Fetching the paper…
Reading the bibliography…
The functionality of a deep learning (DL) model can be stolen via model extraction where an attacker obtains a surrogate model by utilizing the responses from a prediction API of the original model.
Very deep convolutional networks for large-scale image recognition
K. Simonyan and A. Zisserman · 2014
Earlier work this paper cites.
Deep Learning
I. Goodfellow et al · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
K. He et al · 2016
Earlier work this paper cites.
Stealing machine learning models via prediction apis
F. Tramèr et al · 2016
Earlier work this paper cites.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
T. Gu et al · 2017
Earlier work this paper cites.
Adversarial frontier stitching for remote neural network watermarking
E. Merrer et al · 2017
Earlier work this paper cites.
Practical black-box attacks against machine learning
N. Papernot et al · 2017
Earlier work this paper cites.
Embedding watermarks into deep neural networks
Y. Uchida et al · 2017
Earlier work this paper cites.
Turning your weakness into a strength: Watermarking deep neural networks by backdooring
Y. Adi et al · 2018
Earlier work this paper cites.
Watermarking deep neural networks for embedded systems
J. Guo et al · 2018
Earlier work this paper cites.
Defending against machine learning model stealing attacks using deceptive perturbations
T. Lee et al · 2018
Cited alongside, same era.
Edge intelligence: On-demand deep learning model co-inference with device-edge synergy
E. Li et al · 2018
Cited alongside, same era.
Digital watermarking for deep neural networks
Y. Nagai, Y. Uchida, S. Sakazawa, and S. Satoh · 2018
Cited alongside, same era.
Protecting intellectual property of deep neural networks with watermarking
J. Zhang et al · 2018
Cited alongside, same era.
Extraction of complex dnn models: Real threat or boogeyman?
B. G. Atli et al · 2019
Cited alongside, same era.
Deep neural network fingerprinting by conferrable adversarial examples
Deepsigns: An end-to-end watermarking framework for ownership protection of deep neural networks
B. D. Rouhani et al · 2019
Later among the works it cites.
Dawn: Dynamic adversarial watermarking of neural networks
S. Szyller et al · 2019
Later among the works it cites.
Neural cleanse: Identifying and mitigating backdoor attacks in neural networks
B. Wang et al · 2019
Later among the works it cites.
Robust and undetectable white-box watermarks for deep neural networks
T. Wang et al · 2019
Later among the works it cites.
Machine learning at facebook: Understanding inference at the edge
C.-J. Wu et al · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
N. Lukas et al · 2019
Cited alongside, same era.
Knockoff nets: Stealing functionality of black-box models
T. Orekondy et al · 2019
Cited alongside, same era.
Prediction poisoning: Utility-constrained defenses against model stealing attacks
T. Orekondy et al · 2019
Cited alongside, same era.
A framework for the extraction of deep neural networks by leveraging public data
S. Pal et al · 2019
Cited alongside, same era.
https://www.cs.toronto.edu/ kriz/cifar.html
CIFAR-10 dataset
Cited in the paper.
https://github.com/zalandoresearch/fashion-mnist
Fashion MNIST
Cited in the paper.
https://trustedcomputinggroup.org/
TPM
Cited in the paper.
A. Chakraborty et al · 2020
Later among the works it cites.
Fastai: a layered api for deep learning
J. Howard and S. Gugger · 2020
Later among the works it cites.
Defending against model stealing attacks with adaptive misinformation
S. Kariyappa et al · 2020
Later among the works it cites.
Entangled watermarks as a defense against model extraction
H. Jia et al · 2021
Later among the works it cites.