{"url":"/task/model-extraction","name":"Model extraction","slug":"model-extraction","description_markdown":"Model extraction attacks, aka model stealing attacks, are used to extract the parameters from the target model. Ideally, the adversary will be able to steal and replicate a model that will have a very similar performance to the target model.","categories":[{"name":"Adversarial","url":"/area/adversarial"},{"name":"Methodology","url":"/area/methodology"}],"source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","slug_source":"archive_url"},"counts":{"papers_tagged":176,"papers_with_code":57,"benchmarks":1,"benchmark_tables_in_archive":1,"benchmark_tables_shown":1,"benchmark_tables_withheld_as_spam":0,"benchmark_definition":"a leaderboard table with at least one row; benchmark_tables_shown also counts the zero-row tables; benchmark_tables_in_archive adds the tables withheld as spam","datasets":2,"subtasks":0,"parent_tasks":0},"benchmarks":[{"leaderboard":"/sota/model-extraction-on-uml-classes-with-specs","slug":"model-extraction-on-uml-classes-with-specs","dataset":"UML Classes With Specs","dataset_url":"/dataset/uml-classes-with-specs","rows_in_archive":1,"metrics":["Exact Match"],"first_row_in_archive_order":{"model":"three-step-original","paper_title":"Towards Automatically Extracting UML Class Diagrams from Natural Language Specifications","paper_url":"/paper/towards-automatically-extracting-uml-class","paper_date":"2022-10-26","arxiv_id":"2210.14441","code_links":[{"title":"XsongyangX/uml-translation-3step","url":"https://github.com/XsongyangX/uml-translation-3step"}],"syntology":null}}],"datasets":[{"url":"/dataset/data-collected-with-package-delivery","name":"Data Collected with Package Delivery Quadcopter Drone","full_name":"","num_papers_in_archive":2},{"url":"/dataset/uml-classes-with-specs","name":"UML Classes With Specs","full_name":"UML Class Diagrams Paired With Their English Specifications","num_papers_in_archive":1}],"subtasks":[],"parent_tasks":[],"papers":{"order":"repositories listed in the archive (desc), then date (desc); the archive holds no stars","population":"papers tagged with this task that list at least one repository in the archive","shown":30,"of":57,"tagged_in_all":176,"items":[{"url":"/paper/fedrolex-model-heterogeneous-federated","title":"FedRolex: Model-Heterogeneous Federated Learning with Rolling Sub-Model Extraction","date":"2022-12-03","arxiv_id":"2212.01548","repositories_listed":3,"syntology":{"n":15,"n_ran":6,"n_unverified":9,"n_pointer_only":0}},{"url":"/paper/entangled-watermarks-as-a-defense-against","title":"Entangled Watermarks as a Defense against Model Extraction","date":"2020-02-27","arxiv_id":"2002.12200","repositories_listed":3,"syntology":null},{"url":"/paper/alignment-aware-model-extraction-attacks-on","title":"\"Yes, My LoRD.\" Guiding Language Model Extraction with Locality Reinforced Distillation","date":"2024-09-04","arxiv_id":"2409.02718","repositories_listed":2,"syntology":{"n":7,"n_ran":6,"n_unverified":1,"n_pointer_only":7}},{"url":"/paper/protecting-language-generation-models-via","title":"Protecting Language Generation Models via Invisible Watermarking","date":"2023-02-06","arxiv_id":"2302.03162","repositories_listed":2,"syntology":null},{"url":"/paper/process-extraction-from-text-state-of-the-art","title":"Process Extraction from Text: Benchmarking the State of the Art and Paving the Way for Future Challenges","date":"2021-10-07","arxiv_id":"2110.03754","repositories_listed":2,"syntology":null},{"url":"/paper/data-free-model-extraction","title":"Data-Free Model Extraction","date":"2020-11-30","arxiv_id":"2011.14779","repositories_listed":2,"syntology":null},{"url":"/paper/now-you-see-me-cme-concept-based-model","title":"Now You See Me (CME): Concept-based Model Extraction","date":"2020-10-25","arxiv_id":"2010.13233","repositories_listed":2,"syntology":null},{"url":"/paper/cega-a-cost-effective-approach-for-graph","title":"CEGA: A Cost-Effective Approach for Graph-Based Model Extraction and Acquisition","date":"2025-06-21","arxiv_id":"2506.17709","repositories_listed":1,"syntology":{"n":10,"n_ran":3,"n_unverified":7,"n_pointer_only":0}},{"url":"/paper/misleader-defending-against-model-extraction","title":"MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models","date":"2025-06-03","arxiv_id":"2506.02362","repositories_listed":1,"syntology":null},{"url":"/paper/atom-a-framework-of-detecting-query-based","title":"ATOM: A Framework of Detecting Query-Based Model Extraction Attacks for Graph Neural Networks","date":"2025-03-20","arxiv_id":"2503.16693","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/from-counterfactuals-to-trees-competitive","title":"From Counterfactuals to Trees: Competitive Analysis of Model Extraction Attacks","date":"2025-02-07","arxiv_id":"2502.05325","repositories_listed":1,"syntology":null},{"url":"/paper/safety-at-scale-a-comprehensive-survey-of","title":"Safety at Scale: A Comprehensive Survey of Large Model Safety","date":"2025-02-02","arxiv_id":"2502.05206","repositories_listed":1,"syntology":null},{"url":"/paper/neural-honeytrace-a-robust-plug-and-play","title":"Neural Honeytrace: A Robust Plug-and-Play Watermarking Framework against Model Extraction Attacks","date":"2025-01-16","arxiv_id":"2501.09328","repositories_listed":1,"syntology":null},{"url":"/paper/a-hard-label-cryptanalytic-extraction-of-non","title":"A Hard-Label Cryptanalytic Extraction of Non-Fully Connected Deep Neural Networks using Side-Channel Attacks","date":"2024-11-15","arxiv_id":"2411.10174","repositories_listed":1,"syntology":null},{"url":"/paper/your-fixed-watermark-is-fragile-towards","title":"Your Semantic-Independent Watermark is Fragile: A Semantic Perturbation Attack against EaaS Watermark","date":"2024-11-14","arxiv_id":"2411.09359","repositories_listed":1,"syntology":null},{"url":"/paper/espew-robust-copyright-protection-for-llm","title":"Robust and Minimally Invasive Watermarking for EaaS","date":"2024-10-23","arxiv_id":"2410.17552","repositories_listed":1,"syntology":null},{"url":"/paper/efficient-and-effective-model-extraction","title":"Efficient and Effective Model Extraction","date":"2024-09-21","arxiv_id":"2409.14122","repositories_listed":1,"syntology":null},{"url":"/paper/2408-02140","title":"VidModEx: Interpretable and Efficient Black Box Model Extraction for High-Dimensional Spaces","date":"2024-08-04","arxiv_id":"2408.02140","repositories_listed":1,"syntology":null},{"url":"/paper/beyond-slow-signs-in-high-fidelity-model","title":"Beyond Slow Signs in High-fidelity Model Extraction","date":"2024-06-14","arxiv_id":"2406.10011","repositories_listed":1,"syntology":null},{"url":"/paper/watermarking-counterfactual-explanations","title":"Watermarking Counterfactual Explanations","date":"2024-05-29","arxiv_id":"2405.18671","repositories_listed":1,"syntology":null},{"url":"/paper/model-reconstruction-using-counterfactual","title":"Model Reconstruction Using Counterfactual Explanations: A Perspective From Polytope Theory","date":"2024-05-08","arxiv_id":"2405.05369","repositories_listed":1,"syntology":{"n":1,"n_ran":0,"n_unverified":1,"n_pointer_only":0}},{"url":"/paper/knowledge-distillation-based-model-extraction","title":"Knowledge Distillation-Based Model Extraction Attack using GAN-based Private Counterfactual Explanations","date":"2024-04-04","arxiv_id":"2404.03348","repositories_listed":1,"syntology":null},{"url":"/paper/not-just-change-the-labels-learn-the-features","title":"Not Just Change the Labels, Learn the Features: Watermarking Deep Neural Networks with Multi-View Data","date":"2024-03-15","arxiv_id":"2403.10663","repositories_listed":1,"syntology":null},{"url":"/paper/warden-multi-directional-backdoor-watermarks","title":"WARDEN: Multi-Directional Backdoor Watermarks for Embedding-as-a-Service Copyright Protection","date":"2024-03-03","arxiv_id":"2403.01472","repositories_listed":1,"syntology":null},{"url":"/paper/mea-defender-a-robust-watermark-against-model","title":"MEA-Defender: A Robust Watermark against Model Extraction Attack","date":"2024-01-26","arxiv_id":"2401.15239","repositories_listed":1,"syntology":null},{"url":"/paper/same-sample-reconstruction-against-model","title":"SAME: Sample Reconstruction against Model Extraction Attacks","date":"2023-12-17","arxiv_id":"2312.10578","repositories_listed":1,"syntology":null},{"url":"/paper/watermarking-vision-language-pre-trained","title":"Watermarking Vision-Language Pre-trained Models for Multi-modal Embedding as a Service","date":"2023-11-10","arxiv_id":"2311.05863","repositories_listed":1,"syntology":null},{"url":"/paper/army-of-thieves-enhancing-black-box-model","title":"Army of Thieves: Enhancing Black-Box Model Extraction via Ensemble based sample selection","date":"2023-11-08","arxiv_id":"2311.04588","repositories_listed":1,"syntology":null},{"url":"/paper/defense-against-model-extraction-attacks-on","title":"Defense Against Model Extraction Attacks on Recommender Systems","date":"2023-10-25","arxiv_id":"2310.16335","repositories_listed":1,"syntology":null},{"url":"/paper/meaeq-mount-model-extraction-attacks-with","title":"MeaeQ: Mount Model Extraction Attacks with Efficient Queries","date":"2023-10-21","arxiv_id":"2310.14047","repositories_listed":1,"syntology":{"n":7,"n_ran":5,"n_unverified":2,"n_pointer_only":0}}],"syntology_records":6,"syntology_note":"a paper without a record is not a recorded non-run: it may lack an arXiv id or simply be absent from the graph layer"},"description_links":{"kept":0,"unwrapped_to_text":0,"bare_urls_linked":0,"relative_images_dropped":0,"rule":"internal links are kept only when the target slug exists in the catalog"},"syntology":{"read_at":"2026-09-24T18:15:14+00:00","claim":"Per-sample execution status on synthesized fixtures ('ran N of M samples'); not a correctness claim and not a ranking signal.","status_vocabulary":{"ran_honours":"ran, honoured the contract we drafted","ran_violates":"ran, violated the contract we drafted","ran_draft_wrong":"ran; our contract draft was wrong, not the code","ran_fixture":"ran; our fixture could not drive it","ran":"ran on a synthesized input","unverified":"unverified (harvested, no recorded run)"}},"not_shown":{"libraries":"the archive has no per-task library table","trend_sparklines":"the Trend column of the benchmarks table was a rendered image; it is not in the archive","social_and_latest_sorts":"stars and social signals are not in the archive"}}