Black-box model functionality stealing for Vietnamese sentiment analysis

  • Pham Xuan Cong Institute of Information Technology and Electronics, Academy of Military Science and Technology
  • Do Viet Binh Institute of Information Technology and Electronics, Academy of Military Science and Technology
  • Hoang Trung Nguyen Le Quy Don Technical University
  • Tran Cao Truong Le Quy Don Technical University
Keywords: Knockoff model; Black-box model functionality extraction; Vietnamese text sentiment analysis.

Abstract

Black-box deep learning models often keep critical components such as model architecture, hyperparameters, and training data confidential, allowing users to observe only the inputs and outputs without understanding their internal workings. Consequently, there is growing interest in developing "knockoff" models that replicate the behavior of these black-box models without direct access to internal details. We have conducted extensive studies on function extraction attacks targeting English text sentiment analysis models. By employing random or adaptive sampling methods, we have successfully reconstructed knockoff models that achieve functionality equivalent to the original models with high similarity. In this study, we extend our investigation to sentiment analysis datasets in Vietnamese. Experimental results demonstrate that for black-box models in Vietnamese text sentiment analysis, our method remains effective, successfully constructing models with equivalent functionality.

điểm /   đánh giá
Published
2025-06-25
Section
Information Technology & Applied Mathematics