PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
January 1, 202223 citationsOpen Access

Get a Model! Model Hijacking Attack Against Machine Learning Models

ASAhmed SalemMBMichael BackesYZYang Zhang

Key Points

Key points are not available for this paper at this time.

Abstract

Machine learning (ML) has established itself as a cornerstone for various critical applications ranging from autonomous driving to authentication systems. However, with this increasing adoption rate of machine learning models, multiple attacks have emerged. One class of such attacks is training time attack, whereby an adversary executes their attack before or during the machine learning model training. In this work, we propose a new training time attack against computer vision based machine learning models, namely model hijacking attack. The adversary aims to hijack a target model to execute a different task than its original one without the model owner noticing. Model hijacking can cause accountability and security risks since a hijacked model owner can be framed for having their model offering illegal or unethical services. Model hijacking attacks are launched in the same way as existing data poisoning attacks. However, one requirement of the model hijacking attack is to be stealthy, i.e., the data samples used to hijack the target model should look similar to the model's original training dataset. To this end, we propose two different model hijacking attacks, namely Chameleon and Adverse Chameleon, based on a novel encoder-decoder style ML model, namely the Camouflager. Our evaluation shows that both of our model hijacking attacks achieve a high attack success rate, with a negligible drop in model utility. 1

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Salem et al. (2022) studied this question.

synapsesocial.com/papers/6a08be6687fb8448dcba0174https://doi.org/10.14722/ndss.2022.23064
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 4 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Dynamic Backdoor Attacks Against Machine Learning Models2022 · 227 citations
  2. 2ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models2019 · 88 citations
  3. 3You Autocomplete Me: Poisoning Vulnerabilities in Neural Code Completion2021 · 47 citations
  4. 4Very Deep Convolutional Networks for Large-Scale Image Recognition2014 · 75,491 citations