Stealing Machine Learning Models via Prediction APIs
Explore this paper's citation graph
Summary
Simple, efficient attacks are shown that extract target ML models with near-perfect fidelity for popular model classes including logistic regression, neural networks, and decision trees against the online services of BigML and Amazon Machine Learning.
- Type
- preprint
- Published
- 2016-08-10
- Cited by
- 2,197
- References
- 67
- Access
- Open access
- OpenAlex
- https://openalex.org/W2461943168
- Semantic Scholar
- https://api.semanticscholar.org/CorpusID:2984526
Keywords
Computer science, Machine learning, Artificial intelligence, Lasso (programming language), Support vector machine
References
- Good Word Attacks on Statistical Spam Filters
- Privacy in Pharmacogenetics: An End-to-End Case Study of Personalized Warfarin Dosing
- Selection of Relevant Features and Examples in Machine Learning
- Distilling the Knowledge in a Neural Network
- On the hardness of evading combinations of linear classifiers
- Exact Learning Boolean Function via the Monotone Theory
- Extracting Refined Rules from Knowledge-Based Neural Networks
- A Practical Differentially Private Random Decision Tree Classifier
- ANTIDOTE: understanding and defending against poisoning of anomaly detectors
- A theory of the learnable
- Membership privacy: a unifying framework for privacy definitions
- Occam's razor
- Practical Evasion of a Learning-Based Classifier: A Case Study
- Kernel Logistic Regression and the Import Vector Machine
- Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures
- Privacy-preserving deep learning
- Learning decision trees using the Fourier spectrum
- A technique for upper bounding the spectral norm with applications to learning
- Survey and critique of techniques for extracting rules from trained artificial neural networks
- Learnability with Respect to Fixed Distributions
Cited by
- Practical Black-Box Attacks against Deep Learning Systems using Adversarial Examples
- Uncovering Influence Cookbooks: Reverse Engineering the Topological Impact in Peer Ranking Services
- Membership Inference Attacks Against Machine Learning Models
- Pretzel: Email encryption and provider-supplied functions are compatible
- SoK: Security and Privacy in Machine Learning
- Deep Models Under the GAN: Information Leakage from Collaborative Deep Learning
- Practical Black-Box Attacks against Machine Learning
- Data Driven Exploratory Attacks on Black Box Classifiers in Adversarial Domains
- Adversarial Transformation Networks: Learning to Generate Adversarial Examples
- Cleaning the Null Space: A Privacy Mechanism for Predictors
- Fraternal Twins: Unifying Attacks on Machine Learning and Digital Watermarking
- Inference and Regeneration of Programs that Store and Retrieve Data
- Deep learning for healthcare: review, opportunities and challenges
- Attacking Machine Learning models as part of a cyber kill chain
- The Space of Transferable Adversarial Examples
- DeepXplore: Automated Whitebox Testing of Deep Learning Systems
- LOGAN: Evaluating Privacy Leakage of Generative Models Using Generative Adversarial Networks
- Adversarial learning: A critical review and active learning study
- Opportunities and obstacles for deep learning in biology and medicine
- Evading Classifier in the Dark: Guiding Unpredictable Morphing Using Binary-Output Blackboxes
Related papers
- Practical Black-Box Attacks against Machine Learning
- Membership Inference Attacks Against Machine Learning Models
- Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures
- Deep Residual Learning for Image Recognition
- The Limitations of Deep Learning in Adversarial Settings
- Privacy in Pharmacogenetics: An End-to-End Case Study of Personalized Warfarin Dosing
- Learning Multiple Layers of Features from Tiny Images
- Privacy-preserving deep learning