Search⌘ K
AI Features

Extracting a Model Without Ever Seeing It

Explore how attackers can extract machine learning models by querying prediction APIs without accessing weights or training data. Learn to define system boundaries, distinguish model extraction from evasion, and understand how query access and output detail impact extraction risks to protect confidentiality in ML services.

A competitor repeatedly queries a company's paid image-classification API and uses the resulting input/output pairs to train their own local model that reproduces its behavior closely enough to replace it commercially, without ever accessing the original weights, training data, or infrastructure.

A prediction API looks simple from the outside. A client sends an image, the server returns a prediction, and the call ends.

That simplicity is the point of the boundary. The server can keep the training data, learned weights, and preprocessing details private while still selling useful predictions. ...