Fetching the paper…
Reading the bibliography…
Machine Learning-as-a-Service (MLaaS) has become a widespread paradigm, making even the most complex machine learning models available for clients via e.g.
A framework for the extraction of Deep Neural Networks by leveraging public data, 2019
Soham Pal, Yash Gupta, Aditya Shukla, Aditya Kanade, Shirish Shevade, and Vinod Ganapathy · 1905
Earlier work this paper cites.
Adversarial Exploitation of Policy Imitation, 2019
Vahid Behzadan and William Hsu · 1906
Earlier work this paper cites.
Timing Attacks on Implementations of Diffie-Hellman, RSA, DSS, and other Systems
Paul C. Kocher · 1996
Earlier work this paper cites.
Challenges and Countermeasures for Adversarial Attacks on Deep Reinforcement Learning, 2021
Inaam Ilahi, Muhammad Usama, Junaid Qadir, Muhammad Umar Janjua, Ala Al-Fuqaha, Dinh Thai Hoang, and Dusit Niyato · 2001
Earlier work this paper cites.
Stealing Black-Box Functionality Using The Deep Neural Tree Architecture, 2020
Daniel Teitelman, Itay Naeh, and Shie Mannor · 2002
Earlier work this paper cites.
Model Extraction Attacks against Recurrent Neural Networks, 2020
Tatsuya Takemura, Naoto Yanai, and Toru Fujiwara · 2002
Earlier work this paper cites.
Adversarial Learning
Daniel Lowd and Christopher Meek · 2005
Earlier work this paper cites.
Good word attacks on statistical spam filters
Daniel Lowd and Christopher Meek · 2005
Earlier work this paper cites.
A Protection against the Extraction of Neural Network Models, 2020
Hervé Chabanne, Vincent Despiegel, and Linda Guiga · 2005
Earlier work this paper cites.
Remote Physical Device Fingerprinting
T. Kohno, A. Broido, and K.C. Claffy · 2005
Earlier work this paper cites.
Model compression
Cristian Buciluǎ, Rich Caruana, and Alexandru Niculescu-Mizil · 2006
Earlier work this paper cites.
Can machine learning be secure?
Marco Barreno, Blaine Nelson, Russell Sears, Anthony D. Joseph, and J. D. Tygar · 2006
Earlier work this paper cites.
Differential Privacy
Cynthia Dwork · 2006
Earlier work this paper cites.
Exploiting Machine Learning to Subvert Your Spam Filter
Blaine Nelson, Marco Barreno, Fuching Jack Chi, Anthony D. Joseph, Benjamin I. P. Rubinstein, et al · 2008
Earlier work this paper cites.
Active Learning Literature Survey
Burr Settles · 2009
Earlier work this paper cites.
The Graph Neural Network Model
F. Scarselli, M. Gori, Ah Chung Tsoi, M. Hagenbuchner, and G. Monfardini · 2009
Earlier work this paper cites.
Model extraction from counterfactual explanations, 2020
Ulrich Aïvodji, Alexandre Bolot, and Sébastien Gambs · 2009
Earlier work this paper cites.
A Survey on Transfer Learning
Sinno Jialin Pan and Qiang Yang · 2010
Earlier work this paper cites.
Efficient Cache Attacks on AES, and Countermeasures
Eran Tromer, Dag Arne Osvik, and Adi Shamir · 2010
Earlier work this paper cites.
Generative Adversarial Nets
Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Convolutional Neural Networks for Sentence Classification
Yoon Kim · 2014
Earlier work this paper cites.
FLUSH+RELOAD: A High Resolution, Low Noise, L3 Cache Side-Channel Attack
Yuval Yarom and Katrina Falkner · 2014
Earlier work this paper cites.
Adding Robustness to Support Vector Machines Against Adversarial Reverse Engineering
Ibrahim M. Alabdulmohsin, Xin Gao, and Xiangliang Zhang · 2014
Earlier work this paper cites.
Explaining and Harnessing Adversarial Examples
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Stealing Machine Learning Models via Prediction APIs
Florian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter, and Thomas Ristenpart · 2016
Earlier work this paper cites.
Deep Learning
Ian Goodfellow, Yoshua Bengio, and Aaron Courville · 2016
Earlier work this paper cites.
Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow · 2016
Earlier work this paper cites.
Practical Black-Box Attacks against Machine Learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami · 2017
Earlier work this paper cites.
How to steal a machine learning classifier with deep learning
Yi Shi, Yalin Sagduyu, and Alexander Grushin · 2017
Earlier work this paper cites.
Membership Inference Attacks Against Machine Learning Models
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov · 2017
Earlier work this paper cites.
Evasion and causative attacks with adversarial deep learning
Yi Shi and Yalin E. Sagduyu · 2017
Earlier work this paper cites.
‘Security Theater’: On the Vulnerability of Classifiers to Exploratory Attacks
Tegjyot Singh Sethi, Mehmed Kantardzic, and Joung Woo Ryu · 2017
Earlier work this paper cites.
Grad-CAM: Visual Explanations from Deep Networks via Gradient-Based Localization
Ramprasaath R. Selvaraju, Michael Cogswell, Abhishek Das, Ramakrishna Vedantam, Devi Parikh, and Dhruv Batra · 2017
Earlier work this paper cites.
Imitation Learning: A Survey of Learning Methods
Ahmed Hussein, Mohamed Medhat Gaber, Eyad Elyan, and Chrisina Jayne · 2017
Earlier work this paper cites.
Copycat CNN: Stealing Knowledge by Persuading Confession with Random Non-Labeled Data
Jacson Rodrigues Correia-Silva, Rodrigo F. Berriel, Claudine Badue, Alberto F. de Souza, and Thiago Oliveira-Santos · 2018
Earlier work this paper cites.
SoK: Security and Privacy in Machine Learning
Nicolas Papernot, Patrick McDaniel, Arunesh Sinha, and Michael P. Wellman · 2018
Earlier work this paper cites.
Query-Efficient Black-Box Attack by Active Learning
Li Pengcheng, Jinfeng Yi, and Lijun Zhang · 2018
Earlier work this paper cites.
Active Deep Learning Attacks under Strict Rate Limitations for Online API Calls
Yi Shi, Yalin E. Sagduyu, Kemal Davaslioglu, and Jason H. Li · 2018
Earlier work this paper cites.
Model Compression and Acceleration for Deep Neural Networks: The Principles, Progress, and Challenges
Yu Cheng, Duo Wang, Pan Zhou, and Tao Zhang · 2018
Earlier work this paper cites.
Hui Xu, Yuxin Su, Zirui Zhao, Yangfan Zhou, Michael R. Lyu, and Irwin King · 2018
Earlier work this paper cites.
Stealing Hyperparameters in Machine Learning
Binghui Wang and Neil Zhenqiang Gong · 2018
Earlier work this paper cites.
Wild patterns: Ten years after the rise of adversarial machine learning
Battista Biggio and Fabio Roli · 2018
Earlier work this paper cites.
Generative Adversarial Networks for Black-Box API Attacks with Limited Training Data
Yi Shi, Yalin E. Sagduyu, Kemal Davaslioglu, and Jason H. Li · 2018
Earlier work this paper cites.
Towards Reverse-Engineering Black-Box Neural Networks
Seong Joon Oh, M. Augustin, M. Fritz, and B. Schiele · 2018
Earlier work this paper cites.
Reverse engineering convolutional neural networks through side-channel information leaks
Weizhe Hua, Zhiru Zhang, and G. Edward Suh · 2018
Earlier work this paper cites.
Data driven exploratory attacks on black box classifiers in adversarial domains
Tegjyot Singh Sethi and Mehmed Kantardzic · 2018
Earlier work this paper cites.
Malware Detection by Eating a Whole EXE
Edward Raff, Jon Barker, Jared Sylvester, Robert Brandon, Bryan Catanzaro, and Charles K. Nicholas · 2018
Earlier work this paper cites.
Model Extraction Warning in MLaaS Paradigm
Manish Kesarwani, Bhaskar Mukhoty, Vijay Arya, and Sameep Mehta · 2018
Earlier work this paper cites.
Fine-Pruning: Defending Against Backdooring Attacks on Deep Neural Networks
Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg · 2018
Earlier work this paper cites.
Knockoff Nets: Stealing Functionality of Black-Box Models
Tribhuvanesh Orekondy, Bernt Schiele, and Mario Fritz · 2019
Cited alongside, same era.
PRADA: Protecting Against DNN Model Stealing Attacks
Mika Juuti, Sebastian Szyller, Samuel Marchal, and N. Asokan · 2019
Cited alongside, same era.
Stealing Knowledge from Protected Deep Neural Networks Using Composite Unlabeled Data
Itay Mosafi, Eli Omid David, and Nathan S. Netanyahu · 2019
Cited alongside, same era.
Review of Artificial Intelligence Adversarial Attack and Defense Technologies
Shilin Qiu, Qihe Liu, Shijie Zhou, and Chunjiang Wu · 2019
Cited alongside, same era.
Survey of Attacks and Defenses on Edge-Deployed Neural Networks (HPEC)
Mihailo Isakov, Vijay Gadepally, Karen M. Gettings, and Michel A. Kinsy · 2019
Cited alongside, same era.
GDALR: An Efficient Model Duplication Attack on Black Box Machine Learning Models
Monitoring-based Differential Privacy Mechanism Against Query Flooding-based Model Extraction Attack
Haonan Yan, Xiaoguang Li, Hui Li, Jiamin Li, Wenhai Sun, and Fenghua Li · 2021
Later among the works it cites.
Towards Security Threats of Deep Learning Systems: A Survey
Yingzhe He, Guozhu Meng, Kai Chen, Xingbo Hu, and Jinwen He · 2021
Later among the works it cites.
MAZE: Data-Free Model Stealing Attack Using Zeroth-Order Gradient Estimation
Sanjay Kariyappa, Atul Prakash, and Moinuddin K Qureshi · 2021
Later among the works it cites.
Deep Neural Network Fingerprinting by Conferrable Adversarial Examples
Nils Lukas, Yuxuan Zhang, and Florian Kerschbaum · 2021
Later among the works it cites.
Stealing Deep Reinforcement Learning Models for Fun and Profit
Kangjie Chen, Shangwei Guo, Tianwei Zhang, Xiaofei Xie, and Yang Liu · 2021
Later among the works it cites.
MEGEX: Data-Free Model Extraction Attack against Gradient-Based Explainable AI, 2021
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Nikhil Joshi and Rewanth Tammana · 2019
Cited alongside, same era.
Efficiently Stealing Your Machine Learning Models
Robert Nikolai Reith, Thomas Schneider, and Oleksandr Tkachenko · 2019
Cited alongside, same era.
Model Reconstruction from Model Explanations
Smitha Milli, Ludwig Schmidt, Anca D. Dragan, and Moritz Hardt · 2019
Cited alongside, same era.
Model Weight Theft With Just Noise Inputs: The Curious Case of the Petulant Attacker
Nicholas Roberts, Vinay Uday Prabhu, and Matthew McAteer · 2019
Cited alongside, same era.
BDPL: A Boundary Differentially Private Layer Against Machine Learning Model Extraction Attacks
Huadi Zheng, Qingqing Ye, Haibo Hu, Chengfang Fang, and Jie Shi · 2019
Cited alongside, same era.
Interpretable Machine Learning: A Guide for Making Black Box Models Explainable
Christoph Molnar · 2019
Cited alongside, same era.
BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding, 2019
Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova · 2019
Cited alongside, same era.
Takayuki Miura, Satoshi Hasegawa, and Toshiki Shibahara · 2021
Later among the works it cites.
Data-Free Model Extraction
Jean-Baptiste Truong, Pratyush Maini, Robert J. Walls, and Nicolas Papernot · 2021
Later among the works it cites.
Hermes Attack: Steal DNN Models with Lossless Inference Accuracy
Yuankun Zhu, Yueqiang Cheng, Husheng Zhou, and Yantao Lu · 2021
Later among the works it cites.
Stealing Links from Graph Neural Networks
Xinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong, and Yang Zhang · 2021
Later among the works it cites.
Sebastian Szyller, Vasisht Duddu, Tommi Gröndahl, and N. Asokan · 2021
Later among the works it cites.
Model Extraction and Adversarial Transferability, Your BERT is Vulnerable!
Xuanli He, Lingjuan Lyu, Lichao Sun, and Qiongkai Xu · 2021
Later among the works it cites.
Stealing Machine Learning Models: Attacks and Countermeasures for Generative Adversarial Networks
Hailong Hu and Jun Pang · 2021
Later among the works it cites.
Thief, Beware of What Get You There: Towards Understanding Model Extraction Attack, 2021
Xinyi Zhang, Chengfang Fang, and Jie Shi · 2021
Later among the works it cites.
Leveraging Partial Model Extractions using Uncertainty Quantification
Arne Aarts, Wil Michiels, and Peter Roelse · 2021
Later among the works it cites.
InverseNet: Augmenting Model Extraction Attacks with Training Data Inversion
Xueluan Gong, Yanjiao Chen, Wenbin Yang, Guanghao Mei, and Qian Wang · 2021
Later among the works it cites.
Black-Box Attacks on Sequential Recommenders via Data-Free Model Extraction
Zhenrui Yue, Zhankui He, Huimin Zeng, and Julian McAuley · 2021
Later among the works it cites.
SNIFF: Reverse Engineering of Neural Networks With Fault Attacks
Jakub Breier, Dirmanto Jap, Xiaolu Hou, Shivam Bhasin, and Yang Liu · 2021
Later among the works it cites.
Model Extraction and Adversarial Attacks on Neural Networks Using Switching Power Information
Tommy Li and Cory Merkel · 2021
Later among the works it cites.
Dataset Inference: Ownership Resolution in Machine Learning
Pratyush Maini, Mohammad Yaghini, and Nicolas Papernot · 2021
Later among the works it cites.
Entangled Watermarks as a Defense against Model Extraction
Hengrui Jia, Christopher A. Choquette-Choo, Varun Chandrasekaran, and Nicolas Papernot · 2021
Later among the works it cites.
DAWN: Dynamic Adversarial Watermarking of Neural Networks
Sebastian Szyller, Buse Gul Atli, Samuel Marchal, and N. Asokan · 2021
Later among the works it cites.
SEAT: Similarity Encoder by Adversarial Training for Detecting Model Extraction Attack Queries
Zhanyuan Zhang, Yizheng Chen, and David Wagner · 2021
Later among the works it cites.
Stateful Detection of Model Extraction Attacks, 2021
Soham Pal, Yash Gupta, Aditya Kanade, and Shirish Shevade · 2021
Later among the works it cites.
Information Laundering for Model Privacy
Xinran Wang, Yu Xiang, Jun Gao, and Jie Ding · 2021
Later among the works it cites.
Protecting DNNs from Theft using an Ensemble of Diverse Models
Sanjay Kariyappa, Atul Prakash, and Moinuddin K. Qureshi · 2021
Later among the works it cites.
RobustBench: a standardized adversarial robustness benchmark
Francesco Croce, Maksym Andriushchenko, Vikash Sehwag, Edoardo Debenedetti, Nicolas Flammarion, Mung Chiang, Prateek Mittal, and Matthias Hein · 2021
Later among the works it cites.
ES Attack: Model Stealing Against Deep Neural Networks Without Data Hurdles
Xiaoyong Yuan, Leah Ding, Lan Zhang, Xiaolin Li, and Dapeng Oliver Wu · 2022
Closest in time.
Model Extraction Attacks on Graph Neural Networks: Taxonomy and Realisation
Bang Wu, Xiangwen Yang, Shirui Pan, and Xingliang Yuan · 2022
Closest in time.
Enhance Model Stealing Attack via Label Refining
Yixu Wang and Xianming Lin · 2022
Closest in time.
StolenEncoder: Stealing Pre-trained Encoders in Self-supervised Learning
Yupei Liu, Jinyuan Jia, Hongbin Liu, and Neil Zhenqiang Gong · 2022
Closest in time.
Can’t Steal? Cont-Steal! Contrastive Stealing Attacks Against Image Encoders, 2022
Zeyang Sha, Xinlei He, Ning Yu, Michael Backes, and Yang Zhang · 2022
Closest in time.
Black-Box Dissector: Towards Erasing-Based Hard-Label Model Stealing Attack
Yixu Wang, Jie Li, Hong Liu, Yan Wang, Yongjian Wu, Feiyue Huang, and Rongrong Ji · 2022
Closest in time.
Towards explainable model extraction attacks
Anli Yan, Ruitao Hou, Xiaozhang Liu, Hongyang Yan, Teng Huang, and Xianmin Wang · 2022
Closest in time.
Towards Data-Free Model Stealing in a Hard Label Setting
Sunandini Sanyal, Sravanti Addepalli, and R. Venkatesh Babu · 2022
Closest in time.
GAME: Generative-Based Adaptive Model Extraction Attack
Yi Xie, Mengdie Huang, Xiaoyu Zhang, Changyu Dong, Willy Susilo, and Xiaofeng Chen · 2022
Closest in time.
On the Difficulty of Defending Self-Supervised Learning against Model Extraction
Adam Dziedzic, Nikita Dhawan, Muhammad Ahmad Kaleem, Jonas Guan, and Nicolas Papernot · 2022
Closest in time.
Model Stealing Attacks Against Inductive Graph Neural Networks
Yun Shen, Xinlei He, Yufei Han, and Yang Zhang · 2022
Closest in time.
DualCF: Efficient Model Extraction Attack from Counterfactual Explanations
Yongjie Wang, Hangwei Qian, and Chunyan Miao · 2022
Closest in time.
DeepSteal: Advanced Model Extractions Leveraging Efficient Weight Stealing in Memories
Adnan Siraj Rakin, Md Hafizul Islam Chowdhuryy, Fan Yao, and Deliang Fan · 2022
Closest in time.
Demystifying Arch-hints for Model Extraction: An Attack in Unified Memory System, 2022
Zhendong Wang, Xiaoming Zeng, Xulong Tang, Danfeng Zhang, Xing Hu, and Yang Hu · 2022
Closest in time.
High-Fidelity Model Extraction Attacks via Remote Power Monitors
Anuj Dubey, Emre Karabulut, Amro Awad, and Aydin Aysu · 2022
Closest in time.
DynaMarks: Defending Against Deep Learning Model Extraction Using Dynamic Watermarking, 2022
Abhishek Chakraborty, Daniel Xing, Yuntao Liu, and Ankur Srivastava · 2022
Closest in time.
Defending against Model Stealing via Verifying Embedded External Features
Yiming Li, Linghui Zhu, Xiaojun Jia, Yong Jiang, Shu-Tao Xia, and Xiaochun Cao · 2022
Closest in time.
SeInspect: Defending Model Stealing via Heterogeneous Semantic Inspection
Xinjing Liu, Zhuo Ma, Yang Liu, Zhan Qin, Junwei Zhang, and Zhuzhu Wang · 2022
Closest in time.
HODA: Hardness-Oriented Detection of Model Extraction Attacks, 2022
Amir Mahdi Sadeghzadeh, Amir Mohammad Sobhanian, Faezeh Dehghan, and Rasool Jalili · 2022
Closest in time.
Increasing the Cost of Model Extraction with Calibrated Proof of Work
Adam Dziedzic, Muhammad Ahmad Kaleem, Yu Shen Lu, and Nicolas Papernot · 2022
Closest in time.
Model Stealing Defense against Exploiting Information Leak through the Interpretation of Deep Neural Nets
Jeonghyun Lee, Sungmin Han, and Sangkyun Lee · 2022
Closest in time.
How to Steer Your Adversary: Targeted and Efficient Model Stealing Defenses with Gradient Redirection
Mantas Mazeika, Bo Li, and David Forsyth · 2022
Closest in time.
Identifying Appropriate Intellectual Property Protection Mechanisms for Machine Learning Models: A Systematisation of Watermarking, Fingerprinting, Model Access, and Attacks
Isabell Lederer, Rudolf Mayer, and Andreas Rauber · 2023
Closest in time.