{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/knockoff-nets-stealing-functionality-of-black","title":"Knockoff Nets: Stealing Functionality of Black-Box Models","arxiv_id":"1812.02766","date":"2018-12-06","proceeding":"CVPR 2019 6","authors":["Tribhuvanesh Orekondy","Bernt Schiele","Mario Fritz"],"abstract":"Machine Learning (ML) models are increasingly deployed in the wild to perform\na wide range of tasks. In this work, we ask to what extent can an adversary\nsteal functionality of such \"victim\" models based solely on blackbox\ninteractions: image in, predictions out. In contrast to prior work, we present\nan adversary lacking knowledge of train/test data used by the model, its\ninternals, and semantics over model outputs. We formulate model functionality\nstealing as a two-step approach: (i) querying a set of input images to the\nblackbox model to obtain predictions; and (ii) training a \"knockoff\" with\nqueried image-prediction pairs. We make multiple remarkable observations: (a)\nquerying random images from a different distribution than that of the blackbox\ntraining data results in a well-performing knockoff; (b) this is possible even\nwhen the knockoff is represented using a different architecture; and (c) our\nreinforcement learning approach additionally improves query sample efficiency\nin certain settings and provides performance gains. We validate model\nfunctionality stealing on a range of datasets and tasks, as well as on a\npopular image analysis API where we create a reasonable knockoff for as little\nas $30.","url_abs":"http://arxiv.org/abs/1812.02766v1","url_pdf":"http://arxiv.org/pdf/1812.02766v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"knockoff-nets-stealing-functionality-of-black","repo_url":"https://github.com/ssg-research/dawn-dynamic-adversarial-watermarking-of-neural-networks","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null},{"paper_slug":"knockoff-nets-stealing-functionality-of-black","repo_url":"https://github.com/trailofbits/privacyraven","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"unanswered"}}],"tasks":[{"task_slug":"reinforcement-learning","task_name":"Reinforcement Learning"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":"https://app.syntology.ai/?focus=1812.02766","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}