摘要
To boost the encoder stealing attack under the perturbation-based defense that hinders the attack performance, we propose a boosting encoder stealing attack with perturbation recovery named BESA. It aims to overcome perturbation-based defenses. The core of BESA consists of two modules: perturbation detection and perturbation recovery, which can be combined with canonical encoder stealing attacks. The perturbation detection module utilizes the feature vectors obtained from the target encoder to infer the defense mechanism employed by the service provider. Once the defense mechanism is detected, the perturbation recovery module leverages the well-designed generative model to restore a clean feature vector from the perturbed one. Through extensive evaluations based on various datasets, we demonstrate that BESA significantly enhances the surrogate encoder accuracy of existing encoder stealing attacks by up to 24.63% when facing state-of-the-art defenses and combinations of multiple defenses.
| 源语言 | 英语 |
|---|---|
| 页(从-至) | 10007-10018 |
| 页数 | 12 |
| 期刊 | IEEE Transactions on Information Forensics and Security |
| 卷 | 20 |
| DOI | |
| 出版状态 | 已出版 - 2025 |
| 已对外发布 | 是 |
学术指纹
探究 'BESA: Boosting Encoder Stealing Attack With Perturbation Recovery' 的科研主题。它们共同构成独一无二的学术指纹。引用此
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver