<div class="csl-bib-body">
<div class="csl-entry">Oliynyk, D., Mayer, R., & Rauber, A. (2025). Attackers Can Do Better: Over- and Understated Factors of Model Stealing Attacks. In <i>2025 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)</i> (pp. 150–168). IEEE Xplore. https://doi.org/10.1109/SaTML64287.2025.00016</div>
</div>
-
dc.identifier.uri
http://hdl.handle.net/20.500.12708/230329
-
dc.description.abstract
Machine learning (ML) models were shown to be vulnerable to model stealing attacks, which lead to intellectual property infringement. Among other attack methods, substitute model training is an all-encompassing attack applicable to any machine learning model whose behaviour can be approximated from input-output queries. Whereas previous works mainly focused on improving the performance of substitute models by, e.g. developing a new substitute training method, there have been only limited ablation studies that try to understand the impact the strength of an attacker has on the substitute model's performance. As a result, different authors came to diverse, sometimes contradicting, conclusions. In this work, we exhaustively examine the ambivalent influence of different factors resulting from varying the attacker's capabilities and knowledge on a substitute training attack. Our findings suggest that some of the factors that have been considered important in the past are, in fact, not that influential; instead, we discover new correlations between attack conditions and success rate. In particular, we demonstrate that better-performing target models enable higher-fidelity attacks and explain the intuition behind this phenomenon. Further, we propose to shift the focus from the complexity of target models toward the complexity of their learning tasks. Therefore, for the substitute model, rather than aiming for a higher architecture complexity, we suggest focusing on getting data of higher complexity and an appropriate architecture. Finally, we demonstrate that even in the most limited data-free scenario, there is no need to overcompensate weak knowledge with unrealistic capabilities in the form of millions of queries. Our results often exceed or match the performance of previous attacks that assume a stronger attacker, suggesting that these stronger attacks are likely endangering a model owner's intellectual property to a significantly higher degree than shown until now.
en
dc.language.iso
en
-
dc.subject
Ablation Study
en
dc.subject
Adversarial Machine Learning
en
dc.subject
Model Extraction
en
dc.subject
Model Stealing
en
dc.title
Attackers Can Do Better: Over- and Understated Factors of Model Stealing Attacks
en
dc.type
Inproceedings
en
dc.type
Konferenzbeitrag
de
dc.contributor.affiliation
University of Vienna, Austria
-
dc.contributor.affiliation
SBA Research, Austria
-
dc.relation.isbn
979-8-3315-1711-3
-
dc.description.startpage
150
-
dc.description.endpage
168
-
dc.type.category
Full-Paper Contribution
-
tuw.booktitle
2025 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)
-
tuw.peerreviewed
true
-
tuw.relation.publisher
IEEE Xplore
-
tuw.researchTopic.id
I5
-
tuw.researchTopic.id
I4
-
tuw.researchTopic.name
Visual Computing and Human-Centered Technology
-
tuw.researchTopic.name
Information Systems Engineering
-
tuw.researchTopic.value
10
-
tuw.researchTopic.value
90
-
tuw.publication.orgunit
E194-04 - Forschungsbereich Data Science
-
tuw.publication.orgunit
E057-09 - Fachbereich ASC Research Center
-
tuw.publisher.doi
10.1109/SaTML64287.2025.00016
-
dc.description.numberOfPages
19
-
tuw.author.orcid
0000-0003-0424-5999
-
tuw.author.orcid
0000-0002-9272-6225
-
tuw.event.name
2025 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)
en
tuw.event.startdate
09-04-2025
-
tuw.event.enddate
11-04-2025
-
tuw.event.online
On Site
-
tuw.event.type
Event for scientific audience
-
tuw.event.place
Copenhagen
-
tuw.event.country
DK
-
tuw.event.presenter
Oliynyk, Daryna
-
wb.sciencebranch
Informatik
-
wb.sciencebranch
Wirtschaftswissenschaften
-
wb.sciencebranch.oefos
1020
-
wb.sciencebranch.oefos
5020
-
wb.sciencebranch.value
90
-
wb.sciencebranch.value
10
-
item.openairecristype
http://purl.org/coar/resource_type/c_5794
-
item.grantfulltext
none
-
item.openairetype
conference paper
-
item.languageiso639-1
en
-
item.fulltext
no Fulltext
-
item.cerifentitytype
Publications
-
crisitem.author.dept
E194 - Institut für Information Systems Engineering
-
crisitem.author.dept
E194-04 - Forschungsbereich Data Science
-
crisitem.author.orcid
0000-0003-0424-5999
-
crisitem.author.orcid
0000-0002-9272-6225
-
crisitem.author.parentorg
E180 - Fakultät für Informatik
-
crisitem.author.parentorg
E194 - Institut für Information Systems Engineering