{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T16:57:20Z","timestamp":1784912240164,"version":"3.55.0"},"publisher-location":"Cham","reference-count":60,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031729850","type":"print"},{"value":"9783031729867","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,11,2]],"date-time":"2024-11-02T00:00:00Z","timestamp":1730505600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,11,2]],"date-time":"2024-11-02T00:00:00Z","timestamp":1730505600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-72986-7_19","type":"book-chapter","created":{"date-parts":[[2024,11,1]],"date-time":"2024-11-01T05:04:45Z","timestamp":1730437485000},"page":"323-340","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Training A Secure Model Against Data-Free Model Extraction"],"prefix":"10.1007","author":[{"given":"Zhenyi","family":"Wang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Li","family":"Shen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Junfeng","family":"Guo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tiehang","family":"Duan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Siyu","family":"Luan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tongliang","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mingchen","family":"Gao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,11,2]]},"reference":[{"key":"19_CR1","unstructured":"Adi, Y., Baum, C., Cisse, M., Pinkas, B., Keshet, J.: Turning your weakness into a strength: watermarking deep neural networks by backdooring. In: 27th USENIX Security Symposium (USENIX Security 2018) (2018)"},{"key":"19_CR2","unstructured":"Chen, T., Kornblith, S., Norouzi, M., Hinton, G.: A simple framework for contrastive learning of visual representations. In: International Conference on Machine Learning (2020)"},{"key":"19_CR3","doi-asserted-by":"crossref","unstructured":"Chen, X., He, K.: Exploring simple Siamese representation learning. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 15750\u201315758 (2021)","DOI":"10.1109\/CVPR46437.2021.01549"},{"key":"19_CR4","doi-asserted-by":"crossref","unstructured":"Deng, J., Dong, W., Socher, R., Li, L.J., Li, K., Fei-Fei, L.: ImageNet: a large-scale hierarchical image database. In: 2009 IEEE Conference on Computer Vision and Pattern Recognition, pp. 248\u2013255. IEEE (2009)","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"19_CR5","unstructured":"Dziedzic, A., Dhawan, N., Kaleem, M.A., Guan, J., Papernot, N.: On the difficulty of defending self-supervised learning against model extraction. In: International Conference on Machine Learning, pp. 5757\u20135776. PMLR (2022)"},{"key":"19_CR6","unstructured":"Dziedzic, A., Kaleem, M.A., Lu, Y.S., Papernot, N.: Increasing the cost of model extraction with calibrated proof of work. In: International Conference on Learning Representations (2022)"},{"key":"19_CR7","doi-asserted-by":"crossref","unstructured":"Fang, G., Song, J., Wang, X., Shen, C., Wang, X., Song, M.: Contrastive model inversion for data-free knowledge distillation. In: International Joint Conferences on Artificial Intelligence (2021)","DOI":"10.24963\/ijcai.2021\/327"},{"key":"19_CR8","unstructured":"Finn, C., Abbeel, P., Levine, S.: Model-agnostic meta-learning for fast adaptation of deep networks. In: International Conference on Machine Learning (2017)"},{"key":"19_CR9","unstructured":"Goodfellow, I.J., et al.: Generative adversarial networks. In: Advances in Neural Information Processing Systems (2014)"},{"key":"19_CR10","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: IEEE Conference on Computer Vision and Pattern Recognition (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"19_CR11","unstructured":"He, Y., Meng, G., Chen, K., Hu, X., He, J.: Towards security threats of deep learning systems: a survey (2020). https:\/\/arxiv.org\/abs\/1911.12562"},{"key":"19_CR12","doi-asserted-by":"crossref","unstructured":"He, Z., Rakin, A.S., Fan, D.: Parametric noise injection: trainable randomness to improve deep neural network robustness against adversarial attack. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 588\u2013597 (2019)","DOI":"10.1109\/CVPR.2019.00068"},{"key":"19_CR13","doi-asserted-by":"crossref","unstructured":"Hendrycks, D., et\u00a0al.: The many faces of robustness: a critical analysis of out-of-distribution generalization. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 8340\u20138349 (2021)","DOI":"10.1109\/ICCV48922.2021.00823"},{"key":"19_CR14","unstructured":"Hong, Z., et al.: Improving non-transferable representation learning by harnessing content and style. In: The Twelfth International Conference on Learning Representations (2024)"},{"key":"19_CR15","unstructured":"Hu, Z., Shen, L., Wang, Z., Wu, B., Yuan, C., Tao, D.: Learning to learn from APIS: black-box data-free meta-learning. In: International Conference on Machine Learning, pp. 13610\u201313627 (2023)"},{"key":"19_CR16","doi-asserted-by":"crossref","unstructured":"Huang, G., Liu, Z., Van Der\u00a0Maaten, L., Weinberger, K.Q.: Densely connected convolutional networks. In: IEEE Conference on Computer Vision and Pattern Recognition (2017)","DOI":"10.1109\/CVPR.2017.243"},{"key":"19_CR17","unstructured":"Jagielski, M., Carlini, N., Berthelot, D., Kurakin, A., Papernot, N.: High accuracy and high fidelity extraction of neural networks. In: USENIX Security 2020 (2020)"},{"key":"19_CR18","unstructured":"Jia, H., Choquette-Choo, C.A., Chandrasekaran, V., Papernot, N.: Entangled watermarks as a defense against model extraction. In: 30th USENIX Security Symposium (2021)"},{"key":"19_CR19","doi-asserted-by":"crossref","unstructured":"Jia, H., et al.: Proof-of-learning: definitions and practice. In: 42nd IEEE Symposium on Security and Privacy (2021)","DOI":"10.1109\/SP40001.2021.00106"},{"key":"19_CR20","doi-asserted-by":"crossref","unstructured":"Juuti, M., Szyller, S., Marchal, S., Asokan, N.: Prada: protecting against DNN model stealing attacks. In: IEEE European Symposium on Security and Privacy (2019). https:\/\/arxiv.org\/abs\/1805.02628","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"19_CR21","doi-asserted-by":"crossref","unstructured":"Kariyappa, S., Prakash, A., Qureshi, M.K.: Maze: data-free model stealing attack using zeroth-order gradient estimation. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition (2021)","DOI":"10.1109\/CVPR46437.2021.01360"},{"key":"19_CR22","unstructured":"Kariyappa, S., Prakash, A., Qureshi, M.K.: Protecting DNNs from theft using an ensemble of diverse models. In: International Conference on Learning Representations (2021)"},{"key":"19_CR23","doi-asserted-by":"crossref","unstructured":"Kariyappa, S., Qureshi, M.K.: Defending against model stealing attacks with adaptive misinformation. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition (2020)","DOI":"10.1109\/CVPR42600.2020.00085"},{"key":"19_CR24","doi-asserted-by":"crossref","unstructured":"Kong, S., Ramanan, D.: OpenGAN: open-set recognition via open data generation. In: IEEE\/CVF International Conference on Computer Vision (2021)","DOI":"10.1109\/ICCV48922.2021.00085"},{"key":"19_CR25","unstructured":"Krizhevsky, A.: Learning multiple layers of features from tiny images (2009)"},{"key":"19_CR26","unstructured":"Lee, T., Edwards, B., Molloy, I., Su, D.: Defending against machine learning model stealing attacks using deceptive perturbations (2018). https:\/\/arxiv.org\/abs\/1806.00054"},{"key":"19_CR27","unstructured":"Li, C.L., Chang, W.C., Cheng, Y., Yang, Y., P\u00f3czos, B.: MMD GAN: towards deeper understanding of moment matching network. In: Advances in Neural Information Processing Systems (2017)"},{"key":"19_CR28","unstructured":"Li, G., Xu, G., Guo, S., Qiu, H., Li, J., Zhang, T.: Extracting robust models with uncertain examples. In: International Conference on Learning Representations (2023)"},{"key":"19_CR29","doi-asserted-by":"crossref","unstructured":"Liu, S., Chen, P.Y., Kailkhura, B., Zhang, G., Hero, A.O., III., Varshney, P.K.: A primer on zeroth-order optimization in signal processing and machine learning: principals, recent advances, and applications. IEEE Signal Process. Mag. (2020)","DOI":"10.1109\/MSP.2020.3003837"},{"key":"19_CR30","doi-asserted-by":"crossref","unstructured":"Liu, X., Cheng, M., Zhang, H., Hsieh, C.J.: Towards robust neural networks via random self-ensemble. In: European Conference on Computer Vision (2018)","DOI":"10.1007\/978-3-030-01234-2_23"},{"key":"19_CR31","series-title":"AISC","doi-asserted-by":"publisher","first-page":"241","DOI":"10.1007\/978-3-319-60366-7_23","volume-title":"AHFE 2017","author":"G L\u00f3pez","year":"2018","unstructured":"L\u00f3pez, G., Quesada, L., Guerrero, L.A.: Alexa vs. Siri vs. Cortana vs. Google assistant: a comparison of speech-based natural user interfaces. In: Nunes, I. (ed.) AHFE 2017. AISC, vol. 592, pp. 241\u2013250. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-60366-7_23"},{"key":"19_CR32","doi-asserted-by":"crossref","unstructured":"Lowd, D., Meek, C.: Adversarial learning. In: ACM SIGKDD International Conference on Knowledge Discovery in Data Mining. Association for Computing Machinery (2005)","DOI":"10.1145\/1081870.1081950"},{"key":"19_CR33","unstructured":"Maini, P., Yaghini, M., Papernot, N.: Dataset inference: ownership resolution in machine learning. In: International Conference on Learning Representations (2021)"},{"key":"19_CR34","doi-asserted-by":"crossref","unstructured":"Marek, P., Naik, V.I., Auvray, V., Goyal, A.: OodGAN: generative adversarial network for out-of-domain data generation. In: Annual Conference of the North American Chapter of the Association for Computational Linguistics (2021). https:\/\/arxiv.org\/abs\/2104.02484","DOI":"10.18653\/v1\/2021.naacl-industry.30"},{"key":"19_CR35","unstructured":"Mazeika, M., Li, B., Forsyth, D.: How to steer your adversary: targeted and efficient model stealing defenses with gradient redirection. In: International Conference on Machine Learning (2022)"},{"key":"19_CR36","doi-asserted-by":"crossref","unstructured":"Oh, S.J., Augustin, M., Schiele, B., Fritz, M.: Towards reverse-engineering black-box neural networks. In: International Conference on Learning Representations (2018)","DOI":"10.1007\/978-3-030-28954-6_7"},{"key":"19_CR37","unstructured":"van den Oord, A., Li, Y., Vinyals, O.: Representation learning with contrastive predictive coding. arXiv preprint arXiv:1807.03748 (2018)"},{"key":"19_CR38","doi-asserted-by":"crossref","unstructured":"Orekondy, T., Schiele, B., Fritz, M.: Knockoff nets: stealing functionality of black-box models. In: IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (2019)","DOI":"10.1109\/CVPR.2019.00509"},{"key":"19_CR39","unstructured":"Orekondy, T., Schiele, B., Fritz, M.: Prediction poisoning: towards defenses against DNN model stealing attacks. In: International Conference on Learning Representations (2020)"},{"key":"19_CR40","unstructured":"Pal, S., Gupta, Y., Kanade, A., Shevade, S.: Stateful detection of model extraction attacks (2021)"},{"key":"19_CR41","doi-asserted-by":"crossref","unstructured":"Pal, S., Gupta, Y., Shukla, A., Kanade, A., Shevade, S., Ganapathy, V.: ActiveThief: model extraction using active learning and unannotated public data. In: AAAI Conference on Artificial Intelligence, vol.\u00a034 (2020)","DOI":"10.1609\/aaai.v34i01.5432"},{"key":"19_CR42","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z.B., Swami, A.: Practical black-box attacks against machine learning. In: ACM Asia Conference on Computer and Communications Security (2017)","DOI":"10.1145\/3052973.3053009"},{"key":"19_CR43","unstructured":"Radford, A., Metz, L., Chintala, S.: Unsupervised representation learning with deep convolutional generative adversarial networks. In: International Conference on Learning Representations (2016)"},{"key":"19_CR44","doi-asserted-by":"crossref","unstructured":"Sandler, M., Howard, A., Zhu, M., Zhmoginov, A., Chen, L.C.: MobileNetv2: inverted residuals and linear bottlenecks. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition (2018)","DOI":"10.1109\/CVPR.2018.00474"},{"key":"19_CR45","doi-asserted-by":"crossref","unstructured":"Sanyal, S., Addepalli, S., Babu, R.V.: Towards data-free model stealing in a hard label setting. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition (2022)","DOI":"10.1109\/CVPR52688.2022.01485"},{"key":"19_CR46","unstructured":"Steiner, A.P., Kolesnikov, A., Zhai, X., Wightman, R., Uszkoreit, J., Beyer, L.: How to train your ViT? Data, augmentation, and regularization in vision transformers. Trans. Mach. Learn. Res. (2022)"},{"key":"19_CR47","doi-asserted-by":"crossref","unstructured":"Szyller, S., Atli, B.G., Marchal, S., Asokan, N.: Dawn: dynamic adversarial watermarking of neural networks. In: ACM Multimedia (2021)","DOI":"10.1145\/3474085.3475591"},{"key":"19_CR48","unstructured":"Tieleman, T., Hinton, G.: Lecture 6.5-: divide the gradient by a running average of its recent magnitude (2012)"},{"key":"19_CR49","unstructured":"Tram\u00e8r, F., Zhang, F., Juels, A., Reiter, M.K., Ristenpart, T.: Stealing machine learning models via prediction APIs. In: USENIX Security (2016)"},{"key":"19_CR50","doi-asserted-by":"crossref","unstructured":"Truong, J.B., Maini, P., Walls, R.J., Papernot, N.: Data-free model extraction. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition (2021)","DOI":"10.1109\/CVPR46437.2021.00474"},{"key":"19_CR51","unstructured":"Vinyals, O., Blundell, C., Lillicrap, T., Wierstra, D., et\u00a0al.: Matching networks for one shot learning. In: Advances in Neural Information Processing Systems (2016)"},{"key":"19_CR52","doi-asserted-by":"crossref","unstructured":"Vitter, J.S.: Random sampling with a reservoir. ACM Trans. Math. Softw. (1985)","DOI":"10.1145\/3147.3165"},{"key":"19_CR53","doi-asserted-by":"crossref","unstructured":"Wang, B., Gong, N.Z.: Stealing hyperparameters in machine learning. In: In the 39th IEEE Symposium on Security and Privacy (2018)","DOI":"10.1109\/SP.2018.00038"},{"key":"19_CR54","doi-asserted-by":"crossref","unstructured":"Wang, X., et al.: Protecting neural networks with hierarchical random switching: towards better robustness-accuracy trade-off for stochastic defenses. In: International Joint Conference on Artificial Intelligence (2019)","DOI":"10.24963\/ijcai.2019\/833"},{"key":"19_CR55","unstructured":"Wang, Z., et al.: Defending against data-free model extraction by distributionally robust defensive training. In: Thirty-Seventh Conference on Neural Information Processing Systems (2023)"},{"key":"19_CR56","unstructured":"Wang, Z., Wu, Y., Huang, H.: Defense against model extraction attack by Bayesian active watermarking. In: Forty-First International Conference on Machine Learning (2024)"},{"key":"19_CR57","unstructured":"Wang, Z.: Zero-shot knowledge distillation from a decision-based black-box model. In: International Conference on Machine Learning (2021)"},{"key":"19_CR58","unstructured":"Wu, B., et al.: Visual transformers: token-based image representation and processing for computer vision. arXiv preprint arXiv:2006.03677 (2020)"},{"key":"19_CR59","unstructured":"Yang, E., et al.: Continual learning from a stream of APIs. arXiv preprint arXiv:2309.00023 (2023)"},{"key":"19_CR60","doi-asserted-by":"crossref","unstructured":"Zagoruyko, S., Komodakis, N.: Wide residual networks. In: British Machine Vision Conference (2016)","DOI":"10.5244\/C.30.87"}],"container-title":["Lecture Notes in Computer Science","Computer Vision \u2013 ECCV 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-72986-7_19","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,1]],"date-time":"2024-11-01T05:12:03Z","timestamp":1730437923000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-72986-7_19"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,2]]},"ISBN":["9783031729850","9783031729867"],"references-count":60,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-72986-7_19","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,11,2]]},"assertion":[{"value":"2 November 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECCV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Conference on Computer Vision","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Milan","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eccv2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eccv2024.ecva.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}