Pith. sign in

REVIEW 3 cited by

Latent Code Augmentation Based on Stable Diffusion for Data-free Substitute Attacks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2307.12872 v2 pith:CQMTAURP submitted 2023-07-24 cs.CV cs.CRcs.LG

classification cs.CVcs.CRcs.LG
keywords datamodelsubstitutetargettrainingattackdiffusionlatent
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Since the training data of the target model is not available in the black-box substitute attack, most recent schemes utilize GANs to generate data for training the substitute model. However, these GANs-based schemes suffer from low training efficiency as the generator needs to be retrained for each target model during the substitute training process, as well as low generation quality. To overcome these limitations, we consider utilizing the diffusion model to generate data, and propose a novel data-free substitute attack scheme based on the Stable Diffusion (SD) to improve the efficiency and accuracy of substitute training. Despite the data generated by the SD exhibiting high quality, it presents a different distribution of domains and a large variation of positive and negative samples for the target model. For this problem, we propose Latent Code Augmentation (LCA) to facilitate SD in generating data that aligns with the data distribution of the target model. Specifically, we augment the latent codes of the inferred member data with LCA and use them as guidance for SD. With the guidance of LCA, the data generated by the SD not only meets the discriminative criteria of the target model but also exhibits high diversity. By utilizing this data, it is possible to train the substitute model that closely resembles the target model more efficiently. Extensive experiments demonstrate that our LCA achieves higher attack success rates and requires fewer query budgets compared to GANs-based schemes for different target models. Our codes are available at \url{https://github.com/LzhMeng/LCA}.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Stealix: Model Stealing via Prompt Evolution

    cs.CR 2025-06 conditional novelty 7.0 of 10

    An attacker with one seed image per class can steal a black-box image classifier by genetically evolving text prompts, guided only by the victim's hard-label predictions.

  2. LLM4MEA: Data-free Model Extraction Attacks on Sequential Recommenders via Large Language Models

    cs.IR 2025-07 conditional novelty 6.0 of 10

    An LLM-driven agent generates synthetic interaction sequences that, when queried against a target sequential recommender, produce surrogate models with higher agreement to the target than random or autoregressive data...

  3. Explore the vulnerability of black-box models via diffusion models

    cs.CV 2025-06 conditional novelty 4.0 of 10

    Synthetic images from diffusion model APIs can train substitute models that extract black-box classifiers and enable high-success adversarial transfer attacks with 0.01x the query budget of prior methods.

Pith tools