Black-Box Dissector: Towards Erasing-Based Hard-Label Model Stealing Attack
"Previous studies have verified that the functionality of black-box models can be stolen with full probability outputs. However, under the more practical hard-label setting, we observe that existing methods suffer from catastrophic performance degradation. We argue this is due to the lack of rich in…