CISPA
Browse
Sha_Cant_Steal_Cont-Steal_Contrastive_Stealing_Attacks_Against_Image_Encoders_CVPR_2023_paper.pdf (4.03 MB)

Can't Steal? Cont-Steal! Contrastive Stealing Attacks Against Image Encoders

Download (4.03 MB)
conference contribution
posted on 2024-03-19, 13:51 authored by Zeyang ShaZeyang Sha, Xinlei He, Ning Yu, Michael BackesMichael Backes, Yang ZhangYang Zhang
Self-supervised representation learning techniques have been developing rapidly to make full use of unlabeled images. They encode images into rich features that are oblivious to downstream tasks. Behind their revolutionary representation power, the requirements for dedicated model designs and a massive amount of computation resources expose image encoders to the risks of potential model stealing attacks - a cheap way to mimic the well-trained encoder performance while circumventing the demanding requirements. Yet conventional attacks only target supervised classifiers given their predicted labels and/or posteriors, which leaves the vulnerability of unsupervised encoders unexplored. In this paper, we first instantiate the conventional stealing attacks against encoders and demonstrate their severer vulnerability compared with downstream classifiers. To better leverage the rich representation of encoders, we further propose Cont-Steal, a contrastive-learning-based attack, and validate its improved stealing effectiveness in various experiment settings. As a takeaway, we appeal to our community's attention to the intellectual property protection of representation learning techniques, especially to the defenses against encoder stealing attacks like ours.

History

Primary Research Area

  • Trustworthy Information Processing

Name of Conference

IEEE Conference on Computer Vision and Pattern Recognition (CVPR)

Volume

00

Page Range

16373-16383

Publisher

Institute of Electrical and Electronics Engineers (IEEE)

Open Access Type

  • Green

BibTeX

@conference{Sha:He:Yu:Backes:Zhang:2023, title = "Can't Steal? Cont-Steal! Contrastive Stealing Attacks Against Image Encoders", author = "Sha, Zeyang" AND "He, Xinlei" AND "Yu, Ning" AND "Backes, Michael" AND "Zhang, Yang", year = 2023, month = 6, pages = "16373--16383", publisher = "Institute of Electrical and Electronics Engineers (IEEE)", doi = "10.1109/cvpr52729.2023.01571" }

Usage metrics

    Categories

    No categories selected

    Licence

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC