Browse State-of-the-Art › Model extraction
Model extraction
57 papers with code · 1 benchmark · 2 datasets archive 2025-07-28
Model extraction attacks, aka model stealing attacks, are used to extract the parameters from the target model. Ideally, the adversary will be able to steal and replicate a model that will have a very similar performance to the target model.
Description from the archive archive 2025-07-28.
Benchmarks archive 2025-07-28
1 leaderboard table shown for this task, 1 with rows (a “benchmark” on this site is a table with at least one row, as on /sota), ordered by row count. “Best model” is the first row in the archive's own order at snapshot; nothing is re-ranked here and metric direction is not recorded in the archive. PwC's Trend sparklines are not in the archive, so that column is omitted.
| Dataset | Best model (first row in archive order) | Paper | Code | Syntology | Compare |
|---|---|---|---|---|---|
| UML Classes With Specs (1 row) | three-step-original | Towards Automatically Extracting UML Class Diagrams from Natural... | code | — | Compare |
Syntology column: samples harvested from the paper's repositories and executed on synthesized fixtures; “ran” is not a correctness claim and does not order the table. A dash means no Syntology record for that paper, not a recorded non-run. Read from the graph 2026-09-24.
Libraries
Not in the archive: the export carries no per-task library table, so there is nothing to show at snapshot 2025-07-28.
Datasets archive 2025-07-28
2 datasets whose archive record lists this task, ordered by the archive's paper count.
Subtasks archive 2025-07-28
No subtask under this task in the archive's task tree.
Most implemented papers archive 2025-07-28
30 shown of 57 papers with code (176 tagged with this task in all), ordered by repositories listed in the archive, not by stars (the archive holds no stars, so PwC's “Social” and “Latest” sorts cannot be reproduced). Papers without a page here are shown as plain text.
-
3 Dec 2022 3 repositories listed Syntology ran 6 of 15 samples · 9 unverifiedMost cross-device federated learning (FL) studies focus on the model-homogeneous setting where the global server model and local client models are identical.
-
27 Feb 2020 3 repositories listedSuch pairs are watermarks, which are not sampled from the task distribution and are only known to the defender.
-
4 Sep 2024 2 repositories listed Syntology ran 6 of 7 samples · 1 unverified · 7 pointer-only (licence)Model extraction attacks (MEAs) on large language models (LLMs) have received increasing attention in recent research.
-
6 Feb 2023 2 repositories listedWe can then detect the secret message by probing a suspect model to tell if it is distilled from the protected one.
-
7 Oct 2021 2 repositories listedThe extraction of process models from text refers to the problem of turning the information contained in an unstructured textual process descriptions into a formal representation, i.
-
30 Nov 2020 2 repositories listedCurrent model extraction attacks assume that the adversary has access to a surrogate dataset with characteristics similar to the proprietary data used to train the victim model.
-
25 Oct 2020 2 repositories listedDeep Neural Networks (DNNs) have achieved remarkable performance on a range of tasks.
-
21 Jun 2025 1 repository listed Syntology ran 3 of 10 samples · 7 unverifiedGraph Neural Networks (GNNs) have demonstrated remarkable utility across diverse applications, and their growing complexity has made Machine Learning as a Service (MLaaS) a viable platform for scalable deployment.
-
3 Jun 2025 1 repository listedTo address this gap, we propose MISLEADER (enseMbles of dIStiLled modEls Against moDel ExtRaction), a novel defense strategy that does not rely on OOD assumptions.
-
20 Mar 2025 1 repository listed Syntology ran 3 of 3 samples · 0 unverifiedGraph Neural Networks (GNNs) have gained traction in Graph-based Machine Learning as a Service (GMLaaS) platforms, yet they remain vulnerable to graph-based model extraction attacks (MEAs), where adversaries reconstruct…
-
7 Feb 2025 1 repository listedThe advent of Machine Learning as a Service (MLaaS) has heightened the trade-off between model explainability and security.
-
2 Feb 2025 1 repository listedThe rapid advancement of large models, driven by their exceptional abilities in learning and generalization through large-scale pre-training, has reshaped the landscape of Artificial Intelligence (AI).
-
16 Jan 2025 1 repository listedGuided by the model, we further introduce: (1) a similarity-based training-free watermarking method for plug-and-play and flexible watermarking, and (2) a distribution-based multi-step watermark information transmission…
-
15 Nov 2024 1 repository listedIn this work, we introduce a new end-to-end attack framework designed for model extraction of embedded DNNs with high fidelity.
-
14 Nov 2024 1 repository listedEmbedding-as-a-Service (EaaS) has emerged as a successful business pattern but faces significant challenges related to various forms of copyright infringement, particularly, the API misuse and model extraction attacks.
-
23 Oct 2024 1 repository listedMotivated by this, in this paper, we propose a novel embedding-specific watermarking (ESpeW) mechanism to offer robust copyright protection for EaaS.
-
21 Sep 2024 1 repository listedModel extraction aims to create a functionally similar copy from a machine learning as a service (MLaaS) API with minimal overhead, typically for illicit profit or as a precursor to further attacks, posing a significant…
-
4 Aug 2024 1 repository listedIn the domain of black-box model extraction, conventional methods reliant on soft labels or surrogate datasets struggle with scaling to high-dimensional input spaces and managing the complexity of an extensive array of…
-
14 Jun 2024 1 repository listedOur study evaluates the feasibility of parameter extraction methods of Carlini et al.
-
29 May 2024 1 repository listedCounterfactual (CF) explanations for ML model predictions provide actionable recourse recommendations to individuals adversely impacted by predicted outcomes.
-
8 May 2024 1 repository listed Syntology ran 0 of 1 samples · 1 unverifiedHowever, counterfactual explanations can also be leveraged to reconstruct the model by strategically training a surrogate model to give similar predictions as the original (target) model.
-
4 Apr 2024 1 repository listedXAI techniques aim to enhance the transparency of ML models by providing insights, in terms of model's explanations, into their decision-making process.
-
15 Mar 2024 1 repository listedUnfortunately, existing methodologies based on trigger sets are still susceptible to functionality-stealing attacks, potentially enabling adversaries to steal the functionality of the source model without a reliable…
-
3 Mar 2024 1 repository listedEmbedding as a Service (EaaS) has become a widely adopted solution, which offers feature extraction capabilities for addressing various downstream tasks in Natural Language Processing (NLP).
-
26 Jan 2024 1 repository listedTo protect the Intellectual Property (IP) of the original owners over such DNN models, backdoor-based watermarks have been extensively studied.
-
17 Dec 2023 1 repository listedWhile deep learning models have shown significant performance across various domains, their deployment needs extensive resources and advanced computing infrastructure.
-
10 Nov 2023 1 repository listedOur extensive experiments on various datasets indicate that the proposed watermarking approach is effective and safe for verifying the copyright of VLPs for multi-modal EaaS and robust against model extraction attacks.
-
8 Nov 2023 1 repository listedIn this work, we explore the usage of an ensemble of deep learning models as our thief model.
-
25 Oct 2023 1 repository listedThese gradients are used to compute a swap loss, which maximizes the loss of the student model.
-
21 Oct 2023 1 repository listed Syntology ran 5 of 7 samples · 2 unverifiedWe study model extraction attacks in natural language processing (NLP) where attackers aim to steal victim models by repeatedly querying the open Application Programming Interfaces (APIs).
Syntology lines on 6 of the papers shown; no Syntology record for the others (a paper without an arXiv id cannot be joined to the graph, and absence from the graph layer is not a recorded non-run). “Ran” means the sample executed on a synthesized fixture, not that the paper's result was reproduced. Read from the graph 2026-09-24.
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections