Pith. sign in

Paper Citation Record · LEDGER

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models

As of 7 August 2026, this Paper Citation Record lists 65 of 65 outbound references and 5 inbound Pith citation observations for arXiv:2506.02362.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2506.02362 v1

Coverage vector

measured 65 of 65 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T11:29:49.140988Z

measured 70 of 70 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00

measured 5 of 5 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-06T22:23:07.680268Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-05-13T01:47:04.386257Z

Reference resolution

65 of 65 outbound references displayed

  • verified exact1
  • verified fuzzy42
  • unresolved22
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 96c75794-e6be-4f5f-ab25-f440b4922437 · outbound

This paper cites Turning your weakness into a strength: Watermarking deep neural networks by backdooring.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Turning your weakness into a strength: Watermarking deep neural networks by backdooring

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:55.383335Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:42.954810Z digest=sha256:a0f7d5c361d6497f2bdd3f5e0c4ac175291f62f996dce2a6d7ba0a3179794da6

Observation be2e1a90-1d5f-4fd9-9a63-0f39a787d654 · outbound

This paper cites Backpropagation and stochastic gradient descent method.Neurocomputing, 5(4-5):185–196, 1993.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Backpropagation and stochastic gradient descent method.Neurocomputing, 5(4-5):185–196, 1993

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:55.367144Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:43.005028Z digest=sha256:e5bf224cb4319ff07b1a8b6994a8e13e1925c8e006021e399c80bf6f707ef0a3

Observation 4bf8f852-8f14-4a77-b99b-b19f53f8c588 · outbound

This paper cites Knowledge distillation: A good teacher is patient and consistent.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Knowledge distillation: A good teacher is patient and consistent

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:43.068897Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:43.068897Z digest=sha256:afce0360bfa17d2168e89faae480dfeddc878af38022e69a0a6e4da9a89538be

Observation 8a5c073c-aa9a-4c3e-9684-cd0e2b2b7c20 · outbound

This paper cites Data sharing and interoperability: Fostering in- novation and competition through apis.Computer Law & Security Review, 35(5):105314, 2019.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Data sharing and interoperability: Fostering in- novation and competition through apis.Computer Law & Security Review, 35(5):105314, 2019

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:55.341246Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:43.149923Z digest=sha256:321101f4a15b8579f8eb97f3c7fc85da5ead02f44173ebc383f82943dba6bf75

Observation a3d4e200-4019-494e-8d89-8ced57857a80 · outbound

This paper cites ATOM: A Framework of Detecting Query-Based Model Extraction Attacks for Graph Neural Networks.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models ATOM: A Framework of Detecting Query-Based Model Extraction Attacks for Graph Neural Networks

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:43.246771Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:43.246771Z digest=sha256:b09cc0081b71e65d6fd6f195d03e2e29ef1a786287851271d6b4ef188cdbe11c

Observation 0ea5740c-d6ed-43a8-9d60-590fb24db916 · outbound

This paper cites The mnist database of handwritten digit images for machine learning research [best of the web].IEEE signal processing magazine, 29(6):141–142, 2012.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models The mnist database of handwritten digit images for machine learning research [best of the web].IEEE signal processing magazine, 29(6):141–142, 2012

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:43.346168Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:43.346168Z digest=sha256:f4bee57806ed3b98829d3ead6b55516109c06a45c386d4f3464269472b13b5e8

Observation 8bde58b8-d2d0-4209-9809-52ee97f3304c · outbound

This paper cites Simon and Schuster, 2024.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Simon and Schuster, 2024

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:55.314420Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:43.393700Z digest=sha256:1a6cecd43785642538fa3cd0dcfbc51aa6798182dd9681ab51b6d7c25418ef95

Observation 41cd6786-0211-476e-93c5-9e4226f9f477 · outbound

This paper cites An optimized intelligent open-source mlaas framework for user-friendly clustering and anomaly detection.The Journal of Supercomputing, 80(18):26658–26684, 2024.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models An optimized intelligent open-source mlaas framework for user-friendly clustering and anomaly detection.The Journal of Supercomputing, 80(18):26658–26684, 2024

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:55.296348Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:43.442394Z digest=sha256:bca91dd439c853903af7fcf624fb5541cc44482b1fd75828e6eaf6015053b382

Observation fc6d3599-e8f9-4b43-985f-8551e58340d4 · outbound

This paper cites Efficient knowledge distillation from an ensemble of teachers.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Efficient knowledge distillation from an ensemble of teachers

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:55.280408Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:43.508645Z digest=sha256:6af434d8cd4a16e2c078483bd6b943d768d7c441002af35179f877739b59e9a1

Observation 08e040c4-6dc7-4d73-9c5b-57430b1014a3 · outbound

This paper cites Model extraction attacks and defenses on cloud-based machine learning models.IEEE Communications Magazine, 58(12):83–89, 2021.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Model extraction attacks and defenses on cloud-based machine learning models.IEEE Communications Magazine, 58(12):83–89, 2021

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:55.263164Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:43.600457Z digest=sha256:a2e19d7d048fa670fbd537e772a6911193e1f51f1a73a2c7bc2979a9ccbae853

Observation f16855de-899f-425e-8ec3-eda7369586a2 · outbound

This paper cites Machine learning as a service (mlaas)—an enterprise perspective.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Machine learning as a service (mlaas)—an enterprise perspective

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:55.246872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:43.671344Z digest=sha256:5e5a230f3f3f262250ed2172e304ed9217244fb652533176f447f7b9012189f1

Observation 6092f782-cd91-4955-acd6-94fdf7de893d · outbound

This paper cites A realistic model extraction attack against graph neural networks.Knowledge-Based Systems, 300:112144, 2024.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models A realistic model extraction attack against graph neural networks.Knowledge-Based Systems, 300:112144, 2024

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:55.230260Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:43.747845Z digest=sha256:9c7388d8236325b5183226cdff397d916b1e81d78ff4c40e160b8d2e6a3462dd

Observation 191e257e-35d0-42db-89c6-516d0d3adc49 · outbound

This paper cites The content moderator’s dilemma: Removal of toxic content and distortions to online discourse.arXiv preprint arXiv:2412.16114, 2024.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models The content moderator’s dilemma: Removal of toxic content and distortions to online discourse.arXiv preprint arXiv:2412.16114, 2024

Reference 13

Resolution
verified exact
raw_fallback, observed 2026-08-07T11:29:49.617476Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:43.823410Z digest=sha256:e122a60f757b49797163bbb7b02cbe9176c4b1589e045abfc8e4eab34e9889a9

Observation bea71f1e-f0d2-4ac2-ba6b-2269554dde38 · outbound

This paper cites Deep residual learning for image recognition.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Deep residual learning for image recognition

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:43.878264Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:43.878264Z digest=sha256:80c7031141194ef48db12dfbbd6f62830bf735cb1a3753fd9b9f16e6664b443e

Observation 360b649d-826d-47d2-93d2-9288587b41ed · outbound

This paper cites Protecting intellectual property of language generation apis with lexical watermark.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Protecting intellectual property of language generation apis with lexical watermark

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:55.202338Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:43.933632Z digest=sha256:6b13841c96bf0403d6a4c572424ba4e96664d06d45f53896e88eeff9359fba3e

Observation 237dbdeb-8571-40fd-bd3b-d76d7054ec25 · outbound

This paper cites Distilling the Knowledge in a Neural Network.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Distilling the Knowledge in a Neural Network

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:44.014750Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:44.014750Z digest=sha256:d0197ef41e50a0e305731cfe59fb56792a3caf8f3d10d2b43828d0dbc276f1fe

Observation 30a2ff01-83d9-4c90-a8f9-89c8f82635fd · outbound

This paper cites Learning to learn from apis: Black-box data-free meta-learning.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Learning to learn from apis: Black-box data-free meta-learning

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:55.184692Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:44.069042Z digest=sha256:c7b9729430eeaf6e90f3f5fe11a744d0fab458a0e6b9252c8c209963b28bf664

Observation a0eb8dd1-8ebe-4440-98b0-1f1accb9c403 · outbound

This paper cites Densely connected convolutional networks.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Densely connected convolutional networks

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:44.142842Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:44.142842Z digest=sha256:73df0f17be15f9e3081cc870fcf5dac8d5f6aaef700d7bfa67e6b5cb0a83b874

Observation 1ee8aefd-9dfe-4e30-ada2-4bdd7f01e201 · outbound

This paper cites High accuracy and high fidelity extraction of neural networks.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models High accuracy and high fidelity extraction of neural networks

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:55.154429Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:44.212973Z digest=sha256:233d3697489f8547fe3b7957a196e0392ba5852c9d297b7be5865c824dfa055e

Observation 808ccce3-1d0b-4dc7-b312-c9530357ddec · outbound

This paper cites A comprehensive defense framework against model extraction attacks.IEEE Transactions on Dependable and Secure Computing, 21(2):685–700, 2023.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models A comprehensive defense framework against model extraction attacks.IEEE Transactions on Dependable and Secure Computing, 21(2):685–700, 2023

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:55.138246Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:44.290721Z digest=sha256:3a8edef1663d72d253871f1f42de53e9a72e2d590cee223bb0c458aa61fe7d31

Observation 81706863-f513-4aba-a4f3-f4af169e4e8b · outbound

This paper cites Prada: protecting against dnn model stealing attacks.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Prada: protecting against dnn model stealing attacks

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:55.104879Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:44.362445Z digest=sha256:ec40c18829ba879f4a347203e22ea80063940d9ad85c0a43968579384cc5dc23

Observation 1beb6478-54f6-405c-9fa9-a0152c35184b · outbound

This paper cites Maze: Data-free model stealing attack using zeroth-order gradient estimation.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Maze: Data-free model stealing attack using zeroth-order gradient estimation

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:54.977984Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:44.428306Z digest=sha256:85c3d79f7dae7ed8074adbbcd972dff6cc948bb9ff42517d261ad0029f4af2c5

Observation 5f09adf9-dcb7-4d48-9041-4598d94e609c · outbound

This paper cites Protecting dnns from theft using an ensemble of diverse models.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Protecting dnns from theft using an ensemble of diverse models

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:54.798480Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:44.522479Z digest=sha256:cba907d5b2e2abc11729453e7185cdd7ac721baab5e26df8b031c2f0417ef644

Observation 3955441e-2fd8-43a1-90d3-71bf3e8bf34e · outbound

This paper cites Defending against model stealing attacks with adaptive misinformation.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Defending against model stealing attacks with adaptive misinformation

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:44.591416Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:44.591416Z digest=sha256:644950af9d6e4a1245017b4a119d2dadb79e09d546db4695d6c4cd1583acc95e

Observation 88cf8439-7dd9-4013-997b-8cee12db35d0 · outbound

This paper cites Model extraction warning in mlaas paradigm.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Model extraction warning in mlaas paradigm

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:54.641699Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:44.638468Z digest=sha256:215de4c44d2bcfa4e9a79bdad2fe08aed4b22f7638cc5e95ffd291fe7ca205b9

Observation 6618bcec-d434-4885-996c-5257588e200a · outbound

This paper cites NSML: Meet the MLaaS platform with a real-world case study.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models NSML: Meet the MLaaS platform with a real-world case study

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:44.746123Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:44.746123Z digest=sha256:367b8b88a17bc3eac1517f4a697aa5b9e97d693367860a073dd7aca13719ff56

Observation 73a7fe6d-21f5-4f2f-a3b8-5414edb419ed · outbound

This paper cites Learning multiple layers of features from tiny images.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Learning multiple layers of features from tiny images

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:44.852634Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:44.852634Z digest=sha256:fbac5ae3b4626ae6ec4c10c875789dba76dcc2954548aa70ee7f43be76bda861

Observation fe4c7ba1-a2ba-4621-beaf-3968cc1f29ae · outbound

This paper cites An ensemble approach for classification and prediction of diabetes mellitus using soft voting classifier.International Journal of Cognitive Computing in Engineering, 2:40–46, 2021.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models An ensemble approach for classification and prediction of diabetes mellitus using soft voting classifier.International Journal of Cognitive Computing in Engineering, 2:40–46, 2021

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:54.518261Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:44.946695Z digest=sha256:516c5d8e72fb60e3e2d94a3812c451ae721b3747d6059fc7ac9128d6ed3067f6

Observation f5cddcb3-116c-4e84-ba76-b0d8c9c1f670 · outbound

This paper cites Defending against model extraction attacks with physical unclonable function.Information Sciences, 628:196–207, 2023.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Defending against model extraction attacks with physical unclonable function.Information Sciences, 628:196–207, 2023

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:54.362252Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:45.005236Z digest=sha256:0e6cc5ce9c2c250e5bfe65f5f31cdb21b01379257a5a56c1bacef884264a5cd0

Observation d443e543-093d-48c1-ad5e-cad525dc2094 · outbound

This paper cites PhD thesis, Nanyang Technological University, 2025.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models PhD thesis, Nanyang Technological University, 2025

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:54.240412Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:45.136130Z digest=sha256:8fba6da389a0ca3c7d1aea100a531fbb5d9dfa4863cbc1bf595e6e73c893359a

Observation bd4ea582-1b84-450d-a09c-38891304ff16 · outbound

This paper cites Defending against model extraction attacks with ood feature learning and decision boundary confusion.Computers & Security, 136:103563, 2024.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Defending against model extraction attacks with ood feature learning and decision boundary confusion.Computers & Security, 136:103563, 2024

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:54.115666Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:45.251316Z digest=sha256:54e8597f653e1a392b0f220d63383ee47dbd843957b379859be298ef0c1eb79d

Observation 43951b68-0877-4be8-875a-76f137355351 · outbound

This paper cites Model extraction attacks revisited.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Model extraction attacks revisited

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:45.383709Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:45.383709Z digest=sha256:269897f3822593de0b77c317a5d90b0769929898b7e5691d7d7f4b3359be8b9c

Observation 8baa84a2-ce0d-4bb3-b2e8-0f4f0f62093d · outbound

This paper cites Quda: Query-limited data-free model extraction.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Quda: Query-limited data-free model extraction

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:54.057746Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:45.461472Z digest=sha256:92a19ff7fab2e132bfcef60182fca7b1a7f25b481de6089101699867f6909993

Observation 4f23fa17-4653-46b4-b192-46ce5dd9a5b8 · outbound

This paper cites Model extraction attack and defense on deep generative models.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Model extraction attack and defense on deep generative models

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:53.771059Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:45.555517Z digest=sha256:b04f98c9220138bc101a8722ce8b6f0ec1cfb4e11ea73adc37deb7abe77a54a0

Observation cb1dd927-8bca-4b6d-b6dc-237b57b43496 · outbound

This paper cites SGDR: Stochastic Gradient Descent with Warm Restarts.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models SGDR: Stochastic Gradient Descent with Warm Restarts

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:45.638448Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:45.638448Z digest=sha256:b80e1eb954244dd679ecf660604a1824a3f5dba61d685a57f8380f0e57f176b1

Observation f562e1f9-6a63-46ce-9c48-6ee40a31722e · outbound

This paper cites Dynamic neural fortresses: An adaptive shield for model extraction defense.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Dynamic neural fortresses: An adaptive shield for model extraction defense

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:53.456411Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:45.719862Z digest=sha256:dcc2d57cdb5407fdb1b061a88ccd809211dbbec230313c9db844c58125fc4624

Observation f0bec78b-5abf-4f04-b142-b25cbf44dff8 · outbound

This paper cites Dataset Inference: Ownership Resolution in Machine Learning.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Dataset Inference: Ownership Resolution in Machine Learning

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:45.809923Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:45.809923Z digest=sha256:dc8953e8c527c16d9f9e5562b50997750a3fc5345a32c3685fc17dfebbe434d2

Observation 9674f173-d260-4e28-aa78-1212ee20ce3b · outbound

This paper cites How to steer your adversary: Targeted and efficient model stealing defenses with gradient redirection.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models How to steer your adversary: Targeted and efficient model stealing defenses with gradient redirection

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:45.889360Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:45.889360Z digest=sha256:f3a9f998dcc72d644de2d4e5241b144e0f94c32935266b57b1fdcdc3308c0b66

Observation 38841a3d-9dc2-47e3-98bf-60f0746a90df · outbound

This paper cites Mixed Precision Training.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Mixed Precision Training

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:45.960731Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:45.960731Z digest=sha256:054bf656bf44b3f00cd7b5ebd195603841ba4ac38dade7e38f2abac7d27c402b

Observation 07a5608d-af51-4df9-a12d-4e48c60259e5 · outbound

This paper cites Megex: Data-free model extraction attack against gradient-based explainable ai.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Megex: Data-free model extraction attack against gradient-based explainable ai

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:53.111340Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:46.061903Z digest=sha256:4766d05ab02fcd3c87b029ac85ebafc4e8c36657f7d3c6af9814833f81dbd03a

Observation dc245ebc-7ae6-4888-8f4f-737b6e094c16 · outbound

This paper cites The MIT Press, 2nd edition, 2018.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models The MIT Press, 2nd edition, 2018

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:52.781143Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:46.157255Z digest=sha256:aae4a68505f9e90c426a7dc5382ea39fdd7579dfb24b52b56ae768b1a041a3d9

Observation a7bd935f-e061-422c-baf9-b48e639436c0 · outbound

This paper cites PhD thesis, Technische Universität Wien, 2023.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models PhD thesis, Technische Universität Wien, 2023

Reference 42

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:52.694587Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:46.294026Z digest=sha256:f7cfff8a414bc958911cefa0b7557e8bd37a446ed26012e4878187fd29e6fdf1

Observation 022aa366-53cd-474e-bf7d-bcf7dc2eccb7 · outbound

This paper cites Knockoff nets: Stealing functionality of black-box models.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Knockoff nets: Stealing functionality of black-box models

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:46.405187Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:46.405187Z digest=sha256:cb1d6e78b0da7c3c67bd95c41f34d439bbc5dd6545ebcc1c563264f5cc94c9a2

Observation 65aca9c0-a9e8-4ee8-93e7-fbd27e69b3f9 · outbound

This paper cites Prediction Poisoning: Towards Defenses Against DNN Model Stealing Attacks.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Prediction Poisoning: Towards Defenses Against DNN Model Stealing Attacks

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:46.552480Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:46.552480Z digest=sha256:598488087af6d3f448b8405af1c7e1787d5353ad6355805ea3a825fb8cf65e63

Observation 08f13667-6af2-48e7-91f2-ac6a2f8a4025 · outbound

This paper cites Mod- elshield: Adaptive and robust watermark against model extraction attack.IEEE Transactions on Information Forensics and Security, 2025.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Mod- elshield: Adaptive and robust watermark against model extraction attack.IEEE Transactions on Information Forensics and Security, 2025

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:52.574431Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:46.696929Z digest=sha256:23ccf87b8be18c0aadca328e06586520d116d77306964507d16871d76fd814c9

Observation ce321895-d395-4e4c-b557-f5a060d3255c · outbound

This paper cites Practical black-box attacks against machine learning.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Practical black-box attacks against machine learning

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:46.841381Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:46.841381Z digest=sha256:ce8b32abd4ba5d234af043ae68bef94b1ec857c9bf6806c2fff574787cad93bc

Observation 7f57c3fd-0138-41fa-abc5-525e67ddcc6a · outbound

This paper cites Relational knowledge distillation.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Relational knowledge distillation

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:46.989656Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:46.989656Z digest=sha256:db5344efac2adb65c90372eefac70c225c35042274ce61b20005c27e3c198f08

Observation 2b2e1da6-907e-46ba-896e-e8e6c79b96b5 · outbound

This paper cites Automatic differentiation in pytorch.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Automatic differentiation in pytorch

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:47.088565Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:47.088565Z digest=sha256:26574b1e533b556f4487943e0da13e96a35003b01b93ffc5b3ff48ca3bce8268

Observation 87d3db77-060a-4b57-9b4e-8a27b012886f · outbound

This paper cites Mlaas: Machine learning as a service.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Mlaas: Machine learning as a service

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:52.399547Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:47.213201Z digest=sha256:e68a7045c44c9dfb06c7ba11e1b95eff52011822f754ce604b6a0d9418a20c99

Observation 3d91047b-bac6-4082-b95e-6827687c079d · outbound

This paper cites Privacy as intellectual property.Stan.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Privacy as intellectual property.Stan

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:52.283298Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:47.318207Z digest=sha256:25626e9a55f00fc43bf6cd0ed5914d8687de50d76d50b2063115bb41480f4b91

Observation 779fd938-78b7-4503-9b3a-c3251d6657c5 · outbound

This paper cites Mobilenetv2: Inverted residuals and linear bottlenecks.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Mobilenetv2: Inverted residuals and linear bottlenecks

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:47.448509Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:47.448509Z digest=sha256:5453cebd5088396d7356e8f807144c91b946b3a413efad8ad7bcc1827f117d50

Observation a09ea711-c052-4ca0-8b65-5901ecb25f93 · outbound

This paper cites Towards data-free model stealing in a hard label setting.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Towards data-free model stealing in a hard label setting

Reference 52

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:52.180612Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:47.570190Z digest=sha256:62e52c3bc9e2c2e0c042bfc0e622dade2693c668949e08c485c772858f670660

Observation 97d8357e-3a61-4bce-9494-d1e8cfce3c1b · outbound

This paper cites On efficient training of large-scale deep learning models.ACM Computing Surveys, 57(3):1–36, 2024.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models On efficient training of large-scale deep learning models.ACM Computing Surveys, 57(3):1–36, 2024

Reference 53

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:52.049503Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:47.719993Z digest=sha256:cdcce8cbd466db08add9cf95698199c6e7a9be784707ef652a10ffc42fd061aa

Observation b18395a2-b178-42ae-8fd0-71d2ddbe7b94 · outbound

This paper cites Does knowledge distillation really work?Advances in neural information processing systems, 34:6906–6919, 2021.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Does knowledge distillation really work?Advances in neural information processing systems, 34:6906–6919, 2021

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:51.910024Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:47.833373Z digest=sha256:7774e7f97376a86225507f4d7248961314a59bf24fab12f55d0ebdcd913085de

Observation 06f032f6-7550-46ff-9bd2-eb488b2f58e1 · outbound

This paper cites Deep neural network watermarking against model extraction attack.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Deep neural network watermarking against model extraction attack

Reference 55

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:51.789268Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:47.959813Z digest=sha256:95fac451c6a036b62de4cb2ca1b9cd91ec04ac009c76295ff9c572f35e7eb02d

Observation 2f0e70fb-0d69-4c23-b134-697abad43b61 · outbound

This paper cites Stealing machine learning models via prediction {APIs}.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Stealing machine learning models via prediction {APIs}

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-07T11:29:48.095902Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:29:48.095902Z digest=sha256:a3d5e0bf8fc958c7c427b9033035c8cf912319e0f6056b309162087332d4841b

Observation 387f2316-fb70-4fc0-8316-a6da1a7e13cd · outbound

This paper cites Data-free model extraction.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Data-free model extraction

Reference 57

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:51.686598Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:48.219035Z digest=sha256:af7288c897a2cf7f065fd01f143ca3b2ed5837404d4181a9922afd3c44ff20d6

Observation a178aa32-a927-43d1-ab26-826f99153f87 · outbound

This paper cites Defending against data-free model extraction by distributionally robust defensive training.Advances in Neural Information Processing Systems, 36:624–637, 2023.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Defending against data-free model extraction by distributionally robust defensive training.Advances in Neural Information Processing Systems, 36:624–637, 2023

Reference 58

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:51.551622Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:48.352974Z digest=sha256:851d5c5bc4ca7bb4866bf70b5e6d0e29b874f0a7b9c3f58400988ff212dd7366

Observation 72d6f83c-071d-4f74-8ba8-dc106a336bab · outbound

This paper cites Defense against model extraction attack by bayesian active watermarking.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Defense against model extraction attack by bayesian active watermarking

Reference 59

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:51.438230Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:48.477286Z digest=sha256:a71bd4dca291be0e13f7e87053c4831e8d5fcb10c2e3ebcbaa702bd44fcad95a

Observation d288470e-414c-40f5-b4d6-14a0f1fe3c22 · outbound

This paper cites Zero-shot knowledge distillation from a decision-based black-box model.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Zero-shot knowledge distillation from a decision-based black-box model

Reference 60

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:51.249330Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:48.592992Z digest=sha256:4dd34c3be28355d9e4875ce1647a9ea823de7bf5944602dce13a1d4054af2163

Observation db6c8b70-d670-4426-876a-7ddccb2326e4 · outbound

This paper cites Towards explainable model extraction attacks.International Journal of Intelligent Systems, 37(11):9936–9956, 2022.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Towards explainable model extraction attacks.International Journal of Intelligent Systems, 37(11):9936–9956, 2022

Reference 61

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:50.989219Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:48.703182Z digest=sha256:8110645dff57e4ebe4ac4d491a68972cc9dc4bc59c6381589d1b06994aec0a38

Observation 89442633-a36a-4eca-9d97-d71fc9a0d943 · outbound

This paper cites an unresolved cited work.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Unresolved cited work

Reference 62

Resolution
unresolved
raw_fallback, observed 2026-08-07T11:29:50.736835Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:48.807008Z digest=sha256:6a7b70ab08395b40db53a94fedda63206d350063aff74dcf11f7e87f9dc4657a

Observation 19462489-82c2-446b-b2c6-93d1cfabf697 · outbound

This paper cites Mlmodelci: An automatic cloud platform for efficient mlaas.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Mlmodelci: An automatic cloud platform for efficient mlaas

Reference 63

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:50.456875Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:48.932249Z digest=sha256:7fc274ffc8a67a3a7783264fce812f0769680178141ee2ce913e66eedd83eb76

Observation 261f865e-79f2-4b58-b2d9-217bf6e21583 · outbound

This paper cites Minimizing maximum model discrepancy for transferable black-box targeted attacks.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Minimizing maximum model discrepancy for transferable black-box targeted attacks

Reference 64

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:50.234183Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:49.030538Z digest=sha256:8d57fc32636cd81f93415280d65c961628bb872f204a13aa9bb268d9a59020de

Observation 80f696c6-adf2-4d0a-be40-44fff395ddd4 · outbound

This paper cites A survey of model extraction attacks and defenses in distributed computing environments, 2025.

MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models A survey of model extraction attacks and defenses in distributed computing environments, 2025

Reference 65

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:29:49.864470Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:29:49.140988Z digest=sha256:52e61b1ca0e6640e7b4d911856df271aeb260b3ce94d41e090d2480daa3dca44

Pith citing papers

Observation 2915912e-4524-4069-9543-c9c1df610d22 · inbound

A Survey on Model Extraction Attacks and Defenses for Large Language Models cites this paper.

A Survey on Model Extraction Attacks and Defenses for Large Language Models MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-06T22:23:07.680268Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T22:23:07.680268Z digest=sha256:54521f24c02b16e5104e537b7c74cf2ba55eafa6f4d96b6cf1a782c3fd9bc303

Observation ca490b50-3be2-4d14-98ef-3e15920dd554 · inbound

A Systematic Survey of Model Extraction Attacks and Defenses: State-of-the-Art and Perspectives cites this paper.

A Systematic Survey of Model Extraction Attacks and Defenses: State-of-the-Art and Perspectives MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-05T18:12:37.034350Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T18:12:37.034350Z digest=sha256:6db53d5b75656bedcd5aee20b2b42fa5d79d39d24b5d2229c7bd7b7085b70b7f

Observation 5da6b5f7-7453-4261-b633-fd1d64dc03b0 · inbound

Intellectual Property in Graph-Based Machine Learning as a Service: Attacks and Defenses cites this paper.

Intellectual Property in Graph-Based Machine Learning as a Service: Attacks and Defenses MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models

Reference 182

Resolution
unresolved
no resolver link, observed 2026-08-05T15:39:56.130610Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T15:39:56.130610Z digest=sha256:519009aa6d87bf751ed86963385fecb395b2b403389739768201d4c8a6146f65

Observation beefe17b-0f1a-4e24-8930-e80ff25bc258 · inbound

LatentRouter: Can We Choose the Right Multimodal Model Before Seeing Its Answer? cites this paper.

LatentRouter: Can We Choose the Right Multimodal Model Before Seeing Its Answer? MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-05-13T01:47:04.388649Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-13T01:42:54.802658Z digest=sha256:a507104f897938d69534e0aff3c68f4ed6ca188e1eaab56d381f9cd74c638fa7

Observation 9dde8944-2c60-4c02-844d-c0fd23468225 · inbound

ADS-C: Antidistillation Sampling for Classification cites this paper.

ADS-C: Antidistillation Sampling for Classification MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-01T23:20:43.484131Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T23:20:43.484131Z digest=sha256:6001a5ecd8c5a739df14b9f629a2e2a8d5b9b65801c478c941d3d9da83c8cfba