Related Experiment Video
Updated: May 24, 2025

06:25
A Real-Time Interactive System for Studying Confrontational Pursuit Behavior in Rodents
Published on: May 16, 2025
55
STDatav2: Accessing Efficient Black-Box Stealing for Adversarial Attacks
Summary
This study enhances surrogate model training by using both synthesized and proxy data to prevent mode collapse. A new self-conditional framework ensures data diversity and class-specific constraints for improved black-box model stealing defenses.
Area of Science:
- Machine Learning
- Artificial Intelligence
- Cybersecurity
Background:
- Stealing black-box models without training data is challenging due to extreme settings.
- Existing methods like Surrogate Training Data (STDatav1) face limitations such as potential mode collapse and maintaining data diversity.
Purpose of the Study:
- To improve the effectiveness of surrogate model training for black-box model stealing.
- To mitigate mode collapse and enhance data diversity and class-specific constraints in surrogate data generation.
Main Methods:
- Proposed a joint-data optimization scheme using both synthesized and proxy data to train the surrogate model.
- Introduced a self-conditional data synthesis framework with pseudo-class mapping for class-specific constraints and diversity.
- Integrated STDatav1's class-specific constraints and designed a dual cross-entropy loss function.
Main Results:
- Demonstrated considerable performance gains compared to the previous STDatav1.
- Evaluations on four datasets using eight models confirmed the approach's competitive ability and potential.
- The proposed methods effectively addressed mode collapse and maintained data diversity and class-specific constraints.
Conclusions:
- The enhanced surrogate training approach offers significant improvements for black-box model stealing.
- The joint-data optimization and self-conditional synthesis framework represent a promising advancement in the field.
- This work provides a robust method for generating high-quality surrogate data, advancing research in model privacy and security.
Related Concept Videos
Stereotype Content Model
13.9K
The Stereotype Content Model (SCM) was first proposed by Susan Fiske and her colleagues (Fiske, Cuddy, Glick & Xu, 2002; see also Fiske, 2012 and Fiske, 2017). The SCM specifies that when someone encounters a new group, they will stereotype them based on two metrics: warmth—or that group’s perceived intent, and how likely they are to provide help or inflict harm—and competence—or their ability to carry out that objective. Depending on the warmth-competence...
13.9K
Blinding
2.4K
Blinding is a commonly used method of not telling participants which treatment a subject is receiving. Blinding is a critical part of a randomized control trial or RCT. It reduces the bias that affects the results. In an RCT, blinding is used in the form of a placebo. A placebo effect occurs when untreated subjects falsely believe they have received the treatment and report improved symptoms. A placebo or a dummy treatment is administered to subjects to negate the bias caused by such an effect.
2.4K
Law of Effect
1.3K
B.F. Skinner, a prominent figure in behavioral psychology, introduced operant conditioning by emphasizing the role of consequences in shaping behavior. This theory builds upon the law of effect proposed by Edward Thorndike, which posits that behaviors followed by satisfying outcomes are likely to be repeated. In contrast, those followed by unsatisfying outcomes are less likely to recur.
Edward Thorndike's foundational work involved studying learning in animals, particularly using puzzle...
Edward Thorndike's foundational work involved studying learning in animals, particularly using puzzle...
1.3K

