AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
PDF (5.8 MB)
Collect
Submit Manuscript AI Chat Paper
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Research Article | Open Access

From Model Parameters to Data Quality: Implicit Factor Evaluation of Model Extraction Attacks

School of Mathematics and Information Science, Guangzhou University, Guangzhou 510006, China, and also with School of Artificial Intelligence, Guangzhou University, Guangzhou 510006, China
School of Artificial Intelligence, Guangzhou University, Guangzhou 510006, China
School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing 100081, China
Show Author Information

Abstract

Model extraction attacks (MEAs) pose a significant threat to deep learning (DL) models, where adversaries aim to steal the decision behavior of targeted DL models. While several works have shown the ability of a surrogate model to mimic the target DL model, the underlying factors that make a DL model vulnerable to MEAs are unclear. Analyzing these underlying factors is the key to enhancing the security of DL systems. This involves exploring MEAs in diverse scenarios to understand the relationship between their success and the features of DL systems. In this paper, we evaluate the underlying factors influencing MEAs from two crucial perspectives: the model’s intrinsic parameters and the quality of the data used. For the model’s intrinsic parameters, we focus on how the batch size, learning rate, and optimizer influence the effectiveness of MEAs. Regarding data quality, we conduct an in-depth analysis of how data annotation and selection affect MEAs’ success. Our study includes analyzing variations in batch size, five learning rates, eight optimizers, the impact of varying proportions of dirty data, and the effects of subtle changes in data richness. The results of our research reveal a diverse range of susceptibilities to MEAs.

References

【1】
【1】
 
 
Tsinghua Science and Technology
Pages 2204-2220

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Yan A, Li L, Mo K, et al. From Model Parameters to Data Quality: Implicit Factor Evaluation of Model Extraction Attacks. Tsinghua Science and Technology, 2026, 31(4): 2204-2220. https://doi.org/10.26599/TST.2024.9010243

1900

Views

43

Downloads

0

Crossref

0

Web of Science

0

Scopus

0

CSCD

Received: 19 July 2024
Revised: 27 September 2024
Accepted: 08 December 2024
Published: 23 December 2025
© The author(s) 2026.

The articles published in this open access journal are distributed under the terms of the Creative Commons Attribution 4.0 International License (http://creativecommons.org/licenses/by/4.0/).