{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/copycat-cnn-stealing-knowledge-by-persuading","title":"Copycat CNN: Stealing Knowledge by Persuading Confession with Random Non-Labeled Data","arxiv_id":"1806.05476","date":"2018-06-14","proceeding":null,"authors":["Jacson Rodrigues Correia-Silva","Rodrigo F. Berriel","Claudine Badue","Alberto F. de Souza","Thiago Oliveira-Santos"],"abstract":"In the past few years, Convolutional Neural Networks (CNNs) have been\nachieving state-of-the-art performance on a variety of problems. Many companies\nemploy resources and money to generate these models and provide them as an API,\ntherefore it is in their best interest to protect them, i.e., to avoid that\nsomeone else copies them. Recent studies revealed that state-of-the-art CNNs\nare vulnerable to adversarial examples attacks, and this weakness indicates\nthat CNNs do not need to operate in the problem domain (PD). Therefore, we\nhypothesize that they also do not need to be trained with examples of the PD in\norder to operate in it.\n  Given these facts, in this paper, we investigate if a target black-box CNN\ncan be copied by persuading it to confess its knowledge through random\nnon-labeled data. The copy is two-fold: i) the target network is queried with\nrandom data and its predictions are used to create a fake dataset with the\nknowledge of the network; and ii) a copycat network is trained with the fake\ndataset and should be able to achieve similar performance as the target\nnetwork.\n  This hypothesis was evaluated locally in three problems (facial expression,\nobject, and crosswalk classification) and against a cloud-based API. In the\ncopy attacks, images from both non-problem domain and PD were used. All copycat\nnetworks achieved at least 93.7% of the performance of the original models with\nnon-problem domain data, and at least 98.6% using additional data from the PD.\nAdditionally, the copycat CNN successfully copied at least 97.3% of the\nperformance of the Microsoft Azure Emotion API. Our results show that it is\npossible to create a copycat CNN by simply querying a target network as\nblack-box with random non-labeled data.","url_abs":"http://arxiv.org/abs/1806.05476v1","url_pdf":"http://arxiv.org/pdf/1806.05476v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"copycat-cnn-stealing-knowledge-by-persuading","repo_url":"https://github.com/jeiks/Stealing_DL_Models","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"caffe2","reach":null}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1806.05476","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1806.05476"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/jeiks/Stealing_DL_Models","reach":null}],"summary":{"ran_honours":1,"unverified":2},"by_repo_kind":{"official":{"samples":3,"ran":1,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":3,"samples":[{"code_sha256_prefix":"e3f8928fcc9b5812","entry":"preprocess","repo":"jeiks/Stealing_DL_Models","repo_kind":"official","path":"Copycat_CNN-Expansion/01-classification_space-TSNE/experiment-01-DIG10/tsne.py","file_url":"https://github.com/jeiks/Stealing_DL_Models/blob/HEAD/Copycat_CNN-Expansion/01-classification_space-TSNE/experiment-01-DIG10/tsne.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":"invariant","behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"e3f8928fcc9b5812"}},{"code_sha256_prefix":"2cd7184053135d4d","entry":"read_file","repo":"jeiks/Stealing_DL_Models","repo_kind":"official","path":"Copycat_CNN-Expansion/01-classification_space-TSNE/experiment-01-DIG10/tsne.py","file_url":"https://github.com/jeiks/Stealing_DL_Models/blob/HEAD/Copycat_CNN-Expansion/01-classification_space-TSNE/experiment-01-DIG10/tsne.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"2cd7184053135d4d"}},{"code_sha256_prefix":"e8f4fa74fa55f9dc","entry":"run_tsne","repo":"jeiks/Stealing_DL_Models","repo_kind":"official","path":"Copycat_CNN-Expansion/01-classification_space-TSNE/experiment-01-DIG10/tsne.py","file_url":"https://github.com/jeiks/Stealing_DL_Models/blob/HEAD/Copycat_CNN-Expansion/01-classification_space-TSNE/experiment-01-DIG10/tsne.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"e8f4fa74fa55f9dc"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}