Model Extraction Attacks

Whether or not you are paying attention to the changing cyber security landscape, you have to be more and more aware of the use of AI in attack vectors.  Google Threat Intelligence issued a very instructive post on the threats posed by AI.  It is divided into different sections, with each focusing on a variety of methodologies that intersect with the use of AI.  The important thing for cyber protectors to recognize is that these tools are not going anywhere and they do pose a threat. 

As in most security practices the phrase, “We have to be right every time, the enemy only has to be right once” holds true here.  The cyber criminal element has embraced the use of AI and we protectors must do the same, or risk losing the security of our data and networks. 

Google’s post, which is listed below as a resource, noted that the Google Threat Intelligence Group (GTIG) has observed threat actors using AI tools to do the following:

  1.  Accelerate the attack lifecycle
  2. Increase their ability to perform reconnaissance, social engineering and creating malware

All of this increases speed for certain.  It gives the attackers increased abilities to craft their malware and information gathering. 

In the first attack exposed in the article it is called Model Extraction Attacks (MEA).  Yes, we do love our acronyms, do we not?  But I digress.  The MEA happens when the attack manages to use legitimate access to systematically explore mature machine learning model to extract the information needed to train a new model.  The attackers use a technique which is called knowledge distillation (KD).  There is another acronym for you! 

Fig. 1:  Googles’ Illustration of model extraction attacks (MEA)

Google does an excellent job of breaking down this attack format and present it in a usable form. 

So, what are some of the impacts you could expect from such an attack:

  1.  IP theft: the attacker can clone/steal expensive and proprietary models without paying the original cost.  This can include a host of data that is included with the model thefts. 
  2. Privacy violations: with the rapid integration and use of AI, often without proper training or security review, could expose data.  This data can come from training the LMs or from end users entering that data into AI models that are not properly secured. 
  3. Precursor to future attacks: once the attackers have stolen the models, they will certainly use the opportunity to explore different methods of attack.  Never think that an attacker will hit you once and then leave.  They will return and you should be prepared.

There are several videos on YouTube that can help you further explore this attack vector.  In future posts I hope to explore the other information contained in Googles report. 

Resources:  https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use?e=48754805

Leave a Reply

Discover more from Dave Does Cyber Security

Subscribe now to keep reading and get access to the full archive.

Continue reading