דלג לתוכן (מקש קיצור 's')
אירועים

אירועים והרצאות בפקולטה למדעי המחשב ע"ש הנרי ומרילין טאוב

חילוץ רשתות קונבולוציה באמצעות התקפה מבוססת הנדסה לאחור
event speaker icon
יהונתן לוסקי (הרצאה סמינריונית למגיסטר)
event date icon
יום שלישי, 11.02.2025, 14:00
event location icon
טאוב 601 & זום
event speaker icon
מנחה: Prof. Avi Mendelson

The extraction of neural networks poses a significant challenge to the security and intellectual property of AI models, enabling adversaries to recreate proprietary architectures, breach confidentiality, and exploit model functionality. In this seminar talk, I will introduce a novel attack that reconstructs both the structure and exact parameters of black-box convolutional neural networks (CNNs), using only query-based access. This technique is the first to recover the precise weight values and architecture of black-box CNNs. This method allows the extraction of common CNN models, including LeNet-5, AlexNet, and various VGG and ResNet architectures. I will outline the theoretical foundations of the attack and demonstrate its effectiveness through extractions of multiple architectures. This work highlights the real-world feasibility of model extraction and its broader implications for AI security.