[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-122628-en":3,"doc-seo-122628-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},122628,1099513958762,"Logic","https://ap-avatar.wpscdn.com/avatar/1000023916a998db790?x-image-process=image/resize,m_fixed,w_180,h_180&k=1784791008015729253",8,"Research & Report","I Know What You Trained Last Summer - A Survey on Stealing Machine Learning Models and Defences","Machine Learning-as-a-Service enables clients to access complex models via query APIs, but this exposure can jeopardize intellectual property including training data, optimized hyperparameters, and learned parameters. Adversaries can steal models using only prediction labels to replicate (almost) identical behavior. The survey systematizes model stealing attacks, compares their effectiveness across settings, and proposes a taxonomy for attack and defence techniques. It also provides selection guidelines and evaluates which defences weaken under current attack strategies.","arXiv :2206 .08451v1 [ cs .LG] 16 Jun 2022  \nI Know What You Trained Last Summer: A Survey on Stealing Machine Learning Models and Defences  \nDARYNA OLIYNYK, SBA Research, Austria  \nRUDOLF MAYER, SBA Research & Vienna University of Technology, Austria ANDREAS RAUBER, Vienna University of Technology, Austria  \nMachine Learning-as-a-Service (MLaaS) has become a widespread paradigm, making even the most complex machine learning models available for clients via e.g. a pay-per-query principle. This allows users to avoid time-consuming processes of data collection, hyperparameter tuning, and model training. However, by giving their customers access to the (predictions of their) models, MLaaS providers endanger their intellectual property, such as sensitive training data, optimised hyperparameters, or learned model parameters. Adversaries can create a copy of the model with (almost) identical behavior using the the prediction labels only. While many variants of this attack have been described, only scattered defence strategies have been proposed, addressing isolated threats. This raises the necessity for a thorough systematisation of the field of model stealing, to arrive at a comprehensive understanding why these attacks are successful, and how they could be holistically defended against. We address this by categorising and comparing model stealing attacks, assessing their performance, and exploring corresponding defence techniques in different settings. We propose a taxonomy for attack and defence approaches, and provide guidelines on how to select the right attack or defence strategy based on the goal and available resources. Finally, we analyse which defences are rendered less effective by current attack strategies.  \nCCS Concepts: • Security and privacy → Vulnerability management; • Computing methodologies → Machine learning.  \nAdditional Key Words and Phrases: Machine Learning, Model Stealing, Model Extraction  \nACM Reference Format:  \nDaryna Oliynyk, Rudolf Mayer, and Andreas Rauber. 2022. I Know What You Trained Last Summer: A Survey on Stealing Machine  \nLearning Models and Defences. 1, 1 (June 2022), 36 pages. [https://doi.org/10.1145/nnnnnnn.nnnnnnn](https://doi.org/10.1145/nnnnnnn.nnnnnnn)  \n1 INTRODUCTION  \nTraining a machine learning model can be a very complex and time as well as resource-consuming process. To safeguard their intellectual property, owners may opt to keep their models secret, allowing external users to access them only by input-output queries over a predefined API. However, black-box access to a model does not imply a protected model. Recent work has shown how an adversary can steal (extract) such models [1–3] . The technique of model stealing (also called model extraction) aims at obtaining e.g. training hyperparameters, the model architecture, learned parameters, or an approximation of the behavior of a model, all of which to the detriment of the lawful model owner.  \nThe number of domains where model stealing attacks are successful has dramatically risen over the last few years. Dozens of attacks were implemented to attack image classification [3], text classification [4], natural language processing [5] and reinforcement learning [6]. Jagielski et al. provide a preliminary taxonomy based on the attacker’s goal and  \nAuthors’ addresses: Daryna Oliynyk, SBA Research, Vienna, Austria, [doliynyk@sba-research.org](doliynyk@sba-research.org); Rudolf Mayer, SBA Research & Vienna University of  \nTechnology, Vienna, Austria, [rmayer@sba-research.org](rmayer@sba-research.org); Andreas Rauber, Vienna University of Technology, Vienna, Austria, [rauber@ifs.tuwien.ac.at](rauber@ifs.tuwien.ac.at).  \nPermission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work ","cbCait7Izhm1XSzl","https://ap.wps.com/l/cbCait7Izhm1XSzl","pdf",1187741,1,36,"English","en",105,"# Introduction\n## Model stealing under MLaaS black-box access\n## Existing attacks and the need for systematisation\n## Defence approaches: detection vs prevention","[{\"question\":\"Why does MLaaS increase the risk of intellectual property leakage?\",\"answer\":\"MLaaS exposes model predictions through pay-per-query access. By allowing adversaries to observe outputs, it becomes possible to infer sensitive aspects such as behavior, trained parameters, or optimized hyperparameters.\"},{\"question\":\"What is the goal of model stealing (model extraction)?\",\"answer\":\"Model stealing aims to obtain information like training hyperparameters, model architecture, learned parameters, or an approximation of a model’s behavior, harming the lawful model owner.\"},{\"question\":\"How does the paper distinguish between defence strategies?\",\"answer\":\"It contrasts attack detection, which informs the owner about stealing attempts or completed theft, with attack prevention, which seeks to make attacks ineffective or less effective, sometimes only under specific conditions.\"}]","I Know What You Trained Last Summer - A Survey on Stealing Machine Learning Models and Defences | PDF",1785811791,91,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"i-know-what-you-trained-last-summer-a-survey-on-stealing-machine-learning-models-and-defences","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/i-know-what-you-trained-last-summer-a-survey-on-stealing-machine-learning-models-and-defences/122628/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why does MLaaS increase the risk of intellectual property leakage?","Question",{"text":75,"@type":76},"MLaaS exposes model predictions through pay-per-query access. By allowing adversaries to observe outputs, it becomes possible to infer sensitive aspects such as behavior, trained parameters, or optimized hyperparameters.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What is the goal of model stealing (model extraction)?",{"text":80,"@type":76},"Model stealing aims to obtain information like training hyperparameters, model architecture, learned parameters, or an approximation of a model’s behavior, harming the lawful model owner.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the paper distinguish between defence strategies?",{"text":84,"@type":76},"It contrasts attack detection, which informs the owner about stealing attempts or completed theft, with attack prevention, which seeks to make attacks ineffective or less effective, sometimes only under specific conditions.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]