Stealing Models from the Cloud

Topics covered
Popular Clips
Episode Highlights
Extraction Techniques
explores the vulnerabilities of machine learning models hosted on cloud services, focusing on model extraction attacks. These attacks exploit the black-box nature of APIs, allowing attackers to reverse-engineer models by sending inputs and analyzing outputs. explains that attackers can achieve high accuracy, sometimes close to 100%, even without knowing the specific algorithm used 1 2.
We have this online service that hosts a model that we cannot access directly. It's a black box, but we can send inputs to it and retrieve the corresponding outputs.
---
He highlights the potential for data privacy leakage, as models may inadvertently reveal training data, such as images from datasets like AT&T Faces 3.
API Privacy
To safeguard against model extraction, suggests several strategies, though he acknowledges the inherent difficulty in completely preventing such attacks. Increasing model complexity and omitting confidence values can make extraction more challenging, yet not impossible 4.
It's not clear to us whether there is a simple strategy that one might use to either detect extraction attacks, it seems like it's inherently impossible to prevent them entirely.
---
Monitoring the number of queries can help detect suspicious activity, but attackers may still operate under the radar by limiting their requests 5.
Related Episodes


Predictive Models on Random Data
Answers 383 questions

MS Build 2017
Answers 383 questions

Predicting Stock Prices
Answers 383 questions

Data Infrastructure in the Cloud
Answers 383 questions

Fraud Detection with Graphs
Answers 383 questions

Reproducing Deep Learning Models
Answers 383 questions

ML Ops Best Practices
Answers 383 questions

Fashion Predictions
Answers 383 questions

Applied Data Science in Industry
Answers 383 questions

Modeling Fake News
Answers 383 questions

Robustness to Unforeseen Adversarial Attacks
Answers 383 questions

AI Roundtable
Answers 383 questions

Customer Clustering
Answers 383 questions

Machine Learning Done Wrong
Answers 383 questions

ML Ops
Answers 383 questions
