布

学术指纹

探究 'BESA: Boosting Encoder Stealing Attack With Perturbation Recovery' 的科研主题。它们共同构成独一无二的学术指纹。

引用此