Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-07T11:29:49.140988Z
Paper Citation Record · LEDGER
As of 7 August 2026, this Paper Citation Record lists 65 of 65 outbound references and 5 inbound Pith citation observations for arXiv:2506.02362.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-07T11:29:49.140988Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-06T22:23:07.680268Z
A source-named dated measurement, never combined with another source.
Source: arxiv_reference, observed 2026-05-13T01:47:04.386257Z
65 of 65 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 96c75794-e6be-4f5f-ab25-f440b4922437 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Turning your weakness into a strength: Watermarking deep neural networks by backdooring
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation be2e1a90-1d5f-4fd9-9a63-0f39a787d654 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Backpropagation and stochastic gradient descent method.Neurocomputing, 5(4-5):185–196, 1993
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 4bf8f852-8f14-4a77-b99b-b19f53f8c588 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Knowledge distillation: A good teacher is patient and consistent
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8a5c073c-aa9a-4c3e-9684-cd0e2b2b7c20 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Data sharing and interoperability: Fostering in- novation and competition through apis.Computer Law & Security Review, 35(5):105314, 2019
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation a3d4e200-4019-494e-8d89-8ced57857a80 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models ATOM: A Framework of Detecting Query-Based Model Extraction Attacks for Graph Neural Networks
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0ea5740c-d6ed-43a8-9d60-590fb24db916 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models The mnist database of handwritten digit images for machine learning research [best of the web].IEEE signal processing magazine, 29(6):141–142, 2012
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8bde58b8-d2d0-4209-9809-52ee97f3304c · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Simon and Schuster, 2024
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 41cd6786-0211-476e-93c5-9e4226f9f477 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models An optimized intelligent open-source mlaas framework for user-friendly clustering and anomaly detection.The Journal of Supercomputing, 80(18):26658–26684, 2024
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation fc6d3599-e8f9-4b43-985f-8551e58340d4 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Efficient knowledge distillation from an ensemble of teachers
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 08e040c4-6dc7-4d73-9c5b-57430b1014a3 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Model extraction attacks and defenses on cloud-based machine learning models.IEEE Communications Magazine, 58(12):83–89, 2021
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation f16855de-899f-425e-8ec3-eda7369586a2 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Machine learning as a service (mlaas)—an enterprise perspective
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 6092f782-cd91-4955-acd6-94fdf7de893d · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models A realistic model extraction attack against graph neural networks.Knowledge-Based Systems, 300:112144, 2024
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 191e257e-35d0-42db-89c6-516d0d3adc49 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models The content moderator’s dilemma: Removal of toxic content and distortions to online discourse.arXiv preprint arXiv:2412.16114, 2024
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation bea71f1e-f0d2-4ac2-ba6b-2269554dde38 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Deep residual learning for image recognition
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 360b649d-826d-47d2-93d2-9288587b41ed · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Protecting intellectual property of language generation apis with lexical watermark
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 237dbdeb-8571-40fd-bd3b-d76d7054ec25 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Distilling the Knowledge in a Neural Network
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 30a2ff01-83d9-4c90-a8f9-89c8f82635fd · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Learning to learn from apis: Black-box data-free meta-learning
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation a0eb8dd1-8ebe-4440-98b0-1f1accb9c403 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Densely connected convolutional networks
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1ee8aefd-9dfe-4e30-ada2-4bdd7f01e201 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models High accuracy and high fidelity extraction of neural networks
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 808ccce3-1d0b-4dc7-b312-c9530357ddec · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models A comprehensive defense framework against model extraction attacks.IEEE Transactions on Dependable and Secure Computing, 21(2):685–700, 2023
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 81706863-f513-4aba-a4f3-f4af169e4e8b · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Prada: protecting against dnn model stealing attacks
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 1beb6478-54f6-405c-9fa9-a0152c35184b · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Maze: Data-free model stealing attack using zeroth-order gradient estimation
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 5f09adf9-dcb7-4d48-9041-4598d94e609c · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Protecting dnns from theft using an ensemble of diverse models
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 3955441e-2fd8-43a1-90d3-71bf3e8bf34e · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Defending against model stealing attacks with adaptive misinformation
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 88cf8439-7dd9-4013-997b-8cee12db35d0 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Model extraction warning in mlaas paradigm
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 6618bcec-d434-4885-996c-5257588e200a · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models NSML: Meet the MLaaS platform with a real-world case study
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 73a7fe6d-21f5-4f2f-a3b8-5414edb419ed · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Learning multiple layers of features from tiny images
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fe4c7ba1-a2ba-4621-beaf-3968cc1f29ae · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models An ensemble approach for classification and prediction of diabetes mellitus using soft voting classifier.International Journal of Cognitive Computing in Engineering, 2:40–46, 2021
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation f5cddcb3-116c-4e84-ba76-b0d8c9c1f670 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Defending against model extraction attacks with physical unclonable function.Information Sciences, 628:196–207, 2023
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation d443e543-093d-48c1-ad5e-cad525dc2094 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models PhD thesis, Nanyang Technological University, 2025
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation bd4ea582-1b84-450d-a09c-38891304ff16 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Defending against model extraction attacks with ood feature learning and decision boundary confusion.Computers & Security, 136:103563, 2024
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 43951b68-0877-4be8-875a-76f137355351 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Model extraction attacks revisited
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8baa84a2-ce0d-4bb3-b2e8-0f4f0f62093d · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Quda: Query-limited data-free model extraction
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 4f23fa17-4653-46b4-b192-46ce5dd9a5b8 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Model extraction attack and defense on deep generative models
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation cb1dd927-8bca-4b6d-b6dc-237b57b43496 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models SGDR: Stochastic Gradient Descent with Warm Restarts
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f562e1f9-6a63-46ce-9c48-6ee40a31722e · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Dynamic neural fortresses: An adaptive shield for model extraction defense
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation f0bec78b-5abf-4f04-b142-b25cbf44dff8 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Dataset Inference: Ownership Resolution in Machine Learning
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9674f173-d260-4e28-aa78-1212ee20ce3b · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models How to steer your adversary: Targeted and efficient model stealing defenses with gradient redirection
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 38841a3d-9dc2-47e3-98bf-60f0746a90df · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Mixed Precision Training
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 07a5608d-af51-4df9-a12d-4e48c60259e5 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Megex: Data-free model extraction attack against gradient-based explainable ai
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation dc245ebc-7ae6-4888-8f4f-737b6e094c16 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models The MIT Press, 2nd edition, 2018
Reference 41
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation a7bd935f-e061-422c-baf9-b48e639436c0 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models PhD thesis, Technische Universität Wien, 2023
Reference 42
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 022aa366-53cd-474e-bf7d-bcf7dc2eccb7 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Knockoff nets: Stealing functionality of black-box models
Reference 43
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 65aca9c0-a9e8-4ee8-93e7-fbd27e69b3f9 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Prediction Poisoning: Towards Defenses Against DNN Model Stealing Attacks
Reference 44
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 08f13667-6af2-48e7-91f2-ac6a2f8a4025 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Mod- elshield: Adaptive and robust watermark against model extraction attack.IEEE Transactions on Information Forensics and Security, 2025
Reference 45
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation ce321895-d395-4e4c-b557-f5a060d3255c · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Practical black-box attacks against machine learning
Reference 46
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7f57c3fd-0138-41fa-abc5-525e67ddcc6a · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Relational knowledge distillation
Reference 47
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2b2e1da6-907e-46ba-896e-e8e6c79b96b5 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Automatic differentiation in pytorch
Reference 48
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 87d3db77-060a-4b57-9b4e-8a27b012886f · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Mlaas: Machine learning as a service
Reference 49
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 3d91047b-bac6-4082-b95e-6827687c079d · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Privacy as intellectual property.Stan
Reference 50
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 779fd938-78b7-4503-9b3a-c3251d6657c5 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Mobilenetv2: Inverted residuals and linear bottlenecks
Reference 51
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a09ea711-c052-4ca0-8b65-5901ecb25f93 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Towards data-free model stealing in a hard label setting
Reference 52
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 97d8357e-3a61-4bce-9494-d1e8cfce3c1b · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models On efficient training of large-scale deep learning models.ACM Computing Surveys, 57(3):1–36, 2024
Reference 53
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation b18395a2-b178-42ae-8fd0-71d2ddbe7b94 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Does knowledge distillation really work?Advances in neural information processing systems, 34:6906–6919, 2021
Reference 54
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 06f032f6-7550-46ff-9bd2-eb488b2f58e1 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Deep neural network watermarking against model extraction attack
Reference 55
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 2f0e70fb-0d69-4c23-b134-697abad43b61 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Stealing machine learning models via prediction {APIs}
Reference 56
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 387f2316-fb70-4fc0-8316-a6da1a7e13cd · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Data-free model extraction
Reference 57
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation a178aa32-a927-43d1-ab26-826f99153f87 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Defending against data-free model extraction by distributionally robust defensive training.Advances in Neural Information Processing Systems, 36:624–637, 2023
Reference 58
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 72d6f83c-071d-4f74-8ba8-dc106a336bab · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Defense against model extraction attack by bayesian active watermarking
Reference 59
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation d288470e-414c-40f5-b4d6-14a0f1fe3c22 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Zero-shot knowledge distillation from a decision-based black-box model
Reference 60
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation db6c8b70-d670-4426-876a-7ddccb2326e4 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Towards explainable model extraction attacks.International Journal of Intelligent Systems, 37(11):9936–9956, 2022
Reference 61
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 89442633-a36a-4eca-9d97-d71fc9a0d943 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Unresolved cited work
Reference 62
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 19462489-82c2-446b-b2c6-93d1cfabf697 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Mlmodelci: An automatic cloud platform for efficient mlaas
Reference 63
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 261f865e-79f2-4b58-b2d9-217bf6e21583 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models Minimizing maximum model discrepancy for transferable black-box targeted attacks
Reference 64
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 80f696c6-adf2-4d0a-be40-44fff395ddd4 · outbound
MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models A survey of model extraction attacks and defenses in distributed computing environments, 2025
Reference 65
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 2915912e-4524-4069-9543-c9c1df610d22 · inbound
A Survey on Model Extraction Attacks and Defenses for Large Language Models MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ca490b50-3be2-4d14-98ef-3e15920dd554 · inbound
A Systematic Survey of Model Extraction Attacks and Defenses: State-of-the-Art and Perspectives MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models
Reference 42
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5da6b5f7-7453-4261-b633-fd1d64dc03b0 · inbound
Intellectual Property in Graph-Based Machine Learning as a Service: Attacks and Defenses MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models
Reference 182
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation beefe17b-0f1a-4e24-8930-e80ff25bc258 · inbound
LatentRouter: Can We Choose the Right Multimodal Model Before Seeing Its Answer? MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 9dde8944-2c60-4c02-844d-c0fd23468225 · inbound
ADS-C: Antidistillation Sampling for Classification MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models
Reference 41
Source-reported events for the cited work
Unavailable: canonical work link unavailable.