article Open access

Model Protection Scheme Against Distillation Attack in Internet of Vehicles

  • ICST Transactions on e-Education and e-Learning
  • Institute for Computer Sciences, Social Informatics and Telecommunications Engineering
Research footprint

At a glance

Citations
0
References
28
Comments
0
Paper overview

Öz

Aiming at the problems of model security and user data disclosure caused by the deep learning model in the Internet of Vehicles scenario, which can be stolen by malicious roadside units or base stations and other attackers through knowledge distillation and other techniques, this paper proposes a scheme to strengthen prevent against distillation. The scheme exploits the idea of model reinforcement such as model self-learning and attention mechanism to maximize the difference between the pre-trained model and the normal model without sacrificing performance. It also combines local differential privacy technology to reduce the effectiveness of model inversion attacks. Our experimental results on several datasets show that this method is effective for both standard and data-free knowledge distillation, and provides better model protection than passive defense.

Record transparency

Publication details

DOI
10.4108/eetel.v8i3.3318
OpenAlex
W4382242890
Document type
article
Language
EN
Source
ICST Transactions on e-Education and e-Learning
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.