DT-DFRS: Enhanced Data-Free Robustness Stealing via Dual Teacher Guidance in Black-Box Settings

preprint OA: closed
Full text JSON View at publisher

Abstract

Abstract Model Stealing Attacks (MSAs) are identified as a significant privacy threat to Machine Learning as a Service (MLaaS). MSAs aim to craft a substitute model that has the same performance by just querying MLaaS. Various techniques have been proposed to steal the accuracy as well as the robustness of target models so that these models achieve not only the same performance as the victim model but also their robustness against adversarial attacks. Since the training data, architecture, and parameters of these models are inaccessible due to privacy issues, most approaches rely on distillation methods. In this process, a clone model is trained to imitate the behavior of the target model, effectively stealing its efficiency.Robustness Distillation (RD) addresses both the efficiency and robustness challenges of existing models. However, most existing approaches focus solely on distilling model accuracy while neglecting robustness, despite its importance in safety-critical scenarios. Additionally, many approaches rely on access to real or proxy datasets, which is often infeasible due to privacy constraints. Other approaches assume the availability of Soft-Label (SL) predictions, which requires retrieving the outputs from the softmax layer lying before the final classification.In this paper, we propose a novel Dual Teacher Data-Free Hard-Label Robustness Stealing attack (DT-DFRS) that enables robustness distillation without requiring real or proxy data while preserving the model's efficiency in hard-label settings.Our experiments demonstrate how our DT-DFRS is effective over existing state-of-the-art data-free hard-label methods. Our proposed model improves the baseline by 3.41% and 3.13% for CIFAR-10 and CIFAR-100 datasets, respectively.
Full text 11,214 characters · extracted from preprint-html · click to expand
DT-DFRS: Enhanced Data-Free Robustness Stealing via Dual Teacher Guidance in Black-Box Settings | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article DT-DFRS: Enhanced Data-Free Robustness Stealing via Dual Teacher Guidance in Black-Box Settings Rania El-Sayed, Hoda Baraka, Mayada Hadhoud This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-7359779/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract Model Stealing Attacks (MSAs) are identified as a significant privacy threat to Machine Learning as a Service (MLaaS). MSAs aim to craft a substitute model that has the same performance by just querying MLaaS. Various techniques have been proposed to steal the accuracy as well as the robustness of target models so that these models achieve not only the same performance as the victim model but also their robustness against adversarial attacks. Since the training data, architecture, and parameters of these models are inaccessible due to privacy issues, most approaches rely on distillation methods. In this process, a clone model is trained to imitate the behavior of the target model, effectively stealing its efficiency.Robustness Distillation (RD) addresses both the efficiency and robustness challenges of existing models. However, most existing approaches focus solely on distilling model accuracy while neglecting robustness, despite its importance in safety-critical scenarios. Additionally, many approaches rely on access to real or proxy datasets, which is often infeasible due to privacy constraints. Other approaches assume the availability of Soft-Label (SL) predictions, which requires retrieving the outputs from the softmax layer lying before the final classification.In this paper, we propose a novel Dual Teacher Data-Free Hard-Label Robustness Stealing attack (DT-DFRS) that enables robustness distillation without requiring real or proxy data while preserving the model's efficiency in hard-label settings.Our experiments demonstrate how our DT-DFRS is effective over existing state-of-the-art data-free hard-label methods. Our proposed model improves the baseline by 3.41% and 3.13% for CIFAR-10 and CIFAR-100 datasets, respectively. Transfer Learning Robustness Distillation Adversarial Training Dual Teacher Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-7359779","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":505902775,"identity":"bc609c66-f9db-41e0-9c59-0cc1404d9b65","order_by":0,"name":"Rania El-Sayed","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA/UlEQVRIiWNgGAWjYJCCA0AsxwZifQBiNnYitRjzAwnGGSAtzETalDizgYGBmQfEJKTFvP3swQM/KuoYNxxgPvza5tc2eT5mBsYPH3Nwa5E5k5dwsOfMYWaDA2xp1rl9tw3bmBmYJWduw61FgiHH4ABv2wE2gwM8Zsa5PbcZgVrYmHnxaeF/Y3Dw7786HoMD/N+MLXtu2xPWIpFjcJi3gVlCsoGH+THDj9uJRGh5Y3BY5thhA35mNjPG3obbyW3MjM34/cKfY/zxTU1dfRt78+MPP/7ctp3f3nzww0c8WhAA6B4JxjYQi7GBGPUQTR8Y/hCteBSMglEwCkYQAABZpk9iuSIvRgAAAABJRU5ErkJggg==","orcid":"","institution":"Faculty of Engineering, Cairo University","correspondingAuthor":true,"prefix":"","firstName":"Rania","middleName":"","lastName":"El-Sayed","suffix":""},{"id":505902776,"identity":"9ab3ca7b-fbea-4b9e-a1d1-5de4db2b22ca","order_by":1,"name":"Hoda Baraka","email":"","orcid":"","institution":"Faculty of Engineering, Cairo University","correspondingAuthor":false,"prefix":"","firstName":"Hoda","middleName":"","lastName":"Baraka","suffix":""},{"id":505902777,"identity":"9c8a0150-7e43-4ae1-8124-62bfee3e42d9","order_by":2,"name":"Mayada Hadhoud","email":"","orcid":"","institution":"Faculty of Engineering, Cairo University","correspondingAuthor":false,"prefix":"","firstName":"Mayada","middleName":"","lastName":"Hadhoud","suffix":""}],"badges":[],"createdAt":"2025-08-13 01:38:17","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-7359779/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-7359779/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":91392643,"identity":"b4db8a4a-bd0b-46c8-9283-e725528e4a1c","added_by":"auto","created_at":"2025-09-16 04:38:48","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":666031,"visible":true,"origin":"","legend":"","description":"","filename":"Manuscript.pdf","url":"https://assets-eu.researchsquare.com/files/rs-7359779/v1_covered_dccdb32d-478b-4015-8dc7-90101fb4e547.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"DT-DFRS: Enhanced Data-Free Robustness Stealing via Dual Teacher Guidance in Black-Box Settings","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"Transfer Learning, Robustness Distillation, Adversarial Training, Dual Teacher","lastPublishedDoi":"10.21203/rs.3.rs-7359779/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-7359779/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eModel Stealing Attacks (MSAs) are identified as a significant privacy threat to Machine Learning as a Service (MLaaS). MSAs aim to craft a substitute model that has the same performance by just querying MLaaS. Various techniques have been proposed to steal the accuracy as well as the robustness of target models so that these models achieve not only the same performance as the victim model but also their robustness against adversarial attacks. Since the training data, architecture, and parameters of these models are inaccessible due to privacy issues, most approaches rely on distillation methods. In this process, a clone model is trained to imitate the behavior of the target model, effectively stealing its efficiency.Robustness Distillation (RD) addresses both the efficiency and robustness challenges of existing models. However, most existing approaches focus solely on distilling model accuracy while neglecting robustness, despite its importance in safety-critical scenarios. Additionally, many approaches rely on access to real or proxy datasets, which is often infeasible due to privacy constraints. Other approaches assume the availability of Soft-Label (SL) predictions, which requires retrieving the outputs from the softmax layer lying before the final classification.In this paper, we propose a novel Dual Teacher Data-Free Hard-Label Robustness Stealing attack (DT-DFRS) that enables robustness distillation without requiring real or proxy data while preserving the model's efficiency in hard-label settings.Our experiments demonstrate how our DT-DFRS is effective over existing state-of-the-art data-free hard-label methods. Our proposed model improves the baseline by 3.41% and 3.13% for CIFAR-10 and CIFAR-100 datasets, respectively.\u003c/p\u003e","manuscriptTitle":"DT-DFRS: Enhanced Data-Free Robustness Stealing via Dual Teacher Guidance in Black-Box Settings","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2025-08-27 14:33:29","doi":"10.21203/rs.3.rs-7359779/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"275e3cf8-f578-4bc9-ab20-9912277e2c19","owner":[],"postedDate":"August 27th, 2025","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2025-09-16T04:38:24+00:00","versionOfRecord":[],"versionCreatedAt":"2025-08-27 14:33:29","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-7359779","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-7359779","identity":"rs-7359779","version":["v1"]},"buildId":"8U1c8b4HqxoKbykW_rLl7","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2025) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00