{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/towards-reverse-engineering-black-box-neural","title":"Towards Reverse-Engineering Black-Box Neural Networks","arxiv_id":"1711.01768","date":"2017-11-06","proceeding":"ICLR 2018 1","authors":["Seong Joon Oh","Max Augustin","Bernt Schiele","Mario Fritz"],"abstract":"Many deployed learned models are black boxes: given input, returns output.\nInternal information about the model, such as the architecture, optimisation\nprocedure, or training data, is not disclosed explicitly as it might contain\nproprietary information or make the system more vulnerable. This work shows\nthat such attributes of neural networks can be exposed from a sequence of\nqueries. This has multiple implications. On the one hand, our work exposes the\nvulnerability of black-box neural networks to different types of attacks -- we\nshow that the revealed internal information helps generate more effective\nadversarial examples against the black box model. On the other hand, this\ntechnique can be used for better protection of private content from automatic\nrecognition models using adversarial examples. Our paper suggests that it is\nactually hard to draw a line between white box and black box models.","url_abs":"http://arxiv.org/abs/1711.01768v3","url_pdf":"http://arxiv.org/pdf/1711.01768v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"towards-reverse-engineering-black-box-neural","repo_url":"https://github.com/KuoTzu-yang/ML-reverse","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null},{"paper_slug":"towards-reverse-engineering-black-box-neural","repo_url":"https://github.com/coallaoh/whitenblackbox","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok","spdx":"MIT"}},{"paper_slug":"towards-reverse-engineering-black-box-neural","repo_url":"https://github.com/markliou/model_distillation","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":{"status":"ok","spdx":"MIT"}}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1711.01768","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}