Fetching the paper…
Reading the bibliography…
Model Extraction attacks exploit the target model's prediction API to create a surrogate model in order to steal or reconnoiter the functionality of the target model in the black-box setting.
Adversarial learning
D. Lowd and C. Meek · 2005
Earlier work this paper cites.
Caltech-256 object category dataset
G. Griffin, A. Holub, and P. Perona · 2007
Earlier work this paper cites.
Visualizing data using t-sne
Laurens van der Maaten and Geoffrey Hinton · 2008
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
J. Deng, W. Dong, R. Socher, L. J. Li, K. L., and F. F. Li · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky · 2009
Earlier work this paper cites.
The Caltech-UCSD Birds-200-2011 Dataset
C. Wah, S. Branson, P. Welinder, P. Perona, and S. Belongie · 2011
Earlier work this paper cites.
An analysis of single-layer networks in unsupervised feature learning
A. Coates, A. Y. Ng, and H. Lee · 2011
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. J. Goodfellow, and R. Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
Tiny imagenet visual recognition challenge
Y. Le and X. Yang · 2015
Earlier work this paper cites.
Stealing machine learning models via prediction apis
F. Tramèr, F. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
K. He, X. Zhang, S. Ren, and J. Sun · 2016
Earlier work this paper cites.
Practical black-box attacks against machine learning
N. Papernot, P. D. McDaniel, I. J. Goodfellow, S. Jha, Z. Berkay Celik, and A. Swami · 2017
Earlier work this paper cites.
Membership inference attacks against machine learning models
R. Shokri, M. Stronati, C. Song, and V. Shmatikov · 2017
Earlier work this paper cites.
A baseline for detecting misclassified and out-of-distribution examples in neural networks
D. Hendrycks and K. Gimpel · 2017
Earlier work this paper cites.
Densely connected convolutional networks
G. Huang, Z. Liu, L. Van Der Maaten, and K. Q. Weinberger · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
N. Carlini and D. Wagner · 2017
Earlier work this paper cites.
Model extraction warning in mlaas paradigm
M. Kesarwani, B. Mukhoty, V. Arya, and S. Mehta · 2018
Earlier work this paper cites.
Stealing hyperparameters in machine learning
B. Wang and N. Z. Gong · 2018
Earlier work this paper cites.
Copycat CNN: stealing knowledge by persuading confession with random non-labeled data
J. R. C. da Silva, R. F. Berriel, C. Badue, A. F. de Souza, and T. Oliveira-Santos · 2018
Cited alongside, same era.
Enhancing the reliability of out-of-distribution image detection in neural networks
S. Liang, Y. Li, and R. Srikant · 2018
Cited alongside, same era.
Mobilenetv2: Inverted residuals and linear bottlenecks
M. Sandler, A. Howard, M. Zhu, A. Zhmoginov, and L. Chen · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2018
Cited alongside, same era.
Security analysis of deep neural networks operating in the presence of cache side-channel attacks
S. Hong, M. Davinroy, Y. Kaya, S. N. Locke, I. R., K. Kulda, D. Dachman-Soled, and T. Dumitras · 2018
Cited alongside, same era.
Cloudleak: Large-scale deep learning models stealing through adversarial examples
H. Yu, K. Yang, T. Zhang, Y. Tsai, T. Ho, and Y. Jin · 2020
Later among the works it cites.
Black-box ripper: Copying black-box models using generative evolutionary algorithms
A. Barbalau, A. Cosma, R. T. Ionescu, and M. Popescu · 2020
Later among the works it cites.
Extraction of complex dnn models: Real threat or boogeyman?
B. G. Atli, S. Szyller, M. Juuti, S. Marchal, and N. Asokan · 2020
Later among the works it cites.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
F. Croce and M. Hein · 2020
Later among the works it cites.
Exploring connections between active learning and model extraction
V. Chandrasekaran, K. Chaudhuri, I. Giacomelli, S. Jha, and S. Yan · 2020
Later among the works it cites.
Thieves on sesame street! model extraction of bert-based apis
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Protecting intellectual property of deep neural networks with watermarking
J. Zhang, Z. Gu, J. Jang, H. Wu, M. P. Stoecklin, H. Huang, and I. Molloy · 2018
Cited alongside, same era.
Turning your weakness into a strength: Watermarking deep neural networks by backdooring
Y. Adi, C. Baum, M. Cisse, B. Pinkas, and J. Keshet · 2018
Cited alongside, same era.
PRADA: protecting against DNN model stealing attacks
M. Juuti, S. Szyller, S. Marchal, and N. Asokan · 2019
Cited alongside, same era.
Knockoff nets: Stealing functionality of black-box models
T. Orekondy, B. Schiele, and M. Fritz · 2019
Cited alongside, same era.
Defending against neural network model stealing attacks using deceptive perturbations
T. Lee, B. Edwards, I. M. Molloy, and D. Su · 2019
Cited alongside, same era.
An empirical study of example forgetting during deep neural network learning
Mariya Toneva, Alessandro Sordoni, Remi Tachet des Combes, Adam Trischler, Yoshua Bengio, and Geoffrey J. Gordon · 2019
Cited alongside, same era.
Prototypical examples in deep learning: Metrics, characteristics, and utility, 2019
Nicholas Carlini, Ulfar Erlingsson, and Nicolas Papernot · 2019
Cited alongside, same era.
K. Krishna, G. Singh Tomar, A. P. Parikh, N. Papernot, and M. Iyyer · 2020
Later among the works it cites.
Cache telepathy: Leveraging shared resource attacks to learn DNN architectures
M. Yan, C. W. Fletcher, and J. Torrellas · 2020
Later among the works it cites.
Stateful detection of model extraction attacks
S. Pal, Y. Gupta, A. Kanade, and S. K. Shevade · 2021
Closest in time.
Seat: Similarity encoder by adversarial training for detecting model extraction attack queries
Z. Zhang, Y. Chen, and D. Wagner · 2021
Closest in time.
Characterizing structural regularities of labeled data in overparameterized models
Ziheng Jiang, Chiyuan Zhang, Kunal Talwar, and Michael C. Mozer · 2021
Closest in time.
Data-free model extraction
J. B. Truong, P. Maini, R. J. Walls, and N. Papernot · 2021
Closest in time.
When deep classifiers agree: Analyzing correlations between learning order and image statistics
I. Pliushch, M. Mundt, N. Lupp, and V. Ramesh · 2021
Closest in time.
Deep learning through the lens of example difficulty
Robert J. N. Baldock, Hartmut Maennel, and Behnam Neyshabur · 2021
Closest in time.
Stealing links from graph neural networks
X. He, J. Jia, M. Backes, N. Z. Gong, and Y. Zhang · 2021
Closest in time.
Stealing deep reinforcement learning models for fun and profit
K. Chen, S. Guo, T. Zhang, X. Xie, and Y. Liu · 2021
Closest in time.
Hermes attack: Steal DNN models with lossless inference accuracy
Y. Zhu, Y. Cheng, H. Zhou, and Y. Lu · 2021
Closest in time.
Entangled watermarks as a defense against model extraction
H. Jia, C. A. Choquette-Choo, V. Chandrasekaran, and N. Papernot · 2021
Closest in time.
DAWN: dynamic adversarial watermarking of neural networks
S. Szyller, B. Atli, S. Marchal, and N. Asokan · 2021
Closest in time.