{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/stealing-machine-learning-models-via","title":"Stealing Machine Learning Models via Prediction APIs","arxiv_id":"1609.02943","date":"2016-09-09","proceeding":null,"authors":["Florian Tramèr","Fan Zhang","Ari Juels","Michael K. Reiter","Thomas Ristenpart"],"abstract":"Machine learning (ML) models may be deemed confidential due to their\nsensitive training data, commercial value, or use in security applications.\nIncreasingly often, confidential ML models are being deployed with publicly\naccessible query interfaces. ML-as-a-service (\"predictive analytics\") systems\nare an example: Some allow users to train models on potentially sensitive data\nand charge others for access on a pay-per-query basis.\n  The tension between model confidentiality and public access motivates our\ninvestigation of model extraction attacks. In such attacks, an adversary with\nblack-box access, but no prior knowledge of an ML model's parameters or\ntraining data, aims to duplicate the functionality of (i.e., \"steal\") the\nmodel. Unlike in classical learning theory settings, ML-as-a-service offerings\nmay accept partial feature vectors as inputs and include confidence values with\npredictions. Given these practices, we show simple, efficient attacks that\nextract target ML models with near-perfect fidelity for popular model classes\nincluding logistic regression, neural networks, and decision trees. We\ndemonstrate these attacks against the online services of BigML and Amazon\nMachine Learning. We further show that the natural countermeasure of omitting\nconfidence values from model outputs still admits potentially harmful model\nextraction attacks. Our results highlight the need for careful ML model\ndeployment and new model extraction countermeasures.","url_abs":"http://arxiv.org/abs/1609.02943v2","url_pdf":"http://arxiv.org/pdf/1609.02943v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"stealing-machine-learning-models-via","repo_url":"https://github.com/ftramer/Steal-ML","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"none","reach":{"status":"ok"}}],"tasks":[{"task_slug":"machine-learning","task_name":"BIG-bench Machine Learning"},{"task_slug":"learning-theory","task_name":"Learning Theory"},{"task_slug":"model-extraction","task_name":"Model extraction"},{"task_slug":"prediction","task_name":"Prediction"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1609.02943","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}