{"about":{"non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","site":"https://codewithpapers.app","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page","syntology":{"site":"https://syntology.ai","developers":"https://syntology.ai/developers","mcp":{"server":"https://syntology.ai/mcp","transport":"streamable-http","server_card":"https://syntology.ai/.well-known/mcp/server-card.json","auth":{"type":"trial token, no account","trial_token":"https://syntology.ai/api/oauth/trial/token","method":"POST","docs":"https://syntology.ai/developers"}},"have":"https://syntology.ai/api/graph/have?x=<method, arXiv id or title> (free, answers coverage only)","paper_base":"https://syntology.ai/paper/","atlas_base":"https://app.syntology.ai/?focus="},"machine_readable":[{"url":"https://codewithpapers.app/llms.txt","what":"the machine catalog: every machine-readable file, counted"},{"url":"https://codewithpapers.app/index/manifest.json","what":"paper-to-code index by arXiv id, with Syntology's counts"},{"url":"https://codewithpapers.app/search/manifest.json","what":"site search index (titles, authors) and its files"},{"url":"https://codewithpapers.app/download","what":"bulk files: Syntology's layer, described there"},{"url":"https://codewithpapers.app/build_manifest.json","what":"the build record: inputs, counts, exclusions, probes"}]},"url":"/task/model-extraction/papers/2","list_of":"/task/model-extraction","task":"Model extraction","archive":{"snapshot":"2025-07-28"},"key_notes":{"n_ran_checked":"legacy name, kept unchanged so existing readers do not break: it counts the samples that ran with no instrument failure (honoured, violated, and ran with no contract checked); it does not mean a contract was checked, and the pages print it as 'K with no instrument failure', not 'K checked'","n_constructed":"a sub-count of the samples that ran, never subtracted from them and never a failure: an executed sample whose run returned an instance of its own class (fixture_out_type equals the entry name): the run built an object and did not compute a result (Syntology's RAN record, counts.constructed)"},"syntology_read_at":"2026-09-28T10:30:06+00:00","order":"archive","order_definition":"repositories listed in the archive (most first), then date (newest first), then slug","page":2,"pages_in_order":2,"rows_per_page":100,"rows":[101,176],"of":176,"counts":{"archive_papers_tagged":176,"with_a_code_link":57,"where_syntology_ran_a_sample":12,"not_listed_spam_title":0,"listed":176,"listed_where_code_ran":12,"where_syntology_ran_a_sample_split":{"with_a_run_with_no_instrument_failure":10,"every_run_a_failure_of_syntologys_instrument":2,"listed_with_a_run_with_no_instrument_failure":10,"listed_every_run_a_failure_of_syntologys_instrument":2,"filter":{"states":["a run with no instrument failure","any run, instrument failures included"],"default":"a run with no instrument failure","note":"on the 'only where code ran' pages the default hides, in the browser, the rows where every run was a failure of Syntology's instrument; the second state shows them again. Rows are hidden, never re-ordered; these twins list every row"}},"definition":"distinct papers the archive tags; 'where Syntology ran a sample' counts papers with at least one harvested sample that ran, which is not a correctness claim"},"first_page":"/task/model-extraction","prev":"/task/model-extraction","next":null,"papers":[{"url":null,"slug":"mercury-an-automated-remote-side-channel","title":"Mercury: An Automated Remote Side-channel Attack to Nvidia Deep Learning Accelerator","date":"2023-08-02","arxiv_id":"2308.01193","repositories_listed":0,"syntology":null},{"url":null,"slug":"automated-data-driven-model-extraction-and","title":"Automated Data-Driven Model Extraction and Validation of Inverter Dynamics with Grid Support Function","date":"2023-07-28","arxiv_id":"2307.15766","repositories_listed":0,"syntology":null},{"url":null,"slug":"pareto-secure-machine-learning-psml","title":"Pareto-Secure Machine Learning (PSML): Fingerprinting and Securing Inference Serving Systems","date":"2023-07-03","arxiv_id":"2307.01292","repositories_listed":0,"syntology":null},{"url":null,"slug":"fdinet-protecting-against-dnn-model","title":"FDINet: Protecting against DNN Model Extraction via Feature Distortion Index","date":"2023-06-20","arxiv_id":"2306.11338","repositories_listed":0,"syntology":null},{"url":null,"slug":"ownership-protection-of-generative","title":"Ownership Protection of Generative Adversarial Networks","date":"2023-06-08","arxiv_id":"2306.05233","repositories_listed":0,"syntology":null},{"url":null,"slug":"naturalfinger-generating-natural-fingerprint","title":"NaturalFinger: Generating Natural Fingerprint with Generative Adversarial Networks","date":"2023-05-29","arxiv_id":"2305.17868","repositories_listed":0,"syntology":null},{"url":null,"slug":"model-extraction-attacks-against","title":"Model Extraction Attacks Against Reinforcement Learning Based Controllers","date":"2023-04-25","arxiv_id":"2304.13090","repositories_listed":0,"syntology":null},{"url":null,"slug":"grove-ownership-verification-of-graph-neural","title":"GrOVe: Ownership Verification of Graph Neural Networks using Embeddings","date":"2023-04-17","arxiv_id":"2304.08566","repositories_listed":0,"syntology":null},{"url":null,"slug":"ezclone-improving-dnn-model-extraction-attack","title":"EZClone: Improving DNN Model Extraction Attack via Shape Distillation from GPU Execution Profiles","date":"2023-04-06","arxiv_id":"2304.03388","repositories_listed":0,"syntology":null},{"url":null,"slug":"a-desynchronization-based-countermeasure","title":"A Desynchronization-Based Countermeasure Against Side-Channel Analysis of Neural Networks","date":"2023-03-25","arxiv_id":"2303.18132","repositories_listed":0,"syntology":null},{"url":null,"slug":"model-extraction-attacks-on-split-federated","title":"Model Extraction Attacks on Split Federated Learning","date":"2023-03-13","arxiv_id":"2303.08581","repositories_listed":0,"syntology":null},{"url":null,"slug":"an-anatomy-based-v1-model-extraction-of-low","title":"An anatomy-based V1 model: Extraction of Low-level Features, Reduction of distortion and a V1-inspired SOM","date":"2023-02-18","arxiv_id":"2302.09074","repositories_listed":0,"syntology":null},{"url":null,"slug":"a-survey-on-event-based-news-narrative","title":"A Survey on Event-based News Narrative Extraction","date":"2023-02-16","arxiv_id":"2302.08351","repositories_listed":0,"syntology":null},{"url":null,"slug":"autolycus-exploiting-explainable-ai-xai-for","title":"AUTOLYCUS: Exploiting Explainable AI (XAI) for Model Extraction Attacks against Interpretable Models","date":"2023-02-04","arxiv_id":"2302.02162","repositories_listed":0,"syntology":null},{"url":null,"slug":"model-extraction-attack-against-self","title":"Model Extraction Attack against Self-supervised Speech Models","date":"2022-11-29","arxiv_id":"2211.16044","repositories_listed":0,"syntology":null},{"url":null,"slug":"seeds-don-t-lie-an-adaptive-watermarking","title":"Seeds Don't Lie: An Adaptive Watermarking Framework for Computer Vision Models","date":"2022-11-24","arxiv_id":"2211.13644","repositories_listed":0,"syntology":null},{"url":null,"slug":"a-practical-introduction-to-side-channel","title":"A Practical Introduction to Side-Channel Extraction of Deep Neural Network Parameters","date":"2022-11-10","arxiv_id":"2211.05590","repositories_listed":0,"syntology":null},{"url":null,"slug":"seek-model-extraction-attack-against-hybrid","title":"SEEK: model extraction attack against hybrid secure inference protocols","date":"2022-09-14","arxiv_id":"2209.06373","repositories_listed":0,"syntology":null},{"url":null,"slug":"dynamarks-defending-against-deep-learning","title":"DynaMarks: Defending Against Deep Learning Model Extraction Using Dynamic Watermarking","date":"2022-07-27","arxiv_id":"2207.13321","repositories_listed":0,"syntology":null},{"url":null,"slug":"revealing-secrets-from-pre-trained-models","title":"Revealing Secrets From Pre-trained Models","date":"2022-07-19","arxiv_id":"2207.09539","repositories_listed":0,"syntology":null},{"url":null,"slug":"eve-environmental-adaptive-neural-network","title":"EVE: Environmental Adaptive Neural Network Models for Low-power Energy Harvesting System","date":"2022-07-14","arxiv_id":"2207.09258","repositories_listed":0,"syntology":null},{"url":null,"slug":"on-the-amplification-of-security-and-privacy","title":"On the amplification of security and privacy risks by post-hoc explanations in machine learning models","date":"2022-06-28","arxiv_id":"2206.14004","repositories_listed":0,"syntology":null},{"url":null,"slug":"a-framework-for-understanding-model","title":"A Framework for Understanding Model Extraction Attack and Defense","date":"2022-06-23","arxiv_id":"2206.11480","repositories_listed":0,"syntology":null},{"url":null,"slug":"dualcf-efficient-model-extraction-attack-from","title":"DualCF: Efficient Model Extraction Attack from Counterfactual Explanations","date":"2022-05-13","arxiv_id":"2205.06504","repositories_listed":0,"syntology":null},{"url":null,"slug":"split-he-fast-secure-inference-combining","title":"Split HE: Fast Secure Inference Combining Split Learning and Homomorphic Encryption","date":"2022-02-27","arxiv_id":"2202.13351","repositories_listed":0,"syntology":null},{"url":null,"slug":"fingerprinting-deep-neural-networks-globally","title":"Fingerprinting Deep Neural Networks Globally via Universal Adversarial Perturbations","date":"2022-02-17","arxiv_id":"2202.08602","repositories_listed":0,"syntology":null},{"url":null,"slug":"increasing-the-cost-of-model-extraction-with-1","title":"Increasing the Cost of Model Extraction with Calibrated Proof of Work","date":"2022-01-23","arxiv_id":"2201.09243","repositories_listed":0,"syntology":null},{"url":null,"slug":"efficiently-learning-one-hidden-layer-relu","title":"Efficiently Learning One Hidden Layer ReLU Networks From Queries","date":"2021-12-01","arxiv_id":null,"repositories_listed":0,"syntology":null},{"url":null,"slug":"deepsteal-advanced-model-extractions","title":"DeepSteal: Advanced Model Extractions Leveraging Efficient Weight Stealing in Memories","date":"2021-11-08","arxiv_id":"2111.04625","repositories_listed":0,"syntology":null},{"url":null,"slug":"efficiently-learning-any-one-hidden-layer","title":"Efficiently Learning Any One Hidden Layer ReLU Network From Queries","date":"2021-11-08","arxiv_id":"2111.04727","repositories_listed":0,"syntology":null},{"url":null,"slug":"watermarking-graph-neural-networks-based-on","title":"Watermarking Graph Neural Networks based on Backdoor Attacks","date":"2021-10-21","arxiv_id":"2110.11024","repositories_listed":0,"syntology":null},{"url":null,"slug":"first-to-possess-his-statistics-data-free","title":"First to Possess His Statistics: Data-Free Model Extraction Attack on Tabular Data","date":"2021-09-30","arxiv_id":"2109.14857","repositories_listed":0,"syntology":null},{"url":null,"slug":"a-novel-watermarking-framework-for-ownership","title":"A Novel Watermarking Framework for Ownership Verification of DNN Architectures","date":"2021-09-29","arxiv_id":null,"repositories_listed":0,"syntology":null},{"url":null,"slug":"hoda-protecting-dnns-against-model-extraction","title":"HODA: Protecting DNNs Against Model Extraction Attacks via Hardness of Samples","date":"2021-09-29","arxiv_id":null,"repositories_listed":0,"syntology":null},{"url":null,"slug":"naspy-automated-extraction-of-automated","title":"NASPY: Automated Extraction of Automated Machine Learning Models","date":"2021-09-29","arxiv_id":null,"repositories_listed":0,"syntology":null},{"url":null,"slug":"was-my-model-stolen-feature-sharing-for","title":"Was my Model Stolen? Feature Sharing for Robust and Transferable Watermarks","date":"2021-09-29","arxiv_id":null,"repositories_listed":0,"syntology":null},{"url":null,"slug":"emerging-ai-security-threats-for-autonomous","title":"Emerging AI Security Threats for Autonomous Cars -- Case Studies","date":"2021-09-10","arxiv_id":"2109.04865","repositories_listed":0,"syntology":null},{"url":null,"slug":"beyond-model-extraction-imitation-attack-for","title":"Student Surpasses Teacher: Imitation Attack for Black-Box NLP APIs","date":"2021-08-29","arxiv_id":"2108.13873","repositories_listed":0,"syntology":null},{"url":null,"slug":"power-based-attacks-on-spatial-dnn","title":"Power-Based Attacks on Spatial DNN Accelerators","date":"2021-08-28","arxiv_id":"2108.12579","repositories_listed":0,"syntology":null},{"url":null,"slug":"megex-data-free-model-extraction-attack","title":"MEGEX: Data-Free Model Extraction Attack against Gradient-Based Explainable AI","date":"2021-07-19","arxiv_id":"2107.08909","repositories_listed":0,"syntology":null},{"url":null,"slug":"hardness-of-samples-is-all-you-need","title":"HODA: Hardness-Oriented Detection of Model Extraction Attacks","date":"2021-06-21","arxiv_id":"2106.11424","repositories_listed":0,"syntology":null},{"url":null,"slug":"model-extraction-and-adversarial-attacks-on","title":"Model Extraction and Adversarial Attacks on Neural Networks using Switching Power Information","date":"2021-06-15","arxiv_id":"2106.08299","repositories_listed":0,"syntology":null},{"url":null,"slug":"killing-two-birds-with-one-stone-stealing","title":"Killing One Bird with Two Stones: Model Extraction and Attribute Inference Attacks against BERT-based APIs","date":"2021-05-23","arxiv_id":"2105.10909","repositories_listed":0,"syntology":null},{"url":null,"slug":"an-exact-poly-time-membership-queries","title":"An Exact Poly-Time Membership-Queries Algorithm for Extraction a three-Layer ReLU Network","date":"2021-05-20","arxiv_id":"2105.09673","repositories_listed":0,"syntology":null},{"url":null,"slug":"a-review-of-confidentiality-threats-against","title":"A Review of Confidentiality Threats Against Embedded Neural Network Models","date":"2021-05-04","arxiv_id":"2105.01401","repositories_listed":0,"syntology":null},{"url":null,"slug":"good-artists-copy-great-artists-steal-model","title":"Good Artists Copy, Great Artists Steal: Model Extraction Attacks Against Image Translation Models","date":"2021-04-26","arxiv_id":"2104.12623","repositories_listed":0,"syntology":null},{"url":null,"slug":"thief-beware-of-what-get-you-there-towards","title":"Thief, Beware of What Get You There: Towards Understanding Model Extraction Attack","date":"2021-04-13","arxiv_id":"2104.05921","repositories_listed":0,"syntology":null},{"url":null,"slug":"using-python-for-model-inference-in-deep","title":"Using Python for Model Inference in Deep Learning","date":"2021-04-01","arxiv_id":"2104.00254","repositories_listed":0,"syntology":null},{"url":null,"slug":"bodame-bilevel-optimization-for-defense","title":"BODAME: Bilevel Optimization for Defense Against Model Extraction","date":"2021-03-11","arxiv_id":"2103.06797","repositories_listed":0,"syntology":null},{"url":null,"slug":"model-extraction-and-defenses-on-generative","title":"Model Extraction and Defenses on Generative Adversarial Networks","date":"2021-01-06","arxiv_id":"2101.02069","repositories_listed":0,"syntology":null},{"url":null,"slug":"exploring-vulnerabilities-of-bert-based-apis","title":"EXPLORING VULNERABILITIES OF BERT-BASED APIS","date":"2021-01-01","arxiv_id":null,"repositories_listed":0,"syntology":null},{"url":null,"slug":"grey-box-extraction-of-natural-language","title":"Grey-box Extraction of Natural Language Models","date":"2021-01-01","arxiv_id":null,"repositories_listed":0,"syntology":null},{"url":null,"slug":"sparsity-driven-digital-terrain-model","title":"Sparsity-driven Digital Terrain Model Extraction","date":"2020-12-07","arxiv_id":"2012.08639","repositories_listed":0,"syntology":null},{"url":null,"slug":"a-knowledge-representation-approach-to","title":"A Knowledge Representation Approach to Automated Mathematical Modelling","date":"2020-11-12","arxiv_id":"2011.06300","repositories_listed":0,"syntology":null},{"url":null,"slug":"monitoring-based-differential-privacy","title":"Monitoring-based Differential Privacy Mechanism Against Query-Flooding Parameter Duplication Attack","date":"2020-11-01","arxiv_id":"2011.00418","repositories_listed":0,"syntology":null},{"url":null,"slug":"leveraging-extracted-model-adversaries-for","title":"Leveraging Extracted Model Adversaries for Improved Black Box Attacks","date":"2020-10-30","arxiv_id":"2010.16336","repositories_listed":0,"syntology":null},{"url":null,"slug":"stealing-deep-reinforcement-learning-models","title":"Stealing Deep Reinforcement Learning Models for Fun and Profit","date":"2020-06-09","arxiv_id":"2006.05032","repositories_listed":0,"syntology":null},{"url":null,"slug":"mitigating-query-flooding-parameter","title":"Mitigating Query-Flooding Parameter Duplication Attack on Regression Models with High-Dimensional Gaussian Mechanism","date":"2020-02-06","arxiv_id":"2002.02061","repositories_listed":0,"syntology":null},{"url":null,"slug":"model-extraction-attacks-against-recurrent","title":"Model Extraction Attacks against Recurrent Neural Networks","date":"2020-02-01","arxiv_id":"2002.00123","repositories_listed":0,"syntology":null},{"url":null,"slug":"adversarial-model-extraction-on-graph-neural","title":"Adversarial Model Extraction on Graph Neural Networks","date":"2019-12-16","arxiv_id":"1912.07721","repositories_listed":0,"syntology":null},{"url":null,"slug":"towards-privacy-and-security-of-deep-learning","title":"Towards Security Threats of Deep Learning Systems: A Survey","date":"2019-11-28","arxiv_id":"1911.12562","repositories_listed":0,"syntology":null},{"url":null,"slug":"quantifying-hyper-parameter-leakage-in","title":"Quantifying (Hyper) Parameter Leakage in Machine Learning","date":"2019-10-31","arxiv_id":"1910.14409","repositories_listed":0,"syntology":null},{"url":null,"slug":"maskednet-a-pathway-for-secure-inference","title":"MaskedNet: The First Hardware Inference Engine Aiming Power Side-Channel Protection","date":"2019-10-29","arxiv_id":"1910.13063","repositories_listed":0,"syntology":null},{"url":null,"slug":"extraction-of-complex-dnn-models-real-threat","title":"Extraction of Complex DNN Models: Real Threat or Boogeyman?","date":"2019-10-11","arxiv_id":"1910.05429","repositories_listed":0,"syntology":null},{"url":null,"slug":"high-fidelity-extraction-of-neural-network","title":"High Accuracy and High Fidelity Extraction of Neural Networks","date":"2019-09-03","arxiv_id":"1909.01838","repositories_listed":0,"syntology":null},{"url":null,"slug":"automating-agential-reasoning-proof-calculi","title":"Automating Agential Reasoning: Proof-Calculi and Syntactic Decidability for STIT Logics","date":"2019-08-29","arxiv_id":"1908.11360","repositories_listed":0,"syntology":null},{"url":null,"slug":"adversarial-exploitation-of-policy-imitation","title":"Adversarial Exploitation of Policy Imitation","date":"2019-06-03","arxiv_id":"1906.01121","repositories_listed":0,"syntology":null},{"url":null,"slug":"a-framework-for-the-extraction-of-deep-neural","title":"A framework for the extraction of Deep Neural Networks by leveraging public data","date":"2019-05-22","arxiv_id":"1905.09165","repositories_listed":0,"syntology":null},{"url":null,"slug":"exploring-connections-between-active-learning","title":"Exploring Connections Between Active Learning and Model Extraction","date":"2018-11-05","arxiv_id":"1811.02054","repositories_listed":0,"syntology":null},{"url":null,"slug":"dont-encrypt-the-data-just-approximate-the","title":"Don't encrypt the data; just approximate the model \\ Towards Secure Transaction and Fair Pricing of Training Data","date":"2018-01-01","arxiv_id":null,"repositories_listed":0,"syntology":null},{"url":null,"slug":"model-extraction-warning-in-mlaas-paradigm","title":"Model Extraction Warning in MLaaS Paradigm","date":"2017-11-20","arxiv_id":"1711.07221","repositories_listed":0,"syntology":null},{"url":null,"slug":"three-dimensional-planar-model-estimation","title":"Three-dimensional planar model estimation using multi-constraint knowledge based on k-means and RANSAC","date":"2017-08-03","arxiv_id":"1708.01143","repositories_listed":0,"syntology":null},{"url":null,"slug":"interpretability-via-model-extraction","title":"Interpretability via Model Extraction","date":"2017-06-29","arxiv_id":"1706.09773","repositories_listed":0,"syntology":null},{"url":null,"slug":"interpreting-blackbox-models-via-model","title":"Interpreting Blackbox Models via Model Extraction","date":"2017-05-23","arxiv_id":"1705.08504","repositories_listed":0,"syntology":null},{"url":null,"slug":"fraternal-twins-unifying-attacks-on-machine","title":"Fraternal Twins: Unifying Attacks on Machine Learning and Digital Watermarking","date":"2017-03-16","arxiv_id":"1703.05561","repositories_listed":0,"syntology":null},{"url":null,"slug":"bound-your-models-how-to-make-owl-an-asp","title":"Bound Your Models! How to Make OWL an ASP Modeling Language","date":"2015-11-03","arxiv_id":"1511.00924","repositories_listed":0,"syntology":null}],"record_sha256":"b5890eb2821a001e010c020f2726053bcbeb979bdf092bb55f5fdf3bf4670ee0","record_changed_at":"2026-09-28","record_changed_at_basis":"first_hashed"}