Softmax Temperature Parameter for Model Extraction Risk Estimation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for estimating learning devices, especially those using softmax functions for multi-value classification, are ineffective in expressing the device as a linear expression, leading to significant deviations in correct answer rates for fake learning devices created through model extraction attacks, making it difficult to evaluate the risk of such attacks effectively.
Innovation Solution
A learning device estimating apparatus and method that utilizes a recording, inquiring, and learning part with an activation function outputting an ambiguous value, such as a softmax function with temperature, to effectively estimate and evaluate the risk of attack target learning devices by reducing generalization error and determining correct answer rates with a small amount of data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a softmax function is used for multi-value classification in a learning device, then the classification capability is improved, but the device cannot be expressed by a linear expression, making model extraction attacks ineffective
Solution Approach 1:
The patent applies parameter changes by introducing a temperature parameter to the softmax function, transforming it into a softmax function with temperature. This modification allows the function to output ambiguous values rather than definitive classifications, enabling the learning device to be effectively expressed and estimated through linear expressions while maintaining its classification capability. The temperature parameter controls the degree of ambiguity, bridging the gap between complex nonlinear classification and linear expressibility.
2Productivity
If model extraction attacks are performed using existing methods, then prediction results are obtained, but the correct answer rate of fake learning devices deviates significantly from the target learning device
Solution Approach 1:
The patent implements feedback by using the output of the softmax function with temperature as training data for creating fake learning devices. The ambiguous values produced by the modified softmax function provide feedback signals that guide the construction of fake learning devices, ensuring their correct answer rates closely match those of the target learning device. This feedback mechanism corrects the deviation that occurs in traditional model extraction attacks.
3Loss of time
If a small amount of data is used for estimation, then the estimation process is faster, but generalization error increases
Solution Approach 1:
The patent reduces generalization error when using small amounts of data by changing the parameterization of the softmax function to include temperature. This parameter modification allows the function to output ambiguous values that capture uncertainty, enabling more reliable generalization from limited training data. The temperature parameter effectively regularizes the learning process, preventing overfitting even when data is scarce.
Data Source
AI summary
A learning device estimating apparatus aims at a learning device as an attack target, and comprises a recording part, an inquiring part, a capturing part and a learning part. A predetermined plurality of pieces of observation data are recorded. The inquiring part inquires of the attack target learning device for each of the pieces of observation data recorded in the recording part to acquire label data and records the acquired label data to the recording part in association with observation data. The capturing part inputs the observation data and the label data associated with the observation data that have been recorded to the recording part, to the learning part. The learning part is characterized by using an activation function that outputs a predetermined ambiguous value in a process for determining a classification prediction result, and the learning part performs learning using the inputted observation data and label data.


