亲爱的研友该休息了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!身体可是革命的本钱,早点休息,好梦!

Matryoshka: Exploiting the Over-Parametrization of Deep Learning Models for Covert Data Transmission

参数化(大气建模) 计算机科学 人工智能 隐蔽的 传输(电信) 功能可见性 深度学习 数据建模 机器学习 电信 人机交互 语言学 哲学 物理 量子力学 数据库 辐射传输
作者
Xudong Pan,Mi Zhang,Yifan Yan,Shengyao Zhang,Min Yang
出处
期刊:IEEE Transactions on Pattern Analysis and Machine Intelligence [IEEE Computer Society]
卷期号:: 1-16 被引量:1
标识
DOI:10.1109/tpami.2024.3434417
摘要

High-quality private machine learning (ML) data stored in local data centers becomes a key competitive factor for AI corporations. In this paper, we present a novel insider attack called Matryoshka to reveal the possibility of breaking the privacy of ML data even with no exposed interface. Our attack employs a scheduled-to-publish DNN model as a carrier model for covert transmission of secret models which memorize the information of private ML data that otherwise has no interface to the outsider. At the core of our attack, we present a novel parameter sharing approach which exploits the learning capacity of the carrier model for information hiding. Our approach simultaneously achieves: (i) High Capacity - With almost no utility loss of the carrier model, Matryoshka can transmit over 10,000 real-world data samples within a carrier model which has 220× less parameters than the total size of the stolen data, and simultaneously transmit multiple heterogeneous datasets or models within a single carrier model under a trivial distortion rate, neither of which can be done with existing steganography techniques; (ii) Decoding Efficiency - once downloading the published carrier model, an outside colluder can exclusively decode the hidden models from the carrier model with only several integer secrets and the knowledge of the hidden model architecture; (iii) Effectiveness - Moreover, almost all the recovered models either have similar performance as if it is trained independently on the private data, or can be further used to extract memorized raw training data with low error; (iv) Robustness - Information redundancy is naturally implemented to achieve resilience against common post-processing techniques on the carrier before its publishing; (v) Covertness - A model inspector with different levels of prior knowledge could hardly differentiate a carrier model from a normal model.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
傻傻的曼柔完成签到,获得积分10
5秒前
rui完成签到,获得积分10
8秒前
9秒前
ll完成签到 ,获得积分10
11秒前
艾欧勾勾完成签到 ,获得积分10
11秒前
机灵柚子应助山山而川采纳,获得20
12秒前
DWQ关注了科研通微信公众号
12秒前
13秒前
彼岸发布了新的文献求助30
16秒前
小蘑菇应助久怨采纳,获得10
17秒前
18秒前
西弗勒斯完成签到 ,获得积分10
21秒前
傲娇的从灵完成签到,获得积分10
22秒前
Lzqqqqq完成签到,获得积分10
24秒前
林子鸿完成签到 ,获得积分10
30秒前
32秒前
多特WU发布了新的文献求助10
35秒前
37秒前
39秒前
加湿器发布了新的文献求助30
39秒前
慕青应助科研通管家采纳,获得10
42秒前
脑洞疼应助科研通管家采纳,获得10
43秒前
Akim应助科研通管家采纳,获得10
43秒前
Dr. Chen发布了新的文献求助10
45秒前
xing_xing应助dsjlove采纳,获得20
47秒前
机灵小林发布了新的文献求助10
47秒前
50秒前
50秒前
Sam完成签到,获得积分10
53秒前
科研通AI6.4应助shyunk采纳,获得10
53秒前
54秒前
兔子发布了新的文献求助10
54秒前
7788发布了新的文献求助10
1分钟前
1分钟前
1分钟前
Dr. Chen完成签到,获得积分10
1分钟前
好久不见发布了新的文献求助10
1分钟前
糟糕的语蝶完成签到,获得积分10
1分钟前
兔子完成签到,获得积分10
1分钟前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Essentials of Carbohydrate Chemistry and Biochemistry, 4th Edition 800
Navigating Normative Orders. Interdisciplinary Perspectives 800
Organizational Behavior 510
Management and the Arts 510
Matrix Methods in Data Mining and Pattern Recognition Second Edition 510
CLSI VET01S-2024 Performance Standards for Antimicrobial Disk and Dilution Susceptibility Tests for Bacteria Isolated From Animals (7th Ed) 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7759364
求助须知:如何正确求助?哪些是违规求助? 9304932
关于积分的说明 20283660
捐赠科研通 7343437
什么是DOI,文献DOI怎么找? 3312528
关于科研通互助平台的介绍 2463078
邀请新用户注册赠送积分活动 2326522