2024
Poisoning-Free Defense Against Black-Box Model Extraction
ICASSP 2024accepted
Recent research has shown that an adversary can use a surrogate model to steal the functionality of a target deep learning model even under the black-box condition and without data curation, while the existing defense mainly relies on API poisoning to disturb the surrogate training. Unfortunately, d…