@article{Yan2026, 
author = {Anli Yan and Lang Li and Kanghua Mo and Peigen Ye and Shaowei Wang and Li Hu and Hongyang Yan and Jin Li},
title = {From Model Parameters to Data Quality: Implicit Factor Evaluation of Model Extraction Attacks},
year = {2026},
journal = {Tsinghua Science and Technology},
volume = {31},
number = {4},
pages = {2204-2220},
keywords = {model extraction attacks (MEAs), model parameters, data quality, impact factors},
url = {https://www.sciopen.com/article/10.26599/TST.2024.9010243},
doi = {10.26599/TST.2024.9010243},
abstract = {Model extraction attacks (MEAs) pose a significant threat to deep learning (DL) models, where adversaries aim to steal the decision behavior of targeted DL models. While several works have shown the ability of a surrogate model to mimic the target DL model, the underlying factors that make a DL model vulnerable to MEAs are unclear. Analyzing these underlying factors is the key to enhancing the security of DL systems. This involves exploring MEAs in diverse scenarios to understand the relationship between their success and the features of DL systems. In this paper, we evaluate the underlying factors influencing MEAs from two crucial perspectives: the model’s intrinsic parameters and the quality of the data used. For the model’s intrinsic parameters, we focus on how the batch size, learning rate, and optimizer influence the effectiveness of MEAs. Regarding data quality, we conduct an in-depth analysis of how data annotation and selection affect MEAs’ success. Our study includes analyzing variations in batch size, five learning rates, eight optimizers, the impact of varying proportions of dirty data, and the effects of subtle changes in data richness. The results of our research reveal a diverse range of susceptibilities to MEAs.}
}