article وصول مفتوح

Model Protection Scheme Against Distillation Attack in Internet of Vehicles

  • ICST Transactions on e-Education and e-Learning
  • Institute for Computer Sciences, Social Informatics and Telecommunications Engineering
Research footprint

At a glance

الاستشهادات
0
المراجع
28
Comments
0
Paper overview

Abstract

Aiming at the problems of model security and user data disclosure caused by the deep learning model in the Internet of Vehicles scenario, which can be stolen by malicious roadside units or base stations and other attackers through knowledge distillation and other techniques, this paper proposes a scheme to strengthen prevent against distillation. The scheme exploits the idea of model reinforcement such as model self-learning and attention mechanism to maximize the difference between the pre-trained model and the normal model without sacrificing performance. It also combines local differential privacy technology to reduce the effectiveness of model inversion attacks. Our experimental results on several datasets show that this method is effective for both standard and data-free knowledge distillation, and provides better model protection than passive defense.

Record transparency

Publication details

DOI
10.4108/eetel.v8i3.3318
OpenAlex
W4382242890
Document type
article
Language
EN
Source
ICST Transactions on e-Education and e-Learning
Last metadata update
المجتمع

Comments

تسجيل الدخول للانضمام إلى النقاش.

  1. لا توجد تعليقات بعد. ابدأ النقاش.