REVIEW 3 major objections 4 minor 4 cited by
A Systematic Survey of Model Extraction Attacks and Defenses: State-of-the-Art and Perspectives
T0 review · 3 major / 4 minor · reviewed 2026-08-05 · deepseek-v4-flash
Pith's one-line read The paper proposes a unified taxonomy that classifies model extraction attacks by mechanism, defenses by strategy, and both across cloud, edge, and federated environments, claiming to be the first framework to combine all three dimensions.
desk verdict A useful, current survey of model extraction, but the 'novel taxonomy' claims are overstated and the attack categories overlap; worth publishing after revision. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the three-axis taxonomy shown in Figure 3. Its attack axis is organized by the information channel through which model knowledge leaks, progressing from explicit query–response probing to implicit side-channel leakage. Its defense axis is organized by the timing and logic of protection: detecting attacks during querying, verifying ownership after the fact, preventing extraction up front, or combining multiple measures. Its environment axis separates cloud, edge, and federated deployment, because each context changes what attackers can access and what defenders can afford. The taxonomy does the argument's work by making every surveyed paper comparable along the same
What would settle it
A systematic literature search using the same keywords with explicit inclusion criteria could count published extraction attacks and defenses that do not fit any leaf of Figure 3; if a material number of well-established methods require a new branch on the taxonomy, the comprehensiveness claim fails. A simpler check: the paper claims to be the first to combine attack mechanisms, defense strategies, and computing environments, so locating any earlier survey that already integrates all three axes would also falsify the novelty claim.
Extended reading notes
Core claim
The paper's central claim is that model extraction is not an unstructured collection of tricks but a field with a discoverable structure. It proposes a novel taxonomy with three axes: attack mechanism, defense approach, and computing environment. On the attack side it distinguishes query-based attacks, data-driven attacks, side-channel attacks, gradient-based attacks, and attacks on specific data modalities (text, vision, graph). On the defense side it distinguishes attack detection, ownership verification, attack prevention, and integrated or compositional defenses. On the environment axis it separates cloud computing, edge computing, and federated learning. The paper further claims to be t
Load-bearing premise
The claim that the taxonomy is unified and comprehensive depends on the assumption that the papers the authors selected and placed in Figure 3 are representative of the whole model extraction literature, but the paper gives no explicit search protocol, inclusion criteria, or coverage dates to establish that representativeness.
Editorial extensions
If this is right
- A new attack or defense can be positioned within the taxonomy, making it straightforward to compare against prior work in the same leaf and to identify neighboring categories that lack protection.
- Practitioners can match defensive mechanisms to concrete threat categories: monitoring for query floods, watermarking and fingerprinting for ownership disputes, perturbation and access control for prevention, and integrated frameworks for high-stakes deployments.
- The paper's proposed metrics—extraction accuracy, fidelity, efficiency, transferability, and parameter similarity for attacks; defense success rate, utility–security trade-off, query detectability, and robustness to adaptive attacks for defenses—give a common evaluation vocabulary to a field that has lacked one.
- The explicit future directions, including certified defense guarantees, standardized benchmarks, and cross-environment integration, become concrete research programs rather than vague calls for more work.
- The taxonomy highlights the utility–security trade-off as a structural feature of defenses, meaning that any practical protection must be evaluated not just by attack failure but by how much legitimate accuracy and latency are sacrificed.
Reading between the lines
- Because the paper treats attack channels as separate but notes that edge attacks need to combine side-channel and query information, the taxonomy points toward hybrid cross-channel attacks as a likely blind spot in current defenses.
- The survey does not state a systematic search protocol, inclusion criteria, or coverage window, so its comprehensiveness should be read as a synthesis of the authors' selected literature rather than an exhaustive census; a formal meta-analysis with explicit criteria could test whether the taxonomy's leaves cover the whole field.
- The same three-axis structure could be extended to emerging model families—multimodal vision-language systems, diffusion models, and agentic LLMs—that the paper mentions only in passing; applying the taxonomy to those families would be a direct test of its generality.
- If the taxonomy were adopted as the organizing scheme for the authors' continuously updated online repository, category imbalance would become visible at a glance, showing which attack–defense combinations are still underexplored.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper is a survey of model extraction attacks (MEAs) and defenses, organized around a proposed taxonomy that classifies attacks by mechanism, defenses by strategy, and research by computing environment (cloud, edge, federated learning). It reviews attack families (query-based, data-driven, side-channel, gradient-based, and modality-specific), defense families (detection, ownership verification, prevention, and integrated defenses), evaluation metrics, real-world application scenarios (finance, healthcare, autonomous vehicles, cybersecurity), and future research directions. The paper claims to provide 'the first unified and comprehensive framework' for MEAs and maintains a continuously updated online repository of related literature. It does not present new empirical measurements; its contribution is a synthesis and systematization of existing work.
Significance. If the taxonomy were internally consistent and the coverage demonstrably systematic, this survey would be a valuable reference for researchers, practitioners, and policymakers. The paper has real strengths: it covers recent developments in LLM, GNN, and edge/federated extraction; it discusses both attacks and defenses across multiple computing paradigms; it includes a structured evaluation-metrics section; and the online repository is a useful community resource. The breadth of cited work is impressive. However, the paper's central value proposition—the unified taxonomy—is currently undermined by overlapping and inconsistently applied category definitions, and the 'comprehensive' claim is not supported by a transparent selection methodology. These issues are load-bearing for a survey whose main purpose is to organize the field.
major comments (3)
- [Section 3, Fig. 3; Sections 4.1.1, 4.2, 4.4.3] The five attack categories are not mutually exclusive, which undermines the central claim of a systematic taxonomy. Query-based attacks (Sec 4.1.1) are defined by 'systematically querying a target model,' while data-driven attacks (Sec 4.2) are defined as 'use of data to query and replicate target models.' Since every black-box attack must query, the first two categories do not partition the space. Concretely, Knockoff Nets [155] appears under substitute model training (Sec 4.1.2) and again under problem-domain data-driven attacks (Sec 4.2.1); MAZE [96] appears under data-free attacks (Sec 4.2.3) and again under gradient estimation (Sec 4.4.3); ActiveThief [158] appears in both Sec 4.1.2 and Sec 4.2.1. Additionally, 'attacks on other data modalities' (Sec 4.5) is not an attack mechanism but a data type. The taxonomy mixes orthogonal axes (information channel, data availability, data moda
- [Sections 1 and 3] The paper claims to offer 'the first unified and comprehensive framework' and to provide a 'comprehensive and up-to-date overview,' but no systematic literature search protocol is presented. There is no description of databases searched, keywords, inclusion/exclusion criteria, time window, or screening process. The reader cannot assess whether the papers selected for Figure 3 are representative or whether important works are omitted. This is a load-bearing issue for a survey whose central claim is comprehensiveness. Please add a methodology subsection and discuss limitations of coverage.
- [Sections 5.1.1 and 5.2.2] The same defense name 'ModelGuard' is characterized as an information-theoretic monitoring method in Sec 5.1.1 and as an output-perturbation method in Sec 5.2.2, citing [198] in the latter. This internal inconsistency suggests that the taxonomic criteria are applied differently across sections. Combined with the overlapping attack categories, this weakens the paper's stated goal of providing a consistent classification. Please unify definitions and citation contexts.
minor comments (4)
- [Section 4.1.3] The sentence 'ESAs extend beyond model parameters to extract training hyperparameters, an attack method that targets the fundamental training configuration of machine learning models.' appears twice in the same paragraph. Please remove the duplicate.
- [Section 5.3.2] The text contains a missing citation placeholder: '? ] proposed a method to prevent weight stealing by obfuscating the network structure.' This reference must be supplied before publication.
- [Section 7.2] Typo: 'Caculate the proportion' should be 'Calculate the proportion.'
- [Section 8] In the autonomous vehicles paragraph, the sentence ends abruptly with 'often involving edge computing [136].' The thought appears incomplete; please revise.
Circularity Check
No circular derivation; survey is a literature organization with no fitted predictions, and self-citations are not load-bearing.
full rationale
This is a survey paper, not a derivation paper. It proposes a taxonomy and reviews existing attacks and defenses, but it makes no quantitative predictions, fits no parameters, and derives no new results from equations. The central claim—offering a 'first unified and comprehensive framework'—is asserted through qualitative comparison (Table 1) and literature selection, not through a derivation that reduces to its own inputs. The taxonomy's category overlap (e.g., data-driven attacks are defined as using data 'to query' a target model, which also satisfies the definition of query-based attacks) is a real consistency limitation, but it is a classification-quality issue rather than a circularity in the sense of an output being equivalent to an input by construction. Self-citations to the corresponding author's prior work (MISLEADER, Atom, CEGA) appear as surveyed items in Sections 4.5.3, 5.5.3, and 6.1, but the survey's framework does not depend on the correctness or uniqueness of those works; they are examples within the literature review. No theorem, prediction, or claimed derivation rests on a self-citation chain. Therefore, no significant circularity is present.
Assumptions & free parameters
assumptions (3)
- domain assumption The papers selected for the survey are representative of the model extraction field
- domain assumption The taxonomy categories are mutually exclusive and jointly cover all relevant MEA work
- domain assumption Cited attacks and defenses are accurately described
Cite this review
Pith. "Pith review of A Systematic Survey of Model Extraction Attacks and Defenses: State-of-the-Art and Perspectives." pith.science (2026). https://pith.science/paper/NELMGGPY
@misc{pith2026250815031,
author = {Pith},
title = {Pith review of: A Systematic Survey of Model Extraction Attacks and Defenses: State-of-the-Art and Perspectives},
year = {2026},
howpublished = {\url{https://pith.science/paper/NELMGGPY}},
note = {Machine review of arXiv:2508.15031}
}
read the original abstract
Machine learning (ML) models have significantly grown in complexity and utility, driving advances across multiple domains. However, substantial computational resources and specialized expertise have historically restricted their wide adoption. Machine-Learning-as-a-Service (MLaaS) platforms have addressed these barriers by providing scalable, convenient, and affordable access to sophisticated ML models through user-friendly APIs. While this accessibility promotes widespread use of advanced ML capabilities, it also introduces vulnerabilities exploited through Model Extraction Attacks (MEAs). Recent studies have demonstrated that adversaries can systematically replicate a target model's functionality by interacting with publicly exposed interfaces, posing threats to intellectual property, privacy, and system security. In this paper, we offer a comprehensive survey of MEAs and corresponding defense strategies. We propose a novel taxonomy that classifies MEAs according to attack mechanisms, defense approaches, and computing environments. Our analysis covers various attack techniques, evaluates their effectiveness, and highlights challenges faced by existing defenses, particularly the critical trade-off between preserving model utility and ensuring security. We further assess MEAs within different computing paradigms and discuss their technical, ethical, legal, and societal implications, along with promising directions for future research. This systematic survey aims to serve as a valuable reference for researchers, practitioners, and policymakers engaged in AI security and privacy. Additionally, we maintain an online repository continuously updated with related literature at https://github.com/kzhao5/ModelExtractionPapers.
Figures
Forward citations
Cited by 4 Pith papers
-
GraphIP-Bench: How Hard Is It to Steal a Graph Neural Network, and Can We Stop It?
GraphIP-Bench shows stealing GNNs is easy at moderate query budgets, most defenses fail to block or reliably trace extraction, and watermarks lose verification power on surrogates while heterophilic graphs are harder ...
-
GraphIP-Bench: How Hard Is It to Steal a Graph Neural Network, and Can We Stop It?
GraphIP-Bench is a new unified benchmark showing GNN model extraction succeeds at moderate query budgets while most defenses fail to prevent it or retain verification signals on surrogates.
-
A global log for medical AI
MedLog defines a nine-field, syslog-style event log for clinical AI, intended to support real-world surveillance and auditing; the four-deployment validation claimed in the abstract is absent from the body.
-
Intellectual Property in Graph-Based Machine Learning as a Service: Attacks and Defenses
A systematic review that organizes graph-ML IP protection into model-level and data-level attacks and defenses, and ships a benchmark library, PyGIP.
Reference graph
Works this paper leans on
- [155]
-
[96]
Sanjay Kariyappa, Atul Prakash, and Moinuddin K Qureshi. 2021. MAZE: Data-Free Model Stealing Attack Using Zeroth-Order Gradient Estimation. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 1685–1694
2021
-
[158]
Soham Pal, Yash Gupta, Aditya Shukla, Aditya Kanade, Shirish Shevade, and Vinod Ganapathy. 2020. ActiveThief: Model Extraction Using Active Learning and Unannotated Public Data. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 34. 865–872. https://doi.org/10.1609/aaai.v34i01.5427
-
[198]
Minxue Tang, Anna Dai, Louis DiValentin, Aolin Ding, Amin Hass, Neil Zhenqiang Gong, and Yiran Chen. 2024. Modelguard: Information-theoretic defense against model extraction attacks. In 33rd USENIX Security Symposium (Security 2024)
2024
-
[1]
Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016. Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC conference on computer and communications security. 308–318
2016
-
[2]
Babak Abbasov. 2014. Cloud computing: State of the art reseach issues. In 2014 IEEE 8th International Conference on Application of Information and Communication Technologies (AICT) . 1–4
2014
-
[3]
Ahmed Abdelaziz, Mohamed Elhoseny, Ahmed S Salama, and AM Riad. 2018. A machine learning model for improving healthcare services on cloud computing environment. Measurement 119 (2018), 117–128
2018
-
[4]
Alsharif Abuadbba, Hyoungshick Kim, and Surya Nepal. 2021. DeepiSign: invisible fragile watermark to protect the integrity and authenticity of CNN. In Proceedings of the 36th Annual ACM Symposium on Applied Computing . 952–959
2021
Show all 280 references
-
[5]
Yossi Adi, Carsten Baum, Moustapha Cisse, Benny Pinkas, and Joseph Keshet. 2018. Turning your weakness into a strength: Watermarking deep neural networks by backdooring. In 27th USENIX security symposium (USENIX Security 18). 1615–1631
2018
-
[6]
Vasilakos
Ejaz Ahmed, Ibrar Yaqoob, Ibrahim Abaker Targio Hashem, Imran Khan, Abdelmuttlib Ibrahim Abdalla Ahmed, Muhammad Imran, and Athanasios V. Vasilakos. 2017. The Role of Big Data Analytics in Internet of Things.Computer Networks 129 (2017), 459–471
2017
-
[7]
Ulrich Aivodji, Alexandre Bolot, and S’ebastien Gambs. 2020. Model Extraction from Counterfactual Explanations. arXiv preprint arXiv:2009.01884 (2020). https://arxiv.org/abs/2009.01884
2020 arXiv
-
[8]
Mohammad Al-Rubaie and J Morris Chang. 2019. Privacy-preserving machine learning: Threats and solutions. IEEE Security & Privacy 17, 2 (2019), 49–58
2019
-
[9]
Maaruf Ali and Mahdi H Miraz. 2013. Cloud computing applications. In Proceedings of the International Conference on Cloud Computing and eGovernance , Vol. 1. 111:44 Zhao et al
2013
-
[10]
Yuvanesh Anand, Zach Nussbaum, Adam Treat, Aaron Miller, Richard Guo, Ben Schmidt, GPT4All Community, Brandon Duderstadt, and Andriy Mulyar. 2023. GPT4All: An Ecosystem of Open Source Compressed Language Models. arXiv preprint arXiv:2311.04931 (2023). https://arxiv.org/abs/2311.04931
2023 arXiv
-
[11]
Nick Antonopoulos and Lee Gillam. 2010. Cloud computing. Vol. 51. Springer
2010
-
[12]
Buse Gul Atli, Sebastian Szyller, Mika Juuti, Samuel Marchal, and N Asokan. 2020. Extraction of complex dnn models: Real threat or boogeyman?. In Engineering Dependable and Secure Machine Learning Systems: Third International Workshop, EDSMLS 2020, New York City, NY, USA, Febr...
2020
-
[13]
Siamak Azodolmolky, Philipp Wieder, and Ramin Yahyapour. 2013. Cloud computing networking: Challenges and opportunities for innovations. IEEE Communications Magazine 51, 7 (2013), 54–62
2013
-
[14]
Venkata Sai Pranav Bachina, Ankit Gangwal, Aaryan Ajay Sharma, and Charu Sharma. 2024. GENIE: Watermarking Graph Neural Networks for Link Prediction. arXiv preprint arXiv:2406.04805 (2024)
2024 arXiv
-
[15]
Yang Bai, Ge Pei, Jindong Gu, Yong Yang, and Xingjun Ma. 2024. Special characters attack: Toward scalable training data extraction from large language models. arXiv preprint arXiv:2405.05990 (2024)
2024 arXiv
-
[16]
Jayant Baliga, Robert WA Ayre, Kerry Hinton, and Rodney S Tucker. 2010. Green cloud computing: Balancing energy in processing, storage, and transport. Proc. IEEE 99, 1 (2010), 149–167
2010
-
[17]
Antonio Bărbălau, Adrian Cosma, Radu Tudor Ionescu, and Marius Popescu. 2020. Black-Box Ripper: Copying black-box models using generative evolutionary algorithms. In Advances in Neural Information Processing Systems , Vol. 33. 20525–20537
2020
-
[18]
Lejla Batina, Shivam Bhasin, Dirmanto Jap, and Stjepan Picek. 2019. CSI NN: Reverse Engineering of Neural Network Architectures Through Electromagnetic Side Channel. In 28th USENIX Security Symposium (USENIX Security 19) . USENIX Association, 515–532
2019
-
[19]
Lejla Batina, Shivam Bhasin, Dirmanto Jap, and Stjepan Picek. 2019. {CSI}{ NN}: Reverse engineering of neural network architectures through electromagnetic side channel. In 28th USENIX Security Symposium (USENIX Security 19). 515–532
2019
-
[20]
Franziska Boenisch, Adam Dziedzic, Roei Schuster, Ali Shahin Shamsabadi, Ilia Shumailov, and Nicolas Papernot
-
[21]
Keith Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone, H Brendan McMahan, Sarvar Patel, Daniel Ramage, Aaron Segal, and Karn Seth. 2017. Practical secure aggregation for privacy-preserving machine learning. In proceedings of the 2017 ACM SIGSAC Conference on Computer...
2017
-
[22]
Flavio Bonomi, Rodolfo Milito, Jiang Zhu, and Sateesh Addepalli. 2012. Fog Computing and Its Role in the Internet of Things. In Proceedings of the First Edition of the MCC Workshop on Mobile Cloud Computing . 13–16
2012
-
[23]
Jakub Breier, Dirmanto Jap, Xiaolu Hou, Shivam Bhasin, and Yang Liu. 2021. SNIFF: reverse engineering of neural networks with fault attacks. IEEE Transactions on Reliability 71, 4 (2021), 1527–1539
2021
-
[24]
Jakub Breier, Dirmanto Jap, Xiaolu Hou, Shivam Bhasin, and Yang Liu. 2022. SNIFF: Reverse Engineering of Neural Networks With Fault Attacks. IEEE Transactions on Reliability 71, 1 (2022), 82–93. https://doi.org/10.1109/TR.2021. 3105609
2022 doi
-
[25]
Christopher Briggs, Zhong Fan, and Peter Andras. 2020. Federated learning with hierarchical clustering of local updates to improve training on non-IID data. In 2020 international joint conference on neural networks (IJCNN) . IEEE, 1–9
2020
-
[26]
Keyan Cao, Yefan Liu, Gongjie Meng, and Qimeng Sun. 2020. An overview on edge computing research. IEEE access 8 (2020), 85714–85728
2020
-
[27]
Xiaoyu Cao, Jinyuan Jia, and Neil Zhenqiang Gong. 2021. IPGuard: Protecting intellectual property of deep neural networks via fingerprinting the classification boundary. In Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security. 14–25
2021
-
[28]
Nicholas Carlini, Matthew Jagielski, and Ilya Mironov. 2020. Cryptanalytic Extraction of Neural Network Models. In Annual International Cryptology Conference
2020
-
[29]
Feder Cooper, Katherine Lee, Matthew Jagielski, Milad Nasr, Arthur Conmy, Itay Yona, Eric Wallace, David Rolnick, and Florian Tram‘er
Nicholas Carlini, Daniel Paleka, Krishnamurthy Dvijotham, Thomas Steinke, Jonathan Hayase, A. Feder Cooper, Katherine Lee, Matthew Jagielski, Milad Nasr, Arthur Conmy, Itay Yona, Eric Wallace, David Rolnick, and Florian Tram‘er. 2024. Stealing Part of a Production Language Mod...
2024 arXiv
-
[30]
Nicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, Úlfar Erlingsson, Alina Oprea, and Colin Raffel. 2021. Extracting Training Data from Large Language Models. In 30th USENIX Security Symposi...
2021
-
[31]
Hervé Chabanne, Vincent Despiegel, and Linda Guiga. 2020. A protection against the extraction of neural network models. arXiv preprint arXiv:2005.12782 (2020). A Systematic Survey of Model Extraction Attacks and Defenses: State-of-the-Art and Perspectives 111:45
2020 arXiv
-
[32]
Abhishek Chakraborty, Daniel Xing, Yuntao Liu, and Ankur Srivastava. 2022. DynaMarks: Defending Against Deep Learning Model Extraction Using Dynamic Watermarking. arXiv preprint arXiv:2207.13321 (2022)
2022 arXiv
-
[33]
Jha, and Songbai Yan
Varun Chandrasekaran, Kamalika Chaudhuri, Irene Giacomelli, S. Jha, and Songbai Yan. 2018. Model Extraction and Active Learning. In ArXiv
2018
-
[34]
Varun Chandrasekaran, Kamalika Chaudhuri, Irene Giacomelli, Somesh Jha, and Songbai Yan. 2020. Exploring Connections Between Active Learning and Model Extraction. In29th USENIX Security Symposium (USENIX Security 20). USENIX Association, 1309–1326. https://www.usenix.org/confe...
2020
-
[35]
Huajie Chen, Tianqing Zhu, Lefeng Zhang, Bo Liu, Derui Wang, Wanlei Zhou, and Minhui Xue. 2024. QUEEN: Query Unlearning against Model Extraction. arXiv preprint arXiv:2407.01251 (2024)
2024 arXiv
-
[36]
Jinyin Chen, Minying Ma, Haonan Ma, Haibin Zheng, and Jian Zhang. 2024. An Empirical Evaluation of the Data Leakage in Federated Graph Learning. IEEE Transactions on Network Science and Engineering (2024)
2024
-
[37]
Jinyin Chen, Changan Wu, Shijing Shen, Xuhong Zhang, and Jianhao Chen. 2021. DAS-AST: Defending against model stealing attacks based on adaptive softmax transformation. In Information Security and Cryptology: 16th International Conference, Inscrypt 2020, Guangzhou, China, Dece...
2021
-
[38]
Kangjie Chen, Shangwei Guo, Tianwei Zhang, Xiaofei Xie, and Yang Liu. 2021. Stealing Deep Reinforcement Learning Models for Fun and Profit. In Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security . ACM, 375–389. https://doi.org/10.1145/3433210.3453090
2021
-
[39]
Wei-Ning Chen, Christopher A Choquette-Choo, and Peter Kairouz. 2021. Communication efficient federated learning with secure aggregation and differential privacy. In NeurIPS 2021 Workshop Privacy in Machine Learning
2021
-
[40]
Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)
2017 arXiv
-
[41]
Yanjiao Chen, Rui Guan, Xueluan Gong, Jianshuo Dong, and Meng Xue. 2023. D-DAE: Defense-Penetrating Model Extraction Attacks. In 2023 IEEE Symposium on Security and Privacy (SP) . https://ieeexplore.ieee.org/abstract/ document/10179406
2023
-
[42]
Xueqi Cheng, Minxing Zheng, Shixiang Zhu, and Yushun Dong. 2025. MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models. arXiv preprint arXiv:2506.02362 (2025)
2025 arXiv
-
[43]
Zhan Cheng, Bolin Shen, Tianming Sha, Yuan Gao, Shibo Li, and Yushun Dong. 2025. Atom: A framework of detecting query-based model extraction attacks for graph neural networks. In Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V. 2 . 322–333
2025
-
[44]
Mung Chiang and Tao Zhang. 2016. Fog and IoT: An Overview of Research Opportunities. IEEE Internet of Things Journal 3, 6 (2016), 854–864
2016
-
[45]
Jacson Rodrigues Correia-Silva, Rodrigo F Berriel, Claudine Badue, Alberto F de Souza, and Thiago Oliveira-Santos
-
[46]
Enyan Dai, Minhua Lin, and Suhang Wang. 2024. PreGIP: Watermarking the Pretraining of Graph Neural Networks for Deep Intellectual Property Protection. arXiv preprint arXiv:2402.04435 (2024)
2024 arXiv
-
[47]
Enyan Dai, Tianxiang Zhao, Huaisheng Zhu, Junjie Xu, Zhimeng Guo, Hui Liu, Jiliang Tang, and Suhang Wang. 2023. A Comprehensive Survey on Trustworthy Graph Neural Networks: Privacy, Robustness, Fairness, and Explainability. arXiv preprint arXiv:2204.08570 (2023). http://arxiv....
2023 arXiv
-
[48]
Dai, Hui Li, Tian Tian, Xin Huang, L
H. Dai, Hui Li, Tian Tian, Xin Huang, L. Wang, Jun Zhu, and Le Song. 2018. Adversarial Attack on Graph Structured Data. ArXiv (2018)
2018
-
[49]
Emiliano De Cristofaro. 2021. A critical overview of privacy in machine learning. IEEE Security & Privacy 19, 4 (2021), 19–27
2021
-
[50]
David DeFazio and Arti Ramesh. 2019. Adversarial Model Extraction on Graph Neural Networks. arXiv preprint arXiv:1912.07721 (2019). http://arxiv.org/abs/1912.07721
2019 arXiv
-
[51]
Jeroen Delvaux. 2017. Security analysis of PUF-based key generation and entity authentication. Ph. D. dissertation (2017)
2017
-
[52]
Jinhao Duan, Fei Kong, Shiqi Wang, Xiaoshuang Shi, and Kaidi Xu. 2023. Are Diffusion Models Vulnerable to Membership Inference Attacks?. In Proceedings of the 40th International Conference on Machine Learning . https: //proceedings.mlr.press/v202/duan23b.html
2023
-
[53]
Anuj Dubey, Emre Karabulut, Amro Awad, and Aydin Aysu. 2022. High-Fidelity Model Extraction Attacks via Remote Power Monitors. In 2022 IEEE 4th International Conference on Artificial Intelligence Circuits and Systems (AICAS) . IEEE, 207–210. https://doi.org/10.1109/AICAS54282....
2022
-
[54]
Jan Dubinski, Stanislaw Pawlak, Franziska Boenisch, Tomasz Trzcinski, and Adam Dziedzic. 2023. Bucks for buckets (b4b): Active defenses against stealing encoders. In NeurIPS
2023
-
[55]
Vijay Rao, and Valentina E
Vasisht Duddu, Debasis Samanta, D. Vijay Rao, and Valentina E. Balas. 2019. Stealing Neural Networks via Timing Side Channels. arXiv preprint arXiv:1812.11720 (2019). http://arxiv.org/abs/1812.11720 111:46 Zhao et al
2019 arXiv
-
[56]
Adam Dziedzic, Muhammad Ahmad Kaleem, Yu Shen Lu, and Nicolas Papernot. 2022. Increasing the cost of model extraction with calibrated proof of work. arXiv preprint arXiv:2201.09243 (2022)
2022 arXiv
-
[57]
Roberto R Expósito, Guillermo L Taboada, Sabela Ramos, Juan Tourino, and Ramón Doallo. 2013. General-purpose computation on GPUs for high performance cloud computing. Concurrency and Computation: Practice and Experience 25, 12 (2013), 1628–1642
2013
-
[58]
Polra Victor Falade. 2023. Decoding the Threat Landscape: ChatGPT, FraudGPT, and WormGPT in Social Engineering Attacks. International Journal of Scientific Research in Computer Science, Engineering and Information Technology (2023), 185–198. http://dx.doi.org/10.32628/CSEIT2390533
2023 doi
-
[59]
Karan Ganju, Qi Wang, Wei Yang, Carl A Gunter, and Nikita Borisov. 2018. Property inference attacks on fully connected neural networks using permutation invariant representations. In Proceedings of the 2018 ACM SIGSAC conference on computer and communications security . 619–633
2018
-
[60]
Lijun Gao, Wenjun Liu, Kai Liu, and Jiehong Wu. 2024. AugSteal: Advancing Model Steal With Data Augmentation in Active Learning Frameworks. IEEE Transactions on Information Forensics and Security 19 (2024), 3102–3116. https://doi.org/10.1109/TIFS.2024.3367452
2024
-
[61]
Pedro Garcia Lopez, Alberto Montresor, Dick Epema, Anwitaman Datta, Teruo Higashino, Adriana Iamnitchi, Marinho Barcellos, Pascal Felber, and Etienne Riviere. 2015. Edge-centric Computing: Vision and Challenges. ACM SIGCOMM Computer Communication Review 45, 5 (2015), 37–42
2015
-
[62]
Didem Genç, Mustafa Özuysal, and Emrah Tomur. 2023. A taxonomic survey of model extraction attacks. In 2023 IEEE International Conference on Cyber Security and Resilience (CSR) . IEEE, 200–205
2023
-
[63]
Robin C Geyer, Tassilo Klein, and Moin Nabi. 2017. Differentially private federated learning: A client level perspective. arXiv preprint arXiv:1712.07557 (2017)
2017 arXiv
-
[64]
Ran Gilad-Bachrach, Nathan Dowlin, Kim Laine, Kristin Lauter, Michael Naehrig, and John Wernsing. 2016. Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy. In International conference on machine learning. PMLR, 201–210
2016
-
[65]
Brunno F Goldstein, Vinay C Patil, Victor C Ferreira, Alexandre S Nery, Felipe MG França, and Sandip Kundu. 2021. Preventing DNN model IP theft via hardware obfuscation. IEEE Journal on Emerging and Selected Topics in Circuits and Systems 11, 2 (2021), 267–277
2021
-
[66]
Xueluan Gong, Qian Wang, Yanjiao Chen, Wang Yang, and Xinchang Jiang. 2020. Model extraction attacks and defenses on cloud-based machine learning models. IEEE Communications Magazine 58, 12 (2020), 83–89
2020
-
[67]
Justin Grana. 2020. Perturbing inputs to prevent model stealing. In 2020 IEEE Conference on Communications and Network Security (CNS). IEEE, 1–9
2020
-
[68]
Faqian Guan, Tianqing Zhu, Hui Sun, Wanlei Zhou, and Philip S. Yu. 2024. Large Language Models for Link Stealing Attacks Against Graph Neural Networks. arXiv preprint arXiv:2406.16963 (2024)
2024 arXiv
-
[69]
Faqian Guan, Tianqing Zhu, Hanjin Tong, and Wanlei Zhou. 2024. A realistic model extraction attack against graph neural networks. Knowledge-Based Systems (2024), 111657
2024
-
[70]
Faqian Guan, Tianqing Zhu, Wanlei Zhou, and Kim-Kwang Raymond Choo. 2024. Graph neural networks: a survey on the links between privacy and security. Artificial Intelligence Review 57 (2024), 40. https://doi.org/10.1007/s10462- 023-10656-4
2024 doi
-
[71]
Jiyang Guan, Jian Liang, and Ran He. 2022. Are you stealing my model? sample correlation for fingerprinting deep neural networks. Advances in Neural Information Processing Systems 35 (2022), 36571–36584
2022
-
[72]
Jun Guo, Xingyu Zheng, Aishan Liu, Siyuan Liang, Yisong Xiao, Yichao Wu, and Xianglong Liu. 2023. Isolation and Induction: Training Robust Deep Neural Networks against Model Stealing Attacks. In Proceedings of the 31st ACM International Conference on Multimedia . https://doi.o...
2023
-
[73]
Xingang Guo, Fangxu Yu, Huan Zhang, Lianhui Qin, and Bin Hu. 2024. COLD-Attack: Jailbreaking LLMs with Stealthiness and Controllability. arXiv preprint arXiv:2402.08679 (2024)
2024 arXiv
-
[74]
Mahendra Gurve, Sankar Behera, Satyadev Ahlawat, and Yamuna Prasad. 2024. MisGUIDE : Defense Against Data-Free Deep Learning Model Extraction. arXiv preprint arXiv:2403.18580 (2024)
2024 arXiv
-
[75]
Xinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong, and Yang Zhang. 2020. Stealing Links from Graph Neural Networks. ArXiv abs/2005.02131 (2020). https://api.semanticscholar.org/CorpusID:218502486
2020 arXiv
-
[76]
Xuanli He, Lingjuan Lyu, Qiongkai Xu, and Lichao Sun. 2021. Model Extraction and Adversarial Transferability, Your BERT is Vulnerable! arXiv preprint arXiv:2103.10013 (2021)
2021 arXiv
-
[77]
Xuanli He, Qiongkai Xu, Yi Zeng, Lingjuan Lyu, Fangzhao Wu, Jiwei Li, and Ruoxi Jia. 2022. Cater: Intellectual property protection on text generation apis via conditional watermarks. Advances in Neural Information Processing Systems 35 (2022), 5431–5445
2022
-
[78]
Yingzhe He, Guozhu Meng, Kai Chen, Xingbo Hu, and Jinwen He. 2022. Towards Security Threats of Deep Learning Systems: A Survey. IEEE Transactions on Software Engineering 48, 11 (2022), 4203–4220. https://doi.org/10.1109/TSE. 2020.3038641 A Systematic Survey of Model Extraction...
2022
-
[79]
Charles Herder, Meng-Day Yu, Farinaz Koushanfar, and Srinivas Devadas. 2014. Physical unclonable functions and applications: A tutorial. Proc. IEEE 102, 8 (2014), 1126–1141
2014
-
[80]
Sanghyun Hong, Michael Davinroy, Yiˇgitcan Kaya, Stuart Nevans Locke, Ian Rackow, Kevin Kulda, Dana Dachman- Soled, and Tudor Dumitraş. 2018. Security analysis of deep neural networks operating in the presence of cache side-channel attacks. arXiv preprint arXiv:1810.03487 (2018)
2018 arXiv
-
[81]
Jiahui Hou, Jianwei Qian, Yu Wang, Xiang-Yang Li, Haohua Du, and Linlin Chen. 2019. Ml defense: against prediction API threats in cloud-based machine learning service. In Proceedings of the International Symposium on Quality of Service. 1–10
2019
-
[82]
Hailong Hu and Jun Pang. 2021. Stealing Machine Learning Models: Attacks and Countermeasures for Generative Adversarial Networks. In Proceedings of the 37th Annual Computer Security Applications Conference . ACM, 690–704. https://doi.org/10.1145/3485832.3485838
2021
-
[83]
Xing Hu, Ling Liang, Lei Deng, Shuangchen Li, Xinfeng Xie, Yu Ji, Yufei Ding, Chang Liu, Timothy Sherwood, and Yuan Xie. 2019. Neural network model extraction attacks in edge devices by hearing architectural hints. arXiv preprint arXiv:1903.03916 (2019)
2019 arXiv
-
[84]
Xing Hu, Ling Liang, Shuangchen Li, Lei Deng, Pengfei Zuo, Yu Ji, Xinfeng Xie, Yufei Ding, Chang Liu, Timothy Sherwood, et al. 2020. Deepsniffer: A dnn model extraction framework based on learning architectural hints. In Proceedings of the Twenty-Fifth International Conference...
2020
-
[85]
Weizhe Hua, Zhiru Zhang, and G Edward Suh. 2018. Reverse engineering convolutional neural networks through side-channel information leaks. In Proceedings of the 55th Annual Design Automation Conference . 1–6
2018
-
[86]
Jie Huang, Hanyin Shao, and Kevin Chen-Chuan Chang. 2022. Are Large Pre-Trained Language Models Leaking Your Personal Information? (2022). http://arxiv.org/abs/2205.12628
2022 arXiv
-
[87]
Tyler Hunt, Zhipeng Jia, Vance Miller, Ariel Szekely, Yige Hu, Christopher J Rossbach, and Emmett Witchel. 2020. Telekine: Secure computing with cloud {GPUs}. In 17th USENIX Symposium on Networked Systems Design and Implementation (NSDI 20). 817–833
2020
-
[88]
Matthew Jagielski, Nicholas Carlini, David Berthelot, Alexey Kurakin, and Nicolas Papernot. 2019. High Accuracy and High Fidelity Extraction of Neural Networks. In USENIX Security Symposium
2019
-
[89]
Matthew Jagielski, Nicholas Carlini, David Berthelot, Alex Kurakin, and Nicolas Papernot. 2020. High accuracy and high fidelity extraction of neural networks. In 29th USENIX Security Symposium (USENIX Security 20) (2020), 1345–1362
2020
-
[90]
Mohd Javaid, Abid Haleem, Ravi Pratap Singh, Rajiv Suman, and Shanay Rab. 2022. Significance of machine learning in healthcare: Features, pillars and applications. International Journal of Intelligent Networks 3 (2022), 58–73
2022
-
[91]
Choquette-Choo, Varun Chandrasekaran, and Nicolas Papernot
Hengrui Jia, Christopher A. Choquette-Choo, Varun Chandrasekaran, and Nicolas Papernot. 2021. Entangled Watermarks as a Defense against Model Extraction. In 30th USENIX Security Symposium (USENIX Security 21) . USENIX Association, 1937–1954
2021
-
[92]
Wenbo Jiang, Hongwei Li, Guowen Xu, Tianwei Zhang, and Rongxing Lu. 2023. A comprehensive defense framework against model extraction attacks. IEEE Transactions on Dependable and Secure Computing 21, 2 (2023), 685–700
2023
-
[93]
G Joy Persial, M Prabhu, and R Shanmugalakshmi. 2011. Side channel attack-survey. Int. J. Adv. Sci. Res. Rev 1, 4 (2011), 54–57
2011
-
[94]
Yu, and Ming Zhang
Wei Ju, Siyu Yi, Yifan Wang, Zhiping Xiao, Zhengyang Mao, Hourun Li, Yiyang Gu, Yifang Qin, Nan Yin, Senzhang Wang, Xinwang Liu, Xiao Luo, Philip S. Yu, and Ming Zhang. 2024. A Survey of Graph Neural Networks in Real world: Imbalance, Noise, Privacy and OOD Challenges. arXiv p...
2024
-
[95]
Mika Juuti, Sebastian Szyller, Samuel Marchal, and N. Asokan. 2019. PRADA: Protecting Against DNN Model Stealing Attacks. In 2019 IEEE European Symposium on Security and Privacy (EuroS&P) . IEEE, 512–527
2019
-
[97]
Sanjay Kariyappa, Atul Prakash, and Moinuddin K Qureshi. 2021. Protecting dnns from theft using an ensemble of diverse models. In International Conference on Learning Representations
2021
-
[98]
Sanjay Kariyappa and Moinuddin K Qureshi. 2020. Defending against model stealing attacks with adaptive misinfor- mation. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition . 770–778
2020
-
[99]
Pratik Karmakar and Debabrota Basu. 2023. Marich: A Query-efficient Distributionally Equivalent Model Extraction Attack. In Advances in Neural Information Processing Systems
2023
-
[100]
Manish Kesarwani, Bhaskar Mukhoty, Vijay Arya, and Sameep Mehta. 2018. Model extraction warning in mlaas paradigm. In Proceedings of the 34th Annual Computer Security Applications Conference . 371–380
2018
-
[101]
Kacem Khaled, Gabriela Nicolescu, and Felipe Gohring De Magalhães. 2022. Careful What You Wish For: on the Extraction of Adversarially Trained Models. In 2022 19th Annual International Conference on Privacy, Security & Trust 111:48 Zhao et al. (PST). IEEE, 1–10. https://doi.or...
2022
-
[102]
Wazir Zada Khan, Ejaz Ahmed, Saqib Hakak, Ibrar Yaqoob, and Arif Ahmed. 2019. Edge Computing: A Survey.Future Generation Computer Systems 97 (2019), 219–235
2019
-
[103]
Ali Khosravi Kazazi, Fariba Amiri, Yaser Rahmani, Raheleh Samouei, and Hamidreza Rabiei-Dastjerdi. 2022. A new hybrid model for mapping spatial accessibility to healthcare services using machine learning methods. Sustainability 14, 21 (2022), 14106
2022
-
[104]
Kalpesh Krishna, Gaurav Singh Tomar, Ankur P Parikh, Nicolas Papernot, and Mohit Iyyer. 2019. Thieves on sesame street! model extraction of bert-based apis. arXiv preprint arXiv:1910.12366 (2019)
2019 arXiv
-
[105]
Kalpesh Krishna, Gaurav Singh Tomar, Ankur P Parikh, Nicolas Papernot, and Mohit Iyyer. 2020. Thieves on Sesame Street! Model Extraction of BERT-based APIs. In International Conference on Learning Representations . https://openreview.net/forum?id=Byl5NREFDr
2020
-
[106]
Pavana Pradeep Kumar, Amitangshu Pal, and Krishna Kant. 2021. Resource efficient edge computing infrastructure for video surveillance. IEEE Transactions on Sustainable Computing 7, 4 (2021), 774–785
2021
-
[107]
Jeonghyun Lee, Sungmin Han, and Sangkyun Lee. 2022. Model Stealing Defense against Exploiting Information Leak through the Interpretation of Deep Neural Nets. In Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence. 719–725
2022
-
[108]
Taesung Lee, Benjamin Edwards, Ian Molloy, and Dong Su. 2019. Defending Against Neural Network Model Stealing Attacks Using Deceptive Perturbations. In 2019 IEEE Security and Privacy Workshops (SPW) . IEEE, 43–49. https://ieeexplore.ieee.org/document/8844598
2019
-
[109]
Taegyeong Lee, Zhiqi Lin, Saumay Pushp, Caihua Li, Yunxin Liu, Youngki Lee, Fengyuan Xu, Chenren Xu, Lintao Zhang, and Junehwa Song. 2019. Occlumency: Privacy-preserving remote deep-learning inference using SGX. In The 25th Annual International Conference on Mobile Computing a...
2019
-
[110]
Younghan Lee, Sohee Jun, Yungi Cho, Woorim Han, Hyungon Moon, and Yunheung Paek. 2022. Precise Extraction of Deep Learning Models via Side-Channel Attacks on Edge/Endpoint Devices. In Computer Security – ESORICS 2022
2022
-
[111]
Chenyang Li, Zhao Song, Weixin Wang, and Chiwun Yang. 2023. A Theoretical Insight into Attack and Defense of Gradient Leakage in Transformer. arXiv preprint arXiv:2311.13624 (2023). http://arxiv.org/abs/2311.13624
2023 arXiv
-
[112]
Huiyu Li, Nicholas Ayache, and Hervé Delingette. 2022. Data Stealing Attack on Medical Images: Is It Safe to Export Networks from Data Lakes?. In Distributed, Collaborative, and Federated Learning, and Affordable AI and Healthcare for Resource Diverse Global Health . Springer
2022
-
[113]
Jingtao Li, Zhezhi He, Adnan Siraj Rakin, Deliang Fan, and Chaitali Chakrabarti. 2021. NeurObfuscator: A Full-stack Obfuscation Tool to Mitigate Neural Architecture Stealing. In 2021 IEEE International Symposium on Hardware Oriented Security and Trust (HOST) . IEEE, 199–209. h...
2021
-
[114]
Jingtao Li, Adnan Siraj Rakin, Xing Chen, Li Yang, Zhezhi He, Deliang Fan, and Chaitali Chakrabarti. 2023. Model Extraction Attacks on Split Federated Learning.arXiv preprint arXiv:2303.08581 (2023). http://arxiv.org/abs/2303.08581
2023 arXiv
-
[115]
Pengcheng Li, Jinfeng Yi, and Lijun Zhang. 2018. Query-Efficient Black-Box Attack by Active Learning. In 2018 IEEE International Conference on Data Mining (ICDM) . IEEE, 1200–1205. https://doi.org/10.1109/ICDM.2018.00159
2018
-
[116]
Qinfeng Li, Zhiqiang Shen, Zhenghan Qin, Yangfan Xie, Xuhong Zhang, Tianyu Du, Sheng Cheng, Xun Wang, and Jianwei Yin. 2024. TransLinkGuard: Safeguarding Transformer Models Against Model Stealing in Edge Deployment. In Proceedings of the 32nd ACM International Conference on Mu...
2024
-
[117]
Qinbin Li, Zeyi Wen, Zhaomin Wu, Shaobo Hu, Ning Wang, Yuan Li, Xu Liu, and Bingsheng He. 2020. A Survey on Federated Learning Systems: Vision, Hype and Reality for Data Privacy and Protection.arXiv preprint arXiv:1907.09693 (2020)
2020 arXiv
-
[118]
Tommy Li and Cory Merkel. 2021. Model Extraction and Adversarial Attacks on Neural Networks Using Switching Power Information. In Artificial Neural Networks and Machine Learning – ICANN 2021 . Springer
2021
-
[119]
Xiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang, and Zhihua Zhang. 2019. On the convergence of fedavg on non-iid data. arXiv preprint arXiv:1907.02189 (2019)
2019 arXiv
-
[120]
Yuxuan Li, Sarthak Kumar Maharana, and Yunhui Guo. 2024. Not Just Change the Labels, Learn the Features: Watermarking Deep Neural Networks with Multi-View Data. arXiv preprint arXiv:2403.10663 (2024)
2024 arXiv
-
[121]
Yiming Li, Linghui Zhu, Xiaojun Jia, Yong Jiang, Shu-Tao Xia, and Xiaochun Cao. 2022. Defending against model stealing via verifying embedded external features. In Proceedings of the AAAI conference on artificial intelligence , Vol. 36. 1464–1472
2022
-
[122]
Chuang Liang, Jie Huang, Zeping Zhang, and Shuaishuai Zhang. 2024. Defending against model extraction attacks with OOD feature learning and decision boundary confusion. Computers & Security (2024), 103563
2024
-
[123]
Siyuan Liang, Aishan Liu, Jiawei Liang, Longkang Li, Yang Bai, and Xiaochun Cao. 2022. Imitated Detectors: Stealing Knowledge of Black-box Object Detectors. In Proceedings of the 30th ACM International Conference on Multimedia . ACM, 6090–6099. https://doi.org/10.1145/3503161....
2022
-
[124]
Hsiao-Ying Lin, Chengfang Fang, and Jie Shi. 2020. Bident Structure for Neural Network Model Protection.. In ICISSP. 377–384
2020
-
[125]
Bo Liu, Ming Ding, Sina Shaham, Wenny Rahayu, Farhad Farokhi, and Zihuai Lin. 2021. When machine learning meets privacy: A survey and outlook. ACM Computing Surveys (CSUR) 54, 2 (2021), 1–36
2021
-
[126]
Jialin Liu and Han Wang. 2024. Model Extraction Attack against On-device Deep Learning with Power Side Channel. In 2024 25th International Symposium on Quality Electronic Design (ISQED) . IEEE
2024
-
[127]
Xinjing Liu, Zhuo Ma, Yang Liu, Zhan Qin, Junwei Zhang, and Zhuzhu Wang. 2022. SeInspect: Defending Model Stealing via Heterogeneous Semantic Inspection. In Computer Security – ESORICS 2022 . Springer
2022
-
[128]
Ximeng Liu, Lehui Xie, Yaopeng Wang, Jian Zou, Jinbo Xiong, Zuobin Ying, and Athanasios V Vasilakos. 2020. Privacy and security issues in deep learning: A survey. IEEE Access 9 (2020), 4566–4593
2020
-
[129]
Yupei Liu, Jinyuan Jia, Hongbin Liu, and Neil Zhenqiang Gong. 2022. StolenEncoder: Stealing Pre-trained Encoders in Self-supervised Learning. arXiv preprint arXiv:2201.05889 (2022)
2022 arXiv
-
[130]
Yuntao Liu and Ankur Srivastava. 2020. Ganred: Gan-based reverse engineering of dnns via cache side-channel. In Proceedings of the 2020 ACM SIGSAC Conference on Cloud Computing Security Workshop . 41–52
2020
-
[131]
Yu-Hsin Liu, Yu-Chun Shen, Hsi-Wen Chen, and Ming-Syan Chen. 2024. Construct a Secure CNN Against Gradient Inversion Attack. In Advances in Knowledge Discovery and Data Mining . Springer
2024
-
[132]
Nils Lukas, Yuxuan Zhang, and Florian Kerschbaum. 2019. Deep neural network fingerprinting by conferrable adversarial examples. arXiv preprint arXiv:1912.00888 (2019)
2019 arXiv
-
[133]
Lingjuan Lyu, Han Yu, Xingjun Ma, Chen Chen, Lichao Sun, Jun Zhao, Qiang Yang, and S Yu Philip. 2022. Privacy and robustness in federated learning: Attacks and defenses. IEEE transactions on neural networks and learning systems (2022)
2022
-
[134]
Pratyush Maini, Mohammad Yaghini, and Nicolas Papernot. 2021. Dataset inference: Ownership resolution in machine learning. arXiv preprint arXiv:2104.10706 (2021)
2021 arXiv
-
[135]
Antonio Manzalini et al. 2018. Edge Computing: A Market Snapshot . White Paper. 5G Infrastructure Association
2018
-
[136]
Yuyi Mao, Changsheng You, Jun Zhang, Kaibin Huang, and Khaled B. Letaief. 2017. A Survey on Mobile Edge Computing: The Communication Perspective. IEEE Communications Surveys & Tutorials 19, 4 (2017), 2322–2358
2017
-
[137]
AprilPyone Maungmaung and Hitoshi Kiya. 2021. A protection method of trained CNN model with a secret key from unauthorized access. APSIPA Transactions on Signal and Information Processing 10 (2021), e15. https: //doi.org/10.1017/ATSIP.2021.13
2021 doi
-
[138]
Mantas Mazeika, Bo Li, and David Forsyth. 2022. How to steer your adversary: Targeted and efficient model stealing defenses with gradient redirection. In International conference on machine learning . PMLR, 15241–15254
2022
-
[139]
Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication- Efficient Learning of Deep Networks from Decentralized Data. In Proceedings of the 20th International Conference on Artificial Intelligence and Statistics (Proceedings of...
2017
-
[140]
Vincent Meyers, Michael Hefenbrock, Dennis Gnad, and Mehdi Tahoori. 2024. Trained to Leak: Hiding Trojan Side-Channels in Neural Network Weights. In 2024 IEEE International Symposium on Hardware Oriented Security and Trust (HOST). IEEE
2024
-
[141]
Dragan, and Moritz Hardt
Smitha Milli, Ludwig Schmidt, Anca D. Dragan, and Moritz Hardt. 2018. Model Reconstruction from Model Explana- tions. Proceedings of the Conference on Fairness, Accountability, and Transparency (2018)
2018
-
[142]
Smitha Milli, Ludwig Schmidt, Anca D Dragan, and Moritz Hardt. 2019. Model reconstruction from model explanations. In Proceedings of the Conference on Fairness, Accountability, and Transparency . 1–9
2019
-
[143]
Takayuki Miura, Satoshi Hasegawa, and Toshiki Shibahara. 2021. MEGEX: Data-Free Model Extraction Attack against Gradient-Based Explainable AI. (2021). http://arxiv.org/abs/2107.08909
2021 arXiv
-
[144]
Payman Mohassel and Yupeng Zhang. 2017. Secureml: A system for scalable privacy-preserving machine learning. In 2017 IEEE symposium on security and privacy (SP) . IEEE, 19–38
2017
-
[145]
Yuto Mori, Atsushi Nitanda, and Akiko Takeda. 2021. BODAME: Bilevel Optimization for Defense Against Model Extraction. arXiv preprint arXiv:2103.06797 (2021)
2021 arXiv
-
[146]
Preston Mwiinga. 2023. Investigating the Far-Reaching Consequences of Cybercrime A Case Study on the Impact in Lusaka. https://doi.org/10.13140/RG.2.2.15525.68329
2023
-
[147]
Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019. Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In 2019 IEEE symposium on security and privacy (SP). IEEE, 739–753
2019
-
[148]
Sahil Nayan, Bhoomika Sharma, Sepehr Talebi, Tianming Zhu, Kui Ren, Divyakant Sharma, and Yifan Yu. 2024. SoK: All You Need to Know About On-Device ML Model Extraction - The Gap Between Research and Practice. In 31st USENIX Security Symposium (USENIX Security 24)
2024
-
[149]
Najmeh Nazari, Furi Xiang, Chongzhou Fang, Hosein Mohammadi Makrani, Aditya Puri, Kartik Patwari, Hossein Sayadi, Setareh Rafatirad, Chen-Nee Chuah, and Houman Homayoun. 2024. LLM-FIN: Large Language Models 111:50 Zhao et al. Fingerprinting Attack on Edge Devices. In 2024 25th...
2024
-
[150]
Seong Joon Oh, Max Augustin, Bernt Schiele, and Mario Fritz. 2018. Towards Reverse-Engineering Black-Box Neural Networks. arXiv preprint arXiv:1711.01768 (2018)
2018 arXiv
-
[151]
Abdullah Caglar Oksuz, Anisa Halimi, and Erman Ayday. 2023. AUTOLYCUS: Exploiting Explainable AI (XAI) for Model Extraction Attacks against White-Box Models. arXiv preprint arXiv:2302.02162 (2023). http://arxiv.org/abs/ 2302.02162
2023 arXiv
-
[152]
Olatunji, Mandeep Rathee, Thorben Funke, and Megha Khosla
Iyiola E. Olatunji, Mandeep Rathee, Thorben Funke, and Megha Khosla. 2023. Private Graph Extraction via Feature Explanations. Proceedings on Privacy Enhancing Technologies (2023). http://arxiv.org/abs/2206.14724
2023 arXiv
-
[153]
Daryna Oliynyk, Rudolf Mayer, and Andreas Rauber. 2023. I Know What You Trained Last Summer: A Survey on Stealing Machine Learning Models and Defences. Comput. Surveys (2023). https://doi.org/10.1145/3595292
2023 doi
-
[154]
Brooks Olney and Robert Karam. 2022. Protecting deep neural network intellectual property with architecture- agnostic input obfuscation. In Proceedings of the Great Lakes Symposium on VLSI 2022 . 111–115
2022
-
[156]
Tribhuvanesh Orekondy, Bernt Schiele, and Mario Fritz. 2019. Prediction poisoning: Towards defenses against dnn model stealing attacks. arXiv preprint arXiv:1906.10908 (2019)
2019 arXiv
-
[157]
Soham Pal, Yash Gupta, Aditya Kanade, and Shirish Shevade. 2021. Stateful Detection of Model Extraction Attacks. arXiv preprint arXiv:2107.05166 (2021)
2021 arXiv
-
[159]
Kaiyi Pang, Tao Qi, Chuhan Wu, and Minhao Bai. 2024. Adaptive and robust watermark against model extraction attack. arXiv preprint arXiv:2405.02365 (2024)
2024 arXiv
-
[160]
Berkay Celik, and Ananthram Swami
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami. 2017. Practical Black-Box Attacks against Machine Learning. InProceedings of the 2017 ACM on Asia Conference on Computer and Communications Security (ASIA CCS’17) . Associatio...
2017
-
[161]
Nicolas Papernot, Patrick McDaniel, Arunesh Sinha, and Michael P. Wellman. 2018. SoK: Security and Privacy in Machine Learning. In 2018 IEEE European Symposium on Security and Privacy (EuroS&P) . IEEE, 399–414. https: //doi.org/10.1109/EuroSP.2018.00035
2018
-
[162]
Vaidehi Patil, Peter Hase, and Mohit Bansal. 2023. Can sensitive information be deleted from llms? objectives for defending against extraction attacks. arXiv preprint arXiv:2309.17410 (2023)
2023 arXiv
-
[163]
Xinjun Pei, Xiaoheng Deng, Shengwei Tian, Jianqing Liu, and Kaiping Xue. 2024. Privacy-Enhanced Graph Neural Network for Decentralized Local Graphs. IEEE Transactions on Information Forensics and Security (2024)
2024
-
[164]
Zirui Peng, Shaofeng Li, Guoxing Chen, Cheng Zhang, Haojin Zhu, and Minhui Xue. 2022. Fingerprinting deep neural networks globally via universal adversarial perturbations. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition . 13430–13439
2022
-
[165]
Marcin Podhajski, Jan Dubiński, Franziska Boenisch, Adam Dziedzic, Agnieszka Pregowska, and Tomasz Michalak
-
[166]
Adnan Qayyum, Aneeqa Ijaz, Muhammad Usama, Waleed Iqbal, Junaid Qadir, Yehia Elkhatib, and Ala Al-Fuqaha
-
[167]
Tao Qi, Fangzhao Wu, Chuhan Wu, Liang He, Yongfeng Huang, and Xing Xie. 2023. Differentially private knowledge transfer for federated learning. Nature Communications 14, 1 (2023), 3785
2023
-
[168]
Ling Qian, Zhiguo Luo, Yujian Du, and Leitao Guo. 2009. Cloud computing: An overview. In Cloud Computing: First International Conference, CloudCom 2009, Beijing, China, December 1-4, 2009. Proceedings 1 . Springer, 626–631
2009
-
[169]
Yang Qin, Hiroki Matsutani, and Masaaki Kondo. 2020. A selective model aggregation approach in federated learning for online anomaly detection. In 2020 International Conferences on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyb...
2020
-
[170]
Adnan Siraj Rakin, Md Hafizul Islam Chowdhuryy, Fan Yao, and Deliang Fan. 2022. DeepSteal: Advanced Model Extractions Leveraging Efficient Weight Stealing in Memories. In 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 2193–2210. https://doi.org/10.1109/SP46214.2022.9833743
2022
-
[171]
Robert Nikolai Reith, Thomas Schneider, and Oleksandr Tkachenko. 2019. Efficiently Stealing your Machine Learning Models. In Proceedings of the 18th ACM Workshop on Privacy in the Electronic Society . 198–210. https://doi.org/10. A Systematic Survey of Model Extraction Attacks...
2019
-
[172]
Pengcheng Ren, Chaoshun Zuo, Xiaofeng Liu, Wenrui Diao, Qingchuan Zhao, and Shanqing Guo. 2024. DEMISTIFY: Identifying On-device Machine Learning Models Stealing and Reuse Vulnerabilities in Mobile Apps. In Proceedings of the IEEE/ACM 46th International Conference on Software ...
2024
-
[173]
Mauro Ribeiro, Katarina Grolinger, and Miriam AM Capretz. 2015. Mlaas: Machine learning as a service. In 2015 IEEE 14th international conference on machine learning and applications (ICMLA) . IEEE, 896–902
2015
-
[174]
Maria Rigaki and Sebastian Garcia. 2023. A survey of privacy attacks in machine learning. Comput. Surveys 56, 4 (2023), 1–34
2023
-
[175]
David Rolnick and Konrad Paul Kording. 2019. Reverse-engineering deep ReLU networks. In International Conference on Machine Learning
2019
-
[176]
Amir Mahdi Sadeghzadeh, Amir Mohammad Sobhanian, Faezeh Dehghan, and Rasool Jalili. 2023. HODA: Hardness- oriented detection of model extraction attacks. IEEE Transactions on Information Forensics and Security (2023)
2023
-
[177]
2023.{GAP}: Differentially Private Graph Neural Networks with Aggregation Perturbation
Sina Sajadmanesh, Ali Shahin Shamsabadi, Aurélien Bellet, and Daniel Gatica-Perez. 2023.{GAP}: Differentially Private Graph Neural Networks with Aggregation Perturbation. In32nd USENIX Security Symposium (USENIX Security 23). 3223–3240
2023
-
[178]
Venkatesh Babu
Sunandini Sanyal, Sravanti Addepalli, and R. Venkatesh Babu. 2022. Towards Data-Free Model Stealing in a Hard Label Setting. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) . 20543–20552
2022
-
[179]
Mahadev Satyanarayanan. 2017. The Emergence of Edge Computing. Computer 50, 1 (2017), 30–39
2017
-
[180]
Zeyang Sha, Xinlei He, Ning Yu, Michael Backes, and Yang Zhang. 2023. Can’t Steal? Cont-Steal! Contrastive Stealing Attacks Against Image Encoders. arXiv preprint arXiv:2201.07513 (2023). http://arxiv.org/abs/2201.07513
2023 arXiv
-
[181]
Zeyang Sha and Yang Zhang. 2024. Prompt Stealing Attacks Against Large Language Models. arXiv preprint arXiv:2402.12959 (2024)
2024 arXiv
-
[182]
Xinyue Shen, Yiting Qu, Michael Backes, and Yang Zhang. 2024. Prompt Stealing Attacks Against Text-to-Image Generation Models. arXiv preprint arXiv:2302.09923 (2024)
2024 arXiv
-
[183]
Yun Shen, Xinlei He, Yufei Han, and Yang Zhang. 2021. Model Stealing Attacks Against Inductive Graph Neural Networks. arXiv preprint arXiv:2112.08331 (2021)
2021 arXiv
-
[184]
Weisong Shi, Jie Cao, Quan Zhang, Youhuizi Li, and Lanyu Xu. 2016. Edge Computing: Vision and Challenges. IEEE Internet of Things Journal 3, 5 (2016), 637–646
2016
-
[185]
Yi Shi, Yalin Sagduyu, and Alexander Grushin. 2017. How to steal a machine learning classifier with deep learning. In 2017 IEEE International Symposium on Technologies for Homeland Security (HST) . IEEE, 1–5. https://doi.org/10. 1109/THS.2017.7943475
2017
-
[186]
Sagduyu, Kemal Davaslioglu, and Jason H
Yi Shi, Yalin E. Sagduyu, Kemal Davaslioglu, and Jason H. Li. 2018. Active Deep Learning Attacks under Strict Rate Limitations for Online API Calls. In 2018 IEEE International Symposium on Technologies for Homeland Security (HST) . IEEE, 1–6. https://doi.org/10.1109/THS.2018.8574124
2018
-
[187]
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017. Membership inference attacks against machine learning models. In 2017 IEEE symposium on security and privacy (SP) . IEEE, 3–18
2017
-
[188]
Nurit Spingarn-Eliezer and Tomer Michaeli. 2024. Stealing Image-to-Image Translation Models With a Single Query. arXiv preprint arXiv:2406.00828 (2024)
2024 arXiv
-
[189]
François-Xavier Standaert. 2010. Introduction to side-channel attacks. Secure integrated circuits and systems (2010), 27–42
2010
-
[190]
Yidan Sun, Guiyuan Jiang, Xinwang Liu, Peilan He, and Siew-Kei Lam. 2024. Layer Sequence Extraction of Optimized DNNs Using Side-Channel Information Leaks. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems (2024)
2024
-
[191]
Yidan Sun, Siew-Kei Lam, Guiyuan Jiang, and Peilan He. 2024. Streamlining DNN Obfuscation to Defend Against Model Stealing Attacks. In 2024 IEEE International Symposium on Circuits and Systems (ISCAS) . IEEE, 1–5
2024
-
[192]
K’alm’an Szentannai, Jalal Al-Afandi, and Andr’as Horv’ath. 2020. Preventing neural network weight stealing via network obfuscation. In Intelligent Computing: Proceedings of the 2020 Computing Conference, Volume 3 . Springer, 1–11
2020
-
[193]
Sebastian Szyller, Buse Gul Atli, Samuel Marchal, and N. Asokan. 2021. DAWN: Dynamic Adversarial Watermarking of Neural Networks. In Proceedings of the 29th ACM International Conference on Multimedia . 4417–4425. https: //doi.org/10.1145/3474085.3475591
2021
-
[194]
Sebastian Szyller, Vasisht Duddu, Tommi Gröndahl, and N. Asokan. 2023. Good Artists Copy, Great Artists Steal: Model Extraction Attacks Against Image Translation Models. arXiv preprint arXiv:2104.12623 (2023). http://arxiv. org/abs/2104.12623
2023 arXiv
-
[195]
Tatsuya Takemura, Naoto Yanai, and Toru Fujiwara. 2020. Model Extraction Attacks against Recurrent Neural Networks. arXiv preprint arXiv:2002.00123 (2020). https://arxiv.org/abs/2002.00123 111:52 Zhao et al
2020 arXiv
-
[196]
Tarik Taleb, Konstantinos Samdanis, Badr Mada, Hannu Flinck, Sunny Dutta, and Dario Sabella. 2017. On Multi- Access Edge Computing: A Survey of the Emerging 5G Network Edge Cloud Architecture and Orchestration. IEEE Communications Surveys & Tutorials 19, 3 (2017), 1657–1681
2017
-
[197]
Jingxuan Tan, Nan Zhong, Zhenxing Qian, Xinpeng Zhang, and Sheng Li. 2023. Deep Neural Network Watermarking against Model Extraction Attack. In Proceedings of the 31st ACM International Conference on Multimedia . https: //doi.org/10.1145/3581783.3612515
2023
-
[199]
Ruixiang Tang, Hongye Jin, Mengnan Du, Curtis Wigington, Rajiv Jain, and Xia Hu. 2023. Exposing Model Theft: A Robust and Transferable Watermark for Thwarting Model Extraction Attacks. In Proceedings of the 32nd ACM International Conference on Information and Knowledge Managem...
2023
-
[200]
Harry Chandra Tanuwidjaja, Rakyong Choi, Seunggeun Baek, and Kwangjo Kim. 2020. Privacy-preserving deep learning on machine learning as a service—a comprehensive survey. IEEE Access 8 (2020), 167425–167447
2020
-
[201]
Florian Tramer and Dan Boneh. 2018. Slalom: Fast, verifiable and private execution of neural networks in trusted hardware. arXiv preprint arXiv:1806.03287 (2018)
2018 arXiv
-
[202]
Boneh, and P
Florian Tramèr, Alexey Kurakin, Nicolas Papernot, D. Boneh, and P. Mcdaniel. 2017. Ensemble Adversarial Training: Attacks and Defenses. In ArXiv
2017
-
[203]
Reiter, and Thomas Ristenpart
Florian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction APIs. In Proceedings of the 25th USENIX Conference on Security Symposium (SEC’16) . 601–618
2016
-
[204]
Walls, and Nicolas Papernot
Jean-Baptiste Truong, Pratyush Maini, Robert J. Walls, and Nicolas Papernot. 2021. Data-Free Model Extraction. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) . 4322–4332
2021
-
[205]
Jo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin, Baris Kasikci, Frank Piessens, Mark Silberstein, Thomas F Wenisch, Yuval Yarom, and Raoul Strackx. 2018. Foreshadow: Extracting the keys to the intel{SGX} kingdom with transient{Out-of-Order} execution. In 27th USENIX Se...
2018
-
[206]
Blesson Varghese, Nan Wang, Sakil Barbhuiya, Peter Kilpatrick, and Dimitrios S Nikolopoulos. 2016. Challenges and opportunities in edge computing. In 2016 IEEE international conference on smart cloud (SmartCloud) . IEEE, 20–26
2016
-
[207]
Stavros Volos, Kapil Vaswani, and Rodrigo Bruno. 2018. Graviton: Trusted execution environments on{GPUs}. In 13th USENIX Symposium on Operating Systems Design and Implementation (OSDI 18) . 681–696
2018
-
[208]
Asim Waheed, Vasisht Duddu, and N. Asokan. 2023. GrOVe: Ownership Verification of Graph Neural Networks using Embeddings. arXiv preprint arXiv:2304.08566 (2023). http://arxiv.org/abs/2304.08566
2023 arXiv
-
[209]
Aidmar Wainakh, Fabrizio Ventola, Till Müßig, Jens Keim, Carlos Garcia Cordero, Ephraim Zimmer, Tim Grube, Kristian Kersting, and Max Mühlhäuser. 2022. User-Level Label Leakage from Gradients in Federated Learning. arXiv preprint arXiv:2105.09369 (2022). http://arxiv.org/abs/2...
2022 arXiv
-
[210]
Binghui Wang and Neil Zhenqiang Gong. 2018. Stealing Hyperparameters in Machine Learning.2018 IEEE Symposium on Security and Privacy (SP) (2018), 36–52
2018
-
[211]
Chawla, and Jundong Li
Song Wang, Yushun Dong, Binchi Zhang, Zihan Chen, Xingbo Fu, Yinhan He, Cong Shen, Chuxu Zhang, Nitesh V. Chawla, and Jundong Li. 2024. Safety in Graph Machine Learning: Threats and Safeguards. arXiv preprint arXiv:2405.11034 (2024)
2024 arXiv
-
[212]
Shang Wang, Tianqing Zhu, Bo Liu, Ming Ding, Xu Guo, Dayong Ye, Wanlei Zhou, and Philip S. Yu. 2024. Unique Security and Privacy Threats of Large Language Model: A Comprehensive Survey. arXiv preprint arXiv:2406.07973 (2024). https://arxiv.org/abs/2406.07973
2024
-
[213]
Xinran Wang, Yu Xiang, Jun Gao, and Jie Ding. 2020. Information laundering for model privacy. arXiv preprint arXiv:2009.06112 (2020)
2020 arXiv
-
[214]
Yixu Wang, Jie Li, Hong Liu, Yan Wang, Yongjian Wu, Feiyue Huang, and Rongrong Ji. 2022. Black-Box Dissector: Towards Erasing-Based Hard-Label Model Stealing Attack. In Computer Vision – ECCV 2022 . Springer
2022
-
[215]
Yixu Wang and Xianming Lin. 2022. Enhance Model Stealing Attack via Label Refining. In 2022 7th International Conference on Intelligent Computing and Signal Processing (ICSP) . IEEE, 930–934. https://doi.org/10.1109/ICSP54964. 2022.9778562
2022
-
[216]
Yongjie Wang, Hangwei Qian, and Chunyan Miao. 2022. DualCF: Efficient Model Extraction Attack from Coun- terfactual Explanations. Proceedings of the 2022 ACM Conference on Fairness, Accountability, and Transparency (2022)
2022
-
[217]
Zebin Wang, Menghan Lin, Bolin Shen, Ken Anderson, Molei Liu, Tianxi Cai, and Yushun Dong. 2025. CEGA: A Cost-Effective Approach for Graph-Based Model Extraction and Acquisition. arXiv preprint arXiv:2506.17709 (2025)
2025 arXiv
-
[218]
Zhibo Wang, Mengkai Song, Zhifei Zhang, Yang Song, Qian Wang, and Hairong Qi. 2019. Beyond inferring class representatives: User-level privacy leakage from federated learning. In IEEE INFOCOM 2019-IEEE conference on computer communications. IEEE, 2512–2520. A Systematic Survey...
2019
-
[219]
Zhendong Wang, Xiaoming Zeng, Xulong Tang, Danfeng Zhang, Xing Hu, and Yang Hu. 2022. Demystifying Arch-hints for Model Extraction: An Attack in Unified Memory System. arXiv preprint arXiv:2208.13720 (2022)
2022 arXiv
-
[220]
Dong-Dong Wu, Chilin Fu, Weichang Wu, Wenwen Xia, Xiaolu Zhang, Jun Zhou, and Min-Ling Zhang. 2024. Efficient Model Stealing Defense with Noise Transition Matrix. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) . 16675–16684
2024
-
[221]
Tyshetskiy, Andrew Docherty, Kai Lu, and Liming Zhu
Huijun Wu, Chen Wang, Y. Tyshetskiy, Andrew Docherty, Kai Lu, and Liming Zhu. 2019. Adversarial Examples on Graph Data: Deep Insights into Attack and Defense. arXiv preprint arXiv:1903.01610 (2019)
2019 arXiv
-
[222]
Yixin Wu, Xinlei He, Pascal Berrang, Mathias Humbert, Michael Backes, Neil Zhenqiang Gong, and Yang Zhang
-
[223]
Yixin Wu, Rui Wen, Michael Backes, Ning Yu, and Yang Zhang. 2022. Model Stealing Attacks Against Vision-Language Models. (2022)
2022
-
[224]
Zhiyuan Wu, Sheng Sun, Yuwei Wang, Min Liu, Xuefeng Jiang, Runhan Li, and Bo Gao. 2023. Knowledge Distillation in Federated Edge Learning: A Survey. arXiv preprint arXiv:2301.05849 (2023). https://arxiv.org/abs/2301.05849
2023 arXiv
-
[225]
Zhiyuan Wu, Sheng Sun, Yuwei Wang, Min Liu, Ke Xu, Wen Wang, Xuefeng Jiang, Bo Gao, and Jinda Lu. 2023. FedCache: A Knowledge Cache-driven Federated Learning Architecture for Personalized Edge Intelligence. arXiv preprint arXiv:2308.07816 (2023)
2023 arXiv
-
[226]
Xun Xian, Mingyi Hong, and Jie Ding. 2022. A framework for understanding model extraction attack and defense. arXiv preprint arXiv:2206.11480 (2022)
2022 arXiv
-
[227]
arXiv preprint arXiv:2405.05784 (2024)
Link Stealing Attacks Against Inductive Graph Neural Networks. arXiv preprint arXiv:2405.05784 (2024)
2024 arXiv
-
[228]
Yi Xie, Jie Zhang, Shiqian Zhao, Tianwei Zhang, and Xiaofeng Chen. 2024. SAME: Sample Reconstruction against Model Extraction Attacks. In Proceedings of the AAAI Conference on Artificial Intelligence
2024
-
[229]
Hui Xu, Yuxin Su, Zirui Zhao, Yangfan Zhou, Michael R Lyu, and Irwin King. 2018. Deepobfuscation: Securing the structure of convolutional neural networks via knowledge distillation. arXiv preprint arXiv:1806.10313 (2018)
2018 arXiv
-
[230]
Jiashu Xu, Fei Wang, Mingyu Derek Ma, Pang Wei Koh, Chaowei Xiao, and Muhao Chen. 2024. Instructional fingerprinting of large language models. arXiv preprint arXiv:2401.12255 (2024)
2024 arXiv
-
[231]
Anli Yan, Ruitao Hou, Xiaozhang Liu, Hongyang Yan, Teng Huang, and Xianmin Wang. 2022. Towards explainable model extraction attacks. International Journal of Intelligent Systems 37 (2022), 9936–9956
2022
-
[232]
Yun Xiang, Zhuangzhi Chen, Zuohui Chen, Zebin Fang, Haiyang Hao, Jinyin Chen, Yi Liu, Zhefu Wu, Qi Xuan, and Xiaoniu Yang. 2020. Open dnn box by power side-channel attack. IEEE Transactions on Circuits and Systems II: Express Briefs 67, 11 (2020), 2717–2721
2020
-
[233]
Haonan Yan, Xiaoguang Li, Hui Li, Jiamin Li, Wenhai Sun, and Fenghua Li. 2021. Monitoring-based differential privacy mechanism against query flooding-based model extraction attack. IEEE Transactions on Dependable and Secure Computing 19, 4 (2021), 2680–2694
2021
-
[234]
Haonan Yan, Xiaoguang Li, Hui Li, Jiamin Li, Wenhai Sun, and Fenghua Li. 2022. Monitoring-Based Differential Privacy Mechanism Against Query Flooding-Based Model Extraction Attack. IEEE Transactions on Dependable and Secure Computing 19, 5 (2022), 3278–3292. https://doi.org/10...
2022
-
[235]
Fletcher, and Josep Torrellas
Mengjia Yan, Christopher W. Fletcher, and Josep Torrellas. 2020. Cache Telepathy: Leveraging Shared Resource Attacks to Learn DNN Architectures. In 29th USENIX Security Symposium (USENIX Security 20) . USENIX Association, 2003–2020
2020
-
[236]
Panpan Yang, Qinglong Wu, and Xinming Zhang. 2023. Efficient Model Extraction by Data Set Stealing, Balancing, and Filtering. IEEE Internet of Things Journal (2023). https://ieeexplore.ieee.org/abstract/document/10214537
2023
-
[237]
Anli Yan, Teng Huang, Lishan Ke, Xiaozhang Liu, Qi Chen, and Changyu Dong. 2023. Explanation leaks: Explanation- guided model extraction attacks. Information Sciences (2023)
2023
-
[238]
Wenbin Yang, Xueluan Gong, Yanjiao Chen, Qian Wang, and Jianshuo Dong. 2024. SwiftTheft: A Time-Efficient Model Extraction Attack Framework Against Cloud-Based Deep Neural Networks. Chinese Journal of Electronics (2024)
2024
-
[239]
Yifan Yao, Jinhao Duan, Kaidi Xu, Yuanfang Cai, Zhibo Sun, and Yue Zhang. 2024. A survey on large language model (llm) security and privacy: The good, the bad, and the ugly. High-Confidence Computing (2024), 100211
2024
-
[240]
Yuanshun Yao, Zhujun Xiao, Bolun Wang, Bimal Viswanath, Haitao Zheng, and Ben Y Zhao. 2017. Complexity vs. performance: empirical analysis of machine learning as a service. In Proceedings of the 2017 Internet Measurement Conference. 384–397
2017
-
[241]
Eda Yilmaz and Hacer Yalim Keles. 2024. Adversarial Sparse Teacher: Defense Against Distillation-Based Model Stealing Attacks Using Adversarial Examples. arXiv preprint arXiv:2403.05181 (2024)
2024 arXiv
-
[242]
Qiang Yang, Yang Liu, Tianjian Chen, and Yongxin Tong. 2019. Federated machine learning: Concept and applications. ACM Transactions on Intelligent Systems and Technology (TIST) 10, 2 (2019), 1–19
2019
-
[243]
Kota Yoshida, Takaya Kubota, Mitsuru Shiozaki, and Takeshi Fujino. 2019. Model-Extraction Attack Against FPGA- DNN Accelerator Utilizing Correlation Electromagnetic Analysis. In2019 IEEE 27th Annual International Symposium on Field-Programmable Custom Computing Machines (FCCM)...
2019
-
[244]
Xiaoyu You, Youhe Jiang, Jianwei Xu, Mi Zhang, and Min Yang. 2024. GNNGuard: A Fingerprinting Framework for Verifying Ownerships of Graph Neural Networks. arXiv preprint arXiv:2403.14476 (2024)
2024 arXiv
-
[245]
Honggang Yu, Haocheng Ma, Kaichen Yang, Yiqiang Zhao, and Yier Jin. 2020. Deepem: Deep neural networks model recovery through em side-channel information leakage. In 2020 IEEE International Symposium on Hardware Oriented Security and Trust (HOST) . IEEE, 209–218
2020
-
[246]
Honggang Yu, Kaichen Yang, Teng Zhang, Yun-Yun Tsai, Tsung-Yi Ho, and Yier Jin. 2020. CloudLeak: Large-Scale Deep Learning Models Stealing Through Adversarial Examples. In NDSS Symposium
2020
-
[247]
Kota Yoshida and Takeshi Fujino. 2024. Model Extraction Attack Without Natural Images. In Applied Cryptography and Network Security Workshops. Springer. 111:54 Zhao et al
2024
-
[248]
Binchi Zhang, Yushun Dong, Chen Chen, Yada Zhu, Minnan Luo, and Jundong Li. 2024. Adversarial Attacks on Fairness of Graph Neural Networks. arXiv preprint arXiv:2310.13822 (2024)
2024 arXiv
-
[249]
Boyang Zhang, Xinlei He, Yun Shen, Tianhao Wang, and Yang Zhang. 2023. A Plot is Worth a Thousand Words: Model Information Stealing Attacks via Scientific Plots. arXiv preprint arXiv:2302.11982 (2023). http://arxiv.org/abs/ 2302.11982
2023 arXiv
-
[250]
2020.{BatchCrypt}: Efficient homomor- phic encryption for{Cross-Silo} federated learning
Chengliang Zhang, Suyi Li, Junzhe Xia, Wei Wang, Feng Yan, and Yang Liu. 2020.{BatchCrypt}: Efficient homomor- phic encryption for{Cross-Silo} federated learning. In 2020 USENIX annual technical conference (USENIX ATC 20) . 493–506
2020
-
[251]
Yu, and Shui Yu
Chenhan Zhang, Weiqi Wang, James J.Q. Yu, and Shui Yu. 2023. Extracting Privacy-Preserving Subgraphs in Federated Graph Learning using Information Bottleneck. In Proceedings of the 2023 ACM Asia Conference on Computer and Communications Security. https://doi.org/10.1145/357985...
2023
-
[252]
Xiaoyong Yuan, Leah Ding, Lan Zhang, Xiaolin Li, and Dapeng Oliver Wu. 2022. ES Attack: Model Stealing Against Deep Neural Networks Without Data Hurdles. IEEE Transactions on Emerging Topics in Computational Intelligence 6, 4 (2022), 790–801. https://doi.org/10.1109/TETCI.2022.3161087
2022
-
[253]
Hengtong Zhang, Tianhang Zheng, Jing Gao, Chenglin Miao, Lu Su, Yaliang Li, and Kui Ren. 2019. Data Poisoning Attack against Knowledge Graph Embedding. In Proceedings of the Twenty-Eighth International Joint Conference on Artificial Intelligence. 4853–4859. https://www.ijcai.o...
2019
-
[254]
Jiliang Zhang, Shuang Peng, Yansong Gao, Zhi Zhang, and Qinghui Hong. 2023. APMSA: Adversarial Perturbation Against Model Stealing Attacks. IEEE Transactions on Information Forensics and Security (2023). https://ieeexplore. ieee.org/abstract/document/10049136
2023
-
[255]
Ruisi Zhang, Seira Hidano, and Farinaz Koushanfar. 2022. Text Revealer: Private Text Reconstruction via Model Inversion Attacks against Transformers. arXiv preprint arXiv:2209.10505 (2022). http://arxiv.org/abs/2209.10505
2022 arXiv
-
[256]
Sixiao Zhang, Hongzhi Yin, Hongxu Chen, and Cheng Long. 2024. Defense Against Model Extraction Attacks on Recommender Systems. In Proceedings of the 17th ACM International Conference on Web Search and Data Mining . 949–957. https://doi.org/10.1145/3616855.3635751
2024
-
[257]
Haitian Zhang, Guang Hua, Xinya Wang, Hao Jiang, and Wen Yang. 2023. Categorical Inference Poisoning: Verifiable Defense Against Black-Box DNN Model Stealing Without Constraining Surrogate Data and Query Times. IEEE Transactions on Information Forensics and Security (2023). ht...
2023
-
[258]
Yu, and Tyler Derr
Yi Zhang, Yuying Zhao, Zhaoqing Li, Xueqi Cheng, Yu Wang, Olivera Kotevska, Philip S. Yu, and Tyler Derr. 2023. A Survey on Privacy in Graph Neural Networks: Attacks, Preservation, and Applications.arXiv preprint arXiv:2308.16375 (2023). http://arxiv.org/abs/2308.16375
2023 arXiv
-
[259]
Zhanyuan Zhang, Yizheng Chen, and David Wagner. 2021. SEAT: Similarity encoder by adversarial training for detecting model extraction attack queries. In Proceedings of the 14th ACM Workshop on artificial intelligence and security. 37–48
2021
-
[260]
Zaixi Zhang, Qi Liu, Zhenya Huang, Hao Wang, Chengqiang Lu, Chuanren Liu, and Enhong Chen. 2021. GraphMI: Extracting Private Graph Data from Graph Neural Networks. In Proceedings of the Thirtieth International Joint Conference on Artificial Intelligence. 3749–3755
2021
-
[261]
Zhexin Zhang, Jiaxin Wen, and Minlie Huang. 2023. Ethicist: Targeted Training Data Extraction Through Loss Smoothed Soft Prompting and Calibrated Confidence Estimation. arXiv preprint arXiv:2307.04401 (2023). http: //arxiv.org/abs/2307.04401
2023 arXiv
-
[262]
Xinyi Zhang, Chengfang Fang, and Jie Shi. 2021. Thief, Beware of What Get You There: Towards Understanding Model Extraction Attack. arXiv preprint arXiv:2104.05921 (2021)
2021 arXiv
-
[263]
Kaixiang Zhao, Joseph Yousry Attalla, Qian Lou, and Yushun Dong. 2025. DESIGN: Encrypted GNN Inference via Server-Side Input Graph Pruning. arXiv preprint arXiv:2507.05649 (2025). A Systematic Survey of Model Extraction Attacks and Defenses: State-of-the-Art and Perspectives 111:55
2025 arXiv
-
[264]
Kaixiang Zhao, Lincan Li, Kaize Ding, Neil Zhenqiang Gong, Yue Zhao, and Yushun Dong. 2025. A Survey of Model Extraction Attacks and Defenses in Distributed Computing Environments. arXiv preprint arXiv:2502.16065 (2025)
2025 arXiv
-
[265]
Kaixiang Zhao, Lincan Li, Kaize Ding, Neil Zhenqiang Gong, Yue Zhao, and Yushun Dong. 2025. A Survey on Model Extraction Attacks and Defenses for Large Language Models. In Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V. 2 . 6227–6236
2025
-
[266]
Xiangyu Zhao, Hanzhou Wu, and Xinpeng Zhang. 2021. Watermarking Graph Neural Networks by Random Graphs. In 2021 9th International Symposium on Digital Forensics and Security (ISDFS) . IEEE, 1–6
2021
-
[267]
Bo Zhao, Konda Reddy Mopuri, and Hakan Bilen. 2020. idlg: Improved deep leakage from gradients. arXiv preprint arXiv:2001.02610 (2020)
2020 arXiv
-
[268]
Huadi Zheng, Qingqing Ye, Haibo Hu, Chengfang Fang, and Jie Shi. 2019. BDPL: A Boundary Differentially Private Layer Against Machine Learning Model Extraction Attacks. In Computer Security – ESORICS 2019 . Springer
2019
-
[269]
Mingyi Zhou, Xiang Gao, Jing Wu, John C Grundy, Xiao Chen, Chunyang Chen, and Li Li. 2022. Model Obfuscation for Securing Deployed Neural Networks. (2022)
2022
-
[270]
Shuai Zhou, Tianqing Zhu, Dayong Ye, Wanlei Zhou, and Wei Zhao. 2024. Inversion-Guided Defense: Detecting Model Stealing Attacks by Output Inverting. IEEE Transactions on Information Forensics and Security (2024)
2024
-
[271]
Tong Zhou, Yukui Luo, Shaolei Ren, and Xiaolin Xu. 2023. NNSplitter: an active defense solution for DNN model via automated weight obfuscation. In International Conference on Machine Learning . PMLR, 42614–42624
2023
-
[272]
Yunlong Zhao, Xiaoheng Deng, Yijing Liu, Xinjun Pei, Jiazhi Xia, and Wei Chen. 2024. Fully Exploiting Every Real Sample: SuperPixel Sample Gradient Model Stealing. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 24316–24325
2024
-
[273]
Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep leakage from gradients. Advances in neural information processing systems 32 (2019)
2019
-
[274]
Zhihao Zhu, Chenwang Wu, Rui Fan, Yi Yang, Defu Lian, and Enhong Chen. 2023. Model Stealing Attack against Graph Classification with Authenticity, Uncertainty and Diversity. arXiv preprint arXiv:2312.10943 (2023). http: //arxiv.org/abs/2312.10943
2023 arXiv
-
[275]
Jiawei Zhuang, Qi Zhang, and Chuxu Zhang. 2024. Unveiling the Secrets without Data: Can Graph Neural Networks Be Exploited through Data-Free Model Extraction Attacks?. In 31st USENIX Security Symposium (USENIX Security 24) . https://www.usenix.org/conference/usenixsecurity24/p...
2024
-
[277]
Hongyu Zhu, Sichu Liang, Wentao Hu, Fangqi Li, Ju Jia, and Shilin Wang. 2024. Reliable Model Watermarking: Defending Against Theft without Compromising on Evasion. arXiv preprint arXiv:2404.13518 (2024)
2024 arXiv
-
[2018]
In 2018 International Joint Conference on Neural Networks (IJCNN)
Copycat CNN: Stealing Knowledge by Persuading Confession with Random Non-Labeled Data. In 2018 International Joint Conference on Neural Networks (IJCNN) . IEEE, 1–8. https://doi.org/10.1109/IJCNN.2018.8489592
2018
-
[2020]
Frontiers in big Data 3 (2020), 587139
Securing machine learning in the cloud: A systematic review of cloud machine learning security. Frontiers in big Data 3 (2020), 587139
2020
-
[2023]
In 2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P)
When the Curious Abandon Honesty: Federated Learning Is Not Private. In 2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P) . https://ieeexplore.ieee.org/abstract/document/10190537
2023
-
[2024]
arXiv preprint arXiv:2405.12295 (2024)
Efficient Model-Stealing Attacks Against Inductive Graph Neural Networks. arXiv preprint arXiv:2405.12295 (2024)
2024 arXiv
Reviewed August 5, 2026 · model on record in the stance chip above.
Discussion (0). Sign in to comment.