{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T01:43:32Z","timestamp":1787017412792,"version":"build-2736575974"},"publisher-location":"New York, NY, USA","reference-count":57,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,11,11]],"date-time":"2019-11-11T00:00:00Z","timestamp":1573430400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,11,11]]},"DOI":"10.1145\/3338498.3358646","type":"proceedings-article","created":{"date-parts":[[2019,11,11]],"date-time":"2019-11-11T13:15:00Z","timestamp":1573478100000},"page":"198-210","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":51,"title":["Efficiently Stealing your Machine Learning Models"],"prefix":"10.1145","author":[{"given":"Robert Nikolai","family":"Reith","sequence":"first","affiliation":[{"name":"TU Darmstadt, Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thomas","family":"Schneider","sequence":"additional","affiliation":[{"name":"TU Darmstadt, Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Oleksandr","family":"Tkachenko","sequence":"additional","affiliation":[{"name":"TU Darmstadt, Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2019,11,11]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"crossref","unstructured":"M. Barni P. Failla V. Kolesnikov R. Lazzeretti A.-R. Sadeghi and T. Schneider. 2009. Secure Evaluation of Private Linear Branching Programs with Medical Applications. In ESORICS . Full version: https:\/\/ia.cr\/2009\/195.  M. Barni P. Failla V. Kolesnikov R. Lazzeretti A.-R. Sadeghi and T. Schneider. 2009. Secure Evaluation of Private Linear Branching Programs with Medical Applications. In ESORICS . Full version: https:\/\/ia.cr\/2009\/195.","DOI":"10.1007\/978-3-642-04444-1_26"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"crossref","unstructured":"M. Barreno B. Nelson R. Sears A. D. Joseph and J. D. Tygar. 2006. Can Machine Learning be Secure. In CCS .  M. Barreno B. Nelson R. Sears A. D. Joseph and J. D. Tygar. 2006. Can Machine Learning be Secure. In CCS .","DOI":"10.1145\/1128817.1128824"},{"key":"e_1_3_2_1_3_1","unstructured":"B. Biggio B. Nelson and P. Laskov. 2012. Poisoning Attacks against Support Vector Machines. Machine Learning (2012).  B. Biggio B. Nelson and P. Laskov. 2012. Poisoning Attacks against Support Vector Machines. Machine Learning (2012)."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"crossref","unstructured":"G. Camps-Valls J. D. Mart\u00edn-Guerrero J. L. Rojo-Alvarez and E. Soria-Olivas. 2004. Fuzzy Sigmoid Kernel for Support Vector Classifiers. Neurocomputing (2004).  G. Camps-Valls J. D. Mart\u00edn-Guerrero J. L. Rojo-Alvarez and E. Soria-Olivas. 2004. Fuzzy Sigmoid Kernel for Support Vector Classifiers. Neurocomputing (2004).","DOI":"10.1016\/j.neucom.2004.07.004"},{"key":"e_1_3_2_1_5_1","volume":"201","author":"Chang Y.-W.","journal-title":"J. Lin."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"crossref","unstructured":"D. Cohn L. Atlas and R. Ladner. 1994. Improving Generalization with Active Learning. Machine Learning (1994).  D. Cohn L. Atlas and R. Ladner. 1994. Improving Generalization with Active Learning. Machine Learning (1994).","DOI":"10.1007\/BF00993277"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","unstructured":"C. Cortes and V. Vapnik. 1995. Support-Vector Networks. Machine Learning (1995).  C. Cortes and V. Vapnik. 1995. Support-Vector Networks. Machine Learning (1995).","DOI":"10.1007\/BF00994018"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"crossref","unstructured":"D. Demmler T. Schneider and M. Zohner. 2015. ABY-A Framework for Efficient Mixed-Protocol Secure Two-Party Computation. In NDSS .  D. Demmler T. Schneider and M. Zohner. 2015. ABY-A Framework for Efficient Mixed-Protocol Secure Two-Party Computation. In NDSS .","DOI":"10.14722\/ndss.2015.23113"},{"key":"e_1_3_2_1_9_1","unstructured":"A. Dmitrenko. 2018. DNN Model Extraction Attacks using Prediction Interfaces. (2018).  A. Dmitrenko. 2018. DNN Model Extraction Attacks using Prediction Interfaces. (2018)."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"crossref","unstructured":"F. Douak F. Melgani E. Pasolli and N. Benoudjit. 2012. SVR Active Learning for Product Quality Control. In Information Science Signal Processing and their Applications (ISSPA) .  F. Douak F. Melgani E. Pasolli and N. Benoudjit. 2012. SVR Active Learning for Product Quality Control. In Information Science Signal Processing and their Applications (ISSPA) .","DOI":"10.1109\/ISSPA.2012.6310457"},{"key":"e_1_3_2_1_11_1","unstructured":"H. Drucker C. J. C. Burges L. Kaufman A. J. Smola and V. Vapnik. 1997. Support Vector Regression Machines. In Advances in Neural Information Processing Systems .  H. Drucker C. J. C. Burges L. Kaufman A. J. Smola and V. Vapnik. 1997. Support Vector Regression Machines. In Advances in Neural Information Processing Systems ."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"crossref","unstructured":"M. Fredrikson S. Jha and T. Ristenpart. 2015. Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures. In CCS .  M. Fredrikson S. Jha and T. Ristenpart. 2015. Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures. In CCS .","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_1_13_1","unstructured":"J. Friedman T. Hastie R. Tibshirani et almbox. 2000. Additive Logistic Regression: A Statistical View of Boosting. The Annals of Statistics (2000).  J. Friedman T. Hastie R. Tibshirani et almbox. 2000. Additive Logistic Regression: A Statistical View of Boosting. The Annals of Statistics (2000)."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"O. Goldreich S. Micali and A. Wigderson. 1987. How to Play any Mental Game. In STOC .  O. Goldreich S. Micali and A. Wigderson. 1987. How to Play any Mental Game. In STOC .","DOI":"10.1145\/28395.28420"},{"key":"e_1_3_2_1_15_1","unstructured":"I. Goodfellow Y. Bengio A. Courville and Y. Bengio. 2016. Deep Learning .MIT press Cambridge.  I. Goodfellow Y. Bengio A. Courville and Y. Bengio. 2016. Deep Learning .MIT press Cambridge."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"crossref","unstructured":"P. Hallgren C. Orlandi and A. Sabelfeld. 2017. PrivatePool: Privacy-Preserving Ridesharing. In Computer Security Foundations .  P. Hallgren C. Orlandi and A. Sabelfeld. 2017. PrivatePool: Privacy-Preserving Ridesharing. In Computer Security Foundations .","DOI":"10.1109\/CSF.2017.24"},{"key":"e_1_3_2_1_17_1","volume-title":"LOGAN: Membership Inference Attacks against Generative Models. PETs","author":"Hayes J.","year":"2019"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866358"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"crossref","unstructured":"D. W. Hosmer  Jr S. Lemeshow and R. X. Sturdivant. 2013. Applied Logistic Regression .John Wiley & Sons.  D. W. Hosmer Jr S. Lemeshow and R. X. Sturdivant. 2013. Applied Logistic Regression .John Wiley & Sons.","DOI":"10.1002\/9781118548387"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"crossref","unstructured":"K. J\"arvinen \u00c1. Kiss T. Schneider O. Tkachenko and Z. Yang. 2018. Faster Privacy-Preserving Location Proximity Schemes. In CANS .  K. J\"arvinen \u00c1. Kiss T. Schneider O. Tkachenko and Z. Yang. 2018. Faster Privacy-Preserving Location Proximity Schemes. In CANS .","DOI":"10.1007\/978-3-030-00434-7_1"},{"key":"e_1_3_2_1_21_1","volume-title":"PILOT: Practical Privacy-Preserving Indoor Localization using OuTsourcing. In EuroS&P .","author":"K.","year":"2019"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"crossref","unstructured":"M. Kesarwani B. Mukhoty V. Arya and S. Mehta. 2018. Model Extraction Warning in MLaaS Paradigm. Computer Security Applications (2018).  M. Kesarwani B. Mukhoty V. Arya and S. Mehta. 2018. Model Extraction Warning in MLaaS Paradigm. Computer Security Applications (2018).","DOI":"10.1145\/3274694.3274740"},{"key":"e_1_3_2_1_23_1","volume-title":"Evading Classifiers in Discrete Domains with Provable Optimality Guarantees. In NeurIPS Workshop on Security in Machine Learning .","author":"Kulynych B."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","unstructured":"S. Laur H. Lipmaa and T. Mielik\u00e4inen. 2006. Cryptographically Private Support Vector Machines. In Knowledge Discovery and Data Mining .  S. Laur H. Lipmaa and T. Mielik\u00e4inen. 2006. Cryptographically Private Support Vector Machines. In Knowledge Discovery and Data Mining .","DOI":"10.1145\/1150402.1150477"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"crossref","unstructured":"J. Liu and E. Zio. 2016. An Adaptive Online Learning Approach for Support Vector Regression: Online-SVR-FID. Mechanical Systems and Signal Processing (2016).  J. Liu and E. Zio. 2016. An Adaptive Online Learning Approach for Support Vector Regression: Online-SVR-FID. Mechanical Systems and Signal Processing (2016).","DOI":"10.1016\/j.ymssp.2016.02.056"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"crossref","unstructured":"D. Lowd and C. Meek. 2005. Adversarial Learning. In Knowledge Discovery in Data Mining .  D. Lowd and C. Meek. 2005. Adversarial Learning. In Knowledge Discovery in Data Mining .","DOI":"10.1145\/1081870.1081950"},{"key":"e_1_3_2_1_27_1","unstructured":"L. M. Manevitz and M. Yousef. 2001. One-Class SVMs for Document Classification. Machine Learning Research (2001).  L. M. Manevitz and M. Yousef. 2001. One-Class SVMs for Document Classification. Machine Learning Research (2001)."},{"key":"e_1_3_2_1_28_1","unstructured":"S. Mika G. Ratsch J. Weston B. Scholkopf and K.-R. Mullers. 1999. Fisher Discriminant Analysis with Kernels. In Neural Networks for Signal Processing .  S. Mika G. Ratsch J. Weston B. Scholkopf and K.-R. Mullers. 1999. Fisher Discriminant Analysis with Kernels. In Neural Networks for Signal Processing ."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"crossref","unstructured":"J. H Min and Y.-C. Lee. 2005. Bankruptcy Prediction using Support Vector Machine with Optimal Choice of Kernel Function Parameters. Expert Systems with Applications (2005).  J. H Min and Y.-C. Lee. 2005. Bankruptcy Prediction using Support Vector Machine with Optimal Choice of Kernel Function Parameters. Expert Systems with Applications (2005).","DOI":"10.1016\/j.eswa.2004.12.008"},{"key":"e_1_3_2_1_30_1","unstructured":"K. Pace. 1999 a. Boston House Prices Dataset . http:\/\/lib.stat.cmu.edu\/datasets\/boston_corrected.txt  K. Pace. 1999 a. Boston House Prices Dataset . http:\/\/lib.stat.cmu.edu\/datasets\/boston_corrected.txt"},{"key":"e_1_3_2_1_31_1","unstructured":"K. Pace. 1999 b. Califonria Housing Dataset . http:\/\/lib.stat.cmu.edu\/datasets\/houses.zip  K. Pace. 1999 b. Califonria Housing Dataset . http:\/\/lib.stat.cmu.edu\/datasets\/houses.zip"},{"key":"e_1_3_2_1_32_1","unstructured":"P. Paillier. 1999. Public-Key Cryptosystems Based on Composite Degree Residuosity Classes. In EUROCRYPT .  P. Paillier. 1999. Public-Key Cryptosystems Based on Composite Degree Residuosity Classes. In EUROCRYPT ."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"N. Papernot P. McDaniel I. Goodfellow S. Jha Z. B. Celik and A. Swami. 2017. Practical Black-Box Attacks Against Machine Learning. In ASIACCS .  N. Papernot P. McDaniel I. Goodfellow S. Jha Z. B. Celik and A. Swami. 2017. Practical Black-Box Attacks Against Machine Learning. In ASIACCS .","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"crossref","unstructured":"K. Polat and S. G\u00fcne. 2007. Breast Cancer Diagnosis using Least Square Support Vector Machine. Digital Signal Processing (2007).  K. Polat and S. G\u00fcne. 2007. Breast Cancer Diagnosis using Least Square Support Vector Machine. Digital Signal Processing (2007).","DOI":"10.1016\/j.dsp.2006.10.008"},{"key":"e_1_3_2_1_35_1","unstructured":"J. R. Quinlan. 198"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"crossref","unstructured":"Y. Rahulamathavan R. C.-W. Phan S. Veluru K. Cumanan and M. Rajarajan. 2014. Privacy-Preserving Multi-Class Support Vector Machine for Outsourcing the Data Classification in Cloud. Dependable and Secure Computing (2014).  Y. Rahulamathavan R. C.-W. Phan S. Veluru K. Cumanan and M. Rajarajan. 2014. Privacy-Preserving Multi-Class Support Vector Machine for Outsourcing the Data Classification in Cloud. Dependable and Secure Computing (2014).","DOI":"10.1109\/TDSC.2013.51"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1644893.1644895"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"crossref","unstructured":"D. W. Ruck S. K. Rogers M. Kabrisky M. E. Oxley and B. W. Suter. 1990. The Multilayer Perceptron as an Approximation to a Bayes Optimal Discriminant Function. Neural Networks (1990).  D. W. Ruck S. K. Rogers M. Kabrisky M. E. Oxley and B. W. Suter. 1990. The Multilayer Perceptron as an Approximation to a Bayes Optimal Discriminant Function. Neural Networks (1990).","DOI":"10.1109\/72.80266"},{"key":"e_1_3_2_1_39_1","volume":"201","author":"Ruiz A. R. J.","journal-title":"J. Torres-Sospedra."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"crossref","unstructured":"A.-R. Sadeghi and T. Schneider. 2008. Generalized Universal Circuits for Secure Evaluation of Private Functions with Application to Data Classification. In Information Security and Cryptology .  A.-R. Sadeghi and T. Schneider. 2008. Generalized Universal Circuits for Secure Evaluation of Private Functions with Application to Data Classification. In Information Security and Cryptology .","DOI":"10.1007\/978-3-642-00730-9_21"},{"key":"e_1_3_2_1_41_1","volume-title":"Ml-leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models. In NDSS .","author":"Salem A.","year":"2019"},{"key":"e_1_3_2_1_42_1","unstructured":"J. Schmidhuber. 201"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"crossref","unstructured":"Y. Shi Y. Sagduyu and A. Grushin. 2017. How to Steal a Machine Learning Classifier with Deep Learning. In Technologies for Homeland Security .  Y. Shi Y. Sagduyu and A. Grushin. 2017. How to Steal a Machine Learning Classifier with Deep Learning. In Technologies for Homeland Security .","DOI":"10.1109\/THS.2017.7943475"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"crossref","unstructured":"R. Shokri M. Stronati C. Song and V. Shmatikov. 2017. Membership Inference Attacks against Machine Learning Models. In S&P .  R. Shokri M. Stronati C. Song and V. Shmatikov. 2017. Membership Inference Attacks against Machine Learning Models. In S&P .","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"crossref","unstructured":"A. J. Smola and B. Sch\u00f6lkopf. 2004. A Tutorial on Support Vector Regression. Statistics and Computing (2004).  A. J. Smola and B. Sch\u00f6lkopf. 2004. A Tutorial on Support Vector Regression. Statistics and Computing (2004).","DOI":"10.1002\/0470011815.b2a14038"},{"key":"e_1_3_2_1_46_1","volume":"199","author":"Suykens J. A. K.","journal-title":"J. Vandewalle."},{"key":"e_1_3_2_1_47_1","first-page":"i","volume":"201","author":"Torres-Sospedra J.","journal-title":"J. Huerta."},{"key":"e_1_3_2_1_48_1","unstructured":"F. Tram\u00e8r F. Zhang A. Juels M. K. Reiter and T. Ristenpart. 2016. Stealing Machine Learning Models via Prediction APIs. In USENIX Security .  F. Tram\u00e8r F. Zhang A. Juels M. K. Reiter and T. Ristenpart. 2016. Stealing Machine Learning Models via Prediction APIs. In USENIX Security ."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"crossref","unstructured":"L. G. Valiant. 1984. A Theory of the Learnable. Communications of the ACM (1984).  L. G. Valiant. 1984. A Theory of the Learnable. Communications of the ACM (1984).","DOI":"10.1145\/800057.808710"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"crossref","unstructured":"V. Vapnik E. Levin and Y. L. Cun. 1994. Measuring the VC-dimension of a Learning Machine. Neural Computation (1994).  V. Vapnik E. Levin and Y. L. Cun. 1994. Measuring the VC-dimension of a Learning Machine. Neural Computation (1994).","DOI":"10.1162\/neco.1994.6.5.851"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"crossref","unstructured":"B. Wang and N. Z. Gong. 2018. Stealing Hyperparameters in Machine Learning. arXiv preprint arXiv:1802.05351 (2018).  B. Wang and N. Z. Gong. 2018. Stealing Hyperparameters in Machine Learning. arXiv preprint arXiv:1802.05351 (2018).","DOI":"10.1109\/SP.2018.00038"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"crossref","unstructured":"Q. Wu and D.-X. Zhou. 2005. SVM Soft Margin Classifiers: Linear Programming versus Quadratic Programming. Neural Computation (2005).  Q. Wu and D.-X. Zhou. 2005. SVM Soft Margin Classifiers: Linear Programming versus Quadratic Programming. Neural Computation (2005).","DOI":"10.1162\/0899766053491896"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"crossref","unstructured":"Z. Yang and K. J\"arvinen. 2018. The Death and Rebirth of Privacy-Preserving WiFi Fingerprint Localization with Paillier Encryption. In INFOCOM .  Z. Yang and K. J\"arvinen. 2018. The Death and Rebirth of Privacy-Preserving WiFi Fingerprint Localization with Paillier Encryption. In INFOCOM .","DOI":"10.1109\/INFOCOM.2018.8486221"},{"key":"e_1_3_2_1_54_1","unstructured":"A. C.-C. Yao. 1986. How to Generate and Exchange Secrets. In FOCS .  A. C.-C. Yao. 1986. How to Generate and Exchange Secrets. In FOCS ."},{"key":"e_1_3_2_1_55_1","volume":"200","author":"Yu H.","journal-title":"J. Vaidya."},{"key":"e_1_3_2_1_56_1","volume-title":"Privacy-Preserving Wi-Fi Fingerprinting Indoor Localization. In International Workshop on Security .","author":"Zhang T."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"crossref","unstructured":"F. \u00d6. \u00c7atak. 2015. Secure Multi-Party Computation Based Privacy Preserving Extreme Learning Machine Algorithm over Vertically Distributed Data. In Neural Information Processing .  F. \u00d6. \u00c7atak. 2015. Secure Multi-Party Computation Based Privacy Preserving Extreme Learning Machine Algorithm over Vertically Distributed Data. In Neural Information Processing .","DOI":"10.1007\/978-3-319-26535-3_39"}],"event":{"name":"CCS '19: 2019 ACM SIGSAC Conference on Computer and Communications Security","location":"London United Kingdom","acronym":"CCS '19","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 18th ACM Workshop on Privacy in the Electronic Society"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3338498.3358646","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3338498.3358646","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:12:48Z","timestamp":1750187568000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3338498.3358646"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,11,11]]},"references-count":57,"alternative-id":["10.1145\/3338498.3358646","10.1145\/3338498"],"URL":"https:\/\/doi.org\/10.1145\/3338498.3358646","relation":{},"subject":[],"published":{"date-parts":[[2019,11,11]]},"assertion":[{"value":"2019-11-11","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}