Model Extraction Attacks on Text-to-Image Generative Adversarial Networks
At a glance
- Citations
- 0
- References
- 27
- Comments
- 0
Abstract
Model extraction attack refers to attackers ille-gally obtaining the functionality of a victim model by querying it. Currently, attacks primarily focus on discriminative models in computer vision. However, model extraction attacks on generative models, especially tasks like generating images from text, remain underexplored. The task of generating corresponding images for text is not only captivating but also highly challenging. In this study, we are the first to comprehensively investigate the feasibility of executing model extraction attacks on Text-to-Image Generative Adversarial Networks (T2I-GANs). To provide a more nuanced understanding, we introduce the concepts of fidelity and accuracy in model extraction attacks targeting T2I-GANs. Extensive experimental validation in black-box attack scenarios demonstrates that we achieve high-fidelity and high-accuracy extraction of T2I-GAN models. We employ the CLIP model to filter queried data, resulting in a fidelity of 81 % for the substitute model. Furthermore, through subsampling techniques, we effectively filter high-quality samples that closely resemble the distribution of real datasets, thereby increasing accuracy to 87 %.
Publication details
- DOI
- 10.1109/cyberscitech64112.2024.00050
- OpenAlex
- W4405602171
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.