Fetching the paper…
Reading the bibliography…
Model extraction (ME) attacks represent one major threat to Machine-Learning-as-a-Service (MLaaS) platforms by ``stealing'' the functionality of confidential machine-learning models through querying black-box APIs.
A stochastic approximation method
Herbert Robbins and Sutton Monro. 1951 · 1951
Earlier work this paper cites.
Information theory and statistical mechanics
Edwin T Jaynes. 1957 · 1957
Earlier work this paper cites.
One weird trick for parallelizing convolutional neural networks
Alex Krizhevsky. 2014 · 2014
Earlier work this paper cites.
Fitnets: Hints for thin deep nets
Adriana Romero, Nicolas Ballas, Samira Ebrahimi Kahou, Antoine Chassang, Carlo Gatta, and Yoshua Bengio. 2014 · 2014
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman. 2014 · 2014
Earlier work this paper cites.
Going Deeper with Convolutions
Christian Szegedy, Wei Liu, Yangqing Jia, Pierre Sermanet, Scott E. Reed, Dragomir Anguelov, Dumitru Erhan, Vincent Vanhoucke, and Andrew Rabinovich. 2014 · 2014
Earlier work this paper cites.
Deep Residual Learning for Image Recognition. In Proceedings of IEEE Conference on Computer Vision and Pattern Recognition (CVPR)
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2015 · 2015
Earlier work this paper cites.
Distilling the Knowledge in a Neural Network
Geoffrey Hinton, Oriol Vinyals, and Jeff Dean. 2015 · 2015
Earlier work this paper cites.
Deep learning
Yann LeCun, Yoshua Bengio, and Geoffrey Hinton. 2015 · 2015
Earlier work this paper cites.
Training Deep Networks for Facial Expression Recognition with Crowd-Sourced Label Distribution. In Proceedings of ACM International Conference on Multimodal Interaction (ICMI)
Emad Barsoum, Cha Zhang, Cristian Canton Ferrer, and Zhengyou Zhang. 2016 · 2016
Earlier work this paper cites.
Deep residual learning for image recognition. In Proceedings of IEEE Conference on Computer Vision and Pattern Recognition (CVPR)
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016 · 2016
Earlier work this paper cites.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
Nicolas Papernot, Patrick D McDaniel, and Ian J Goodfellow. 2016a · 2016
Earlier work this paper cites.
Stealing Machine Learning Models via Prediction APIs.. In Proceedings of USENIX Security Symposium (SEC)
Florian Tramèr, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart. 2016 · 2016
Earlier work this paper cites.
From Facial Expression Recognition to Interpersonal Relation Prediction
Zhanpeng Zhang, Ping Luo, Chen Change Loy, and Xiaoou Tang. 2016 · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks. In Proceedings of IEEE Symposium on Security and Privacy (S&P)
Nicholas Carlini and David Wagner. 2017 · 2017
Earlier work this paper cites.
Densely connected convolutional networks. In Proceedings of IEEE Conference on Computer Vision and Pattern Recognition (CVPR)
Gao Huang, Zhuang Liu, Laurens Van Der Maaten, and Kilian Q Weinberger. 2017 · 2017
Earlier work this paper cites.
Like what you like: Knowledge distill via neuron selectivity transfer
Zehao Huang and Naiyan Wang. 2017 · 2017
Earlier work this paper cites.
Adam: A Method for Stochastic Optimization
Diederik P. Kingma and Jimmy Ba. 2017 · 2017
Earlier work this paper cites.
Practical black-box attacks against machine learning. In Proceedings of ACM Symposium on Information, Computer and Communications Security (AsiaCCS)
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami. 2017 · 2017
Earlier work this paper cites.
Active learning for convolutional neural networks: A core-set approach
Ozan Sener and Silvio Savarese. 2017 · 2017
Earlier work this paper cites.
How to steal a machine learning classifier with deep learning. In Proceedings of the IEEE International Symposium on Technologies for Homeland Security (HST)
Yi Shi, Yalin Sagduyu, and Alexander Grushin. 2017 · 2017
Earlier work this paper cites.
A gift from knowledge distillation: Fast optimization, network minimization and transfer learning. In Proceedings of IEEE Conference on Computer Vision and Pattern Recognition (CVPR)
Junho Yim, Donggyu Joo, Jihoon Bae, and Junmo Kim. 2017 · 2017
Earlier work this paper cites.
Vggface2: A dataset for recognizing faces across pose and age. In Proceedings of the IEEE International Conference on Automatic Face & Gesture Recognition (FG)
Qiong Cao, Li Shen, Weidi Xie, Omkar M Parkhi, and Andrew Zisserman. 2018 · 2018
Earlier work this paper cites.
Copycat cnn: Stealing knowledge by persuading confession with random non-labeled data. In Proceedings of the International Joint Conference on Neural Networks (IJCNN)
Jacson Rodrigues Correia-Silva, Rodrigo F Berriel, Claudine Badue, Alberto F de Souza, and Thiago Oliveira-Santos. 2018 · 2018
Earlier work this paper cites.
Bert: Pre-training of deep bidirectional transformers for language understanding
Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2018 · 2018
Earlier work this paper cites.
Densely Connected Convolutional Networks
Gao Huang, Zhuang Liu, Laurens van der Maaten, and Kilian Q. Weinberger. 2018 · 2018
Earlier work this paper cites.
Self-supervised knowledge distillation using singular value decomposition. In Proceedings of European Conference on Computer Vision (ECCV)
Seung Hyun Lee, Dae Ha Kim, and Byung Cheol Song. 2018 · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks. In Proceedings of International Conference on Learning Representations (ICLR)
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018 · 2018
Cited alongside, same era.
Sok: Security and privacy in machine learning. In Proceedings of IEEE European Symposium on Security and Privacy (Euro S&P)
Nicolas Papernot, Patrick McDaniel, Arunesh Sinha, and Michael P Wellman. 2018 · 2018
Cited alongside, same era.
Query-efficient black-box attack by active learning. In Proceedings of IEEE International Conference on Data Mining (ICDM)
Li Pengcheng, Jinfeng Yi, and Lijun Zhang. 2018 · 2018
Cited alongside, same era.
Active deep learning attacks under strict rate limitations for online API calls. In 2018 IEEE International Symposium on Technologies for Homeland Security (HST)
Extracting Training Data from Large Language Models.. In Proceedings of USENIX Security Symposium (SEC)
Nicholas Carlini, Florian Tramer, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom B Brown, Dawn Song, Ulfar Erlingsson, et al · 2021
Later among the works it cites.
LiveROI: Region of Interest Analysis for Viewport Prediction in Live Mobile Virtual Reality Streaming. In Proceedings of the ACM Multimedia Systems Conference (MMSys)
Xianglong Feng, Weitian Li, and Sheng Wei. 2021 · 2021
Later among the works it cites.
InverseNet: Augmenting Model Extraction Attacks with Training Data Inversion.. In Proceedings of International Joint Conference on Artificial Intelligence (IJCAI)
Xueluan Gong, Yanjiao Chen, Wenbin Yang, Guanghao Mei, and Qian Wang. 2021 · 2021
Later among the works it cites.
Knowledge distillation: A survey
Jianping Gou, Baosheng Yu, Stephen J Maybank, and Dacheng Tao. 2021 · 2021
Later among the works it cites.
Stealing machine learning models: Attacks and countermeasures for generative adversarial networks. In Annual Computer Security Applications Conference . 1–16
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Yi Shi, Yalin E Sagduyu, Kemal Davaslioglu, and Jason H Li. 2018 · 2018
Cited alongside, same era.
MixMatch: A Holistic Approach to Semi-Supervised Learning
David Berthelot, Nicholas Carlini, Ian J. Goodfellow, Nicolas Papernot, Avital Oliver, and Colin Raffel. 2019 · 2019
Cited alongside, same era.
PRADA: protecting against DNN model stealing attacks. In Proceedings of IEEE European Symposium on Security and Privacy (Euro S&P)
Mika Juuti, Sebastian Szyller, Samuel Marchal, and N Asokan. 2019 · 2019
Cited alongside, same era.
Thieves on sesame street! model extraction of bert-based apis
Kalpesh Krishna, Gaurav Singh Tomar, Ankur P Parikh, Nicolas Papernot, and Mohit Iyyer. 2019 · 2019
Cited alongside, same era.
Defending against neural network model stealing attacks using deceptive perturbations. In 2019 IEEE Security and Privacy Workshops (SPW) . IEEE, 43–49
Taesung Lee, Benjamin Edwards, Ian Molloy, and Dong Su. 2019 · 2019
Cited alongside, same era.
DeT: Defending against adversarial examples via decreasing transferability. In Cyberspace Safety and Security: 11th International Symposium, CSS 2019, Guangzhou, China, December 1–3, 2019, Proceedings, Part I 11 . Springer International Publishing, 307–322
Changjiang Li, Haiqin Weng, Shouling Ji, Jianfeng Dong, and Qinming He. 2019 · 2019
Cited alongside, same era.
Reliable Crowdsourcing and Deep Locality-Preserving Learning for Unconstrained Facial Expression Recognition
Shan Li and Weihong Deng. 2019 · 2019
Cited alongside, same era.
Roberta: A robustly optimized bert pretraining approach
Yinhan Liu, Myle Ott, Naman Goyal, Jingfei Du, Mandar Joshi, Danqi Chen, Omer Levy, Mike Lewis, Luke Zettlemoyer, and Veselin Stoyanov. 2019 · 2019
Cited alongside, same era.
Hailong Hu and Jun Pang. 2021 · 2021
Later among the works it cites.
Towards certifying the asymmetric robustness for neural networks: quantification and applications
Changjiang Li, Shouling Ji, Haiqin Weng, Bo Li, Jie Shi, Raheem Beyah, Shanqing Guo, Zonghui Wang, and Ting Wang. 2021 · 2021
Later among the works it cites.
Omnilytics: A blockchain-based secure data market for decentralized machine learning
Jiacheng Liang, Songze Li, Bochuan Cao, Wensi Jiang, and Chaoyang He. 2021 · 2021
Later among the works it cites.
Data-Free Model Extraction. In Proceedings of IEEE Conference on Computer Vision and Pattern Recognition (CVPR)
Jean-Baptiste Truong, Pratyush Maini, Robert J. Walls, and Nicolas Papernot. 2021 · 2021
Later among the works it cites.
Learning dynamics of gradient descent optimization in deep neural networks
Wei Wu, Xiaoyuan Jing, Wencai Du, and Guoliang Chen. 2021 · 2021
Later among the works it cites.
Restore DeepFakes video frames via identifying individual motion styles
Haichao Zhang, Zhe-Ming Lu, Hao Luo, and Ya-Pei Feng. 2021 · 2021
Later among the works it cites.
HAPI: A Large-scale Longitudinal Dataset of Commercial ML API Predictions
Lingjiao Chen, Zhihua Jin, Sabri Eyuboglu, Christopher Ré, Matei Zaharia, and James Zou. 2022a · 2022
Later among the works it cites.
Seeing is living? rethinking the security of facial liveness verification in the deepfake era
Changjiang Li, Li Wang, Shouling Ji, Xuhong Zhang, Zhaohan Xi, Shanqing Guo, and Ting Wang. 2022 · 2022
Later among the works it cites.
Efficient dropout-resilient aggregation for privacy-preserving machine learning
Ziyao Liu, Jiale Guo, Kwok-Yan Lam, and Jun Zhao. 2022 · 2022
Later among the works it cites.
The Karolinska directed emotional faces—KDEF, CD ROM from Department of Clinical Neuroscience, Psychology section, Karolinska Institutet, 1998
Daniel Lundqvist, Anders Flykt, and A Öhman. 2022 · 2022
Later among the works it cites.
IMDb Datasets
[n. d.] · 2023
Closest in time.
Yelp Datasets
[n. d.] · 2023
Closest in time.
Symbolic Discovery of Optimization Algorithms
Xiangning Chen, Chen Liang, Da Huang, Esteban Real, Kaiyuan Wang, Yao Liu, Hieu Pham, Xuanyi Dong, Thang Luong, Cho-Jui Hsieh, Yifeng Lu, and Quoc V. Le. 2023a · 2023
Closest in time.
An Embarrassingly Simple Backdoor Attack on Self-supervised Learning. In The 2023 International Conference on Computer Vision (ICCV’ 23)
Changjiang Li, Ren Pang, Zhaohan Xi, Tianyu Du, Shouling Ji, Yuan Yao, and Ting Wang. 2023 · 2023
Closest in time.
Long-term privacy-preserving aggregation with user-dynamics for federated learning
Ziyao Liu, Hsiao-Ying Lin, and Yamin Liu. 2023a · 2023
Closest in time.
Attention-Enhancing Backdoor Attacks Against BERT-based Models
Weimin Lyu, Songzhu Zheng, Lu Pang, Haibin Ling, and Chao Chen. 2023 · 2023
Closest in time.
OCBEV: Object-Centric BEV Transformer for Multi-View 3D Object Detection
Zhangyang Qi, Jiaqi Wang, Xiaoyang Wu, and Hengshuang Zhao. 2023 · 2023
Closest in time.
Meilong Xu, Xiaoling Hu, Saumya Gupta, Shahira Abousamra, and Chao Chen. 2023 · 2023
Closest in time.
PASS: Patch Automatic Skip Scheme for Efficient Real-Time Video Perception on Edge Devices. In Proceedings of AAAI Conference on Artificial Intelligence (AAAI) , Vol. 37
Qihua Zhou, Song Guo, Jun Pan, Jiacheng Liang, Zhenda Xu, and Jingren Zhou. 2023 · 2023
Closest in time.
Feature Manipulation for DDPM based Change Detection
Zhenglin Li, Yangchen Huang, Mengran Zhu, Jingyu Zhang, JingHao Chang, and Houze Liu. 2024 · 2024
Closest in time.
Please Tell Me More: Privacy Impact of Explainability through the Lens of Membership Inference Attack. In 2024 IEEE Symposium on Security and Privacy (SP) . IEEE Computer Society, 120–120
Han Liu, Yuhao Wu, Zhiyuan Yu, and Ning Zhang. 2024 · 2024
Closest in time.
Task-Agnostic Detector for Insertion-Based Backdoor Attacks
Weimin Lyu, Xiao Lin, Songzhu Zheng, Lu Pang, Haibin Ling, Susmit Jha, and Chao Chen. 2024 · 2024
Closest in time.