Consider a model extraction attack. Assuming that the model is a simple deep neural network, the attacker can use the returned score from the server and solve a linear equation to compute the weights. Assume the server applies a defense technique that limits the number of queries that the attacker can submit, e.g., set the limit m = 4. The attacker submits the following queries. [1, 0, 1, 1, 5, 3, 6, 3] -> received feedback score [8] [9, 3, 10, 0, 2, 3, 4, 8] -> received feedback score [2] [12, 0, -4, 1, 8, 3, 6, 15] -> received feedback score [0] [1, 0, -2, -4, -2, 8, 9, 12] -> received feedback score [3] Now in order to solve Ax = b (x is the weights of the model), the attacker needs to submit 4 more queries, but it is limited by the server to 4. Thus, what the attacker can do is to approximate x with least square approximation: A^T A x^{hat} = A^T b, and solve for x^{hat}. Show your step of calculating x^{hat}. Question gives a 8*8 matrix when applying the A^T•A

Computer Networking: A Top-Down Approach (7th Edition)
7th Edition
ISBN:9780133594140
Author:James Kurose, Keith Ross
Publisher:James Kurose, Keith Ross
Chapter1: Computer Networks And The Internet
Section: Chapter Questions
Problem R1RQ: What is the difference between a host and an end system? List several different types of end...
icon
Related questions
Question

Consider a model extraction attack. Assuming that the model is a simple deep neural network, the attacker can use the returned score from the server and solve a linear equation to compute the weights. Assume the server applies a defense technique that limits the number of queries that the attacker can submit, e.g., set the limit m = 4. The attacker submits the following queries.

[1, 0, 1, 1, 5, 3, 6, 3] -> received feedback score [8]

[9, 3, 10, 0, 2, 3, 4, 8] -> received feedback score [2]

[12, 0, -4, 1, 8, 3, 6, 15] -> received feedback score [0]

[1, 0, -2, -4, -2, 8, 9, 12] -> received feedback score [3]

Now in order to solve Ax = b (x is the weights of the model), the attacker needs to submit 4 more queries, but it is limited by the server to 4. Thus, what the attacker can do is to approximate x with least square approximation: A^T A x^{hat} = A^T b, and solve for x^{hat}. Show your step of calculating x^{hat}. Question gives a 8*8 matrix when applying the A^T•A

Expert Solution
trending now

Trending now

This is a popular solution!

steps

Step by step

Solved in 2 steps

Blurred answer
Recommended textbooks for you
Computer Networking: A Top-Down Approach (7th Edi…
Computer Networking: A Top-Down Approach (7th Edi…
Computer Engineering
ISBN:
9780133594140
Author:
James Kurose, Keith Ross
Publisher:
PEARSON
Computer Organization and Design MIPS Edition, Fi…
Computer Organization and Design MIPS Edition, Fi…
Computer Engineering
ISBN:
9780124077263
Author:
David A. Patterson, John L. Hennessy
Publisher:
Elsevier Science
Network+ Guide to Networks (MindTap Course List)
Network+ Guide to Networks (MindTap Course List)
Computer Engineering
ISBN:
9781337569330
Author:
Jill West, Tamara Dean, Jean Andrews
Publisher:
Cengage Learning
Concepts of Database Management
Concepts of Database Management
Computer Engineering
ISBN:
9781337093422
Author:
Joy L. Starks, Philip J. Pratt, Mary Z. Last
Publisher:
Cengage Learning
Prelude to Programming
Prelude to Programming
Computer Engineering
ISBN:
9780133750423
Author:
VENIT, Stewart
Publisher:
Pearson Education
Sc Business Data Communications and Networking, T…
Sc Business Data Communications and Networking, T…
Computer Engineering
ISBN:
9781119368830
Author:
FITZGERALD
Publisher:
WILEY