Functional Extraction vs. Parameter Recovery: Matching Evidence
Explore how to differentiate between functional extraction and parameter recovery in machine learning security. Learn to critically assess extraction claims by matching them with appropriate evidence and understanding API access constraints, enabling you to evaluate the validity of confidentiality and privacy attack reports effectively.
In the running example, an attacker queries an API and trains a substitute model. The key reading skill is to pin down what the author claims was extracted and then check whether the evidence actually measures that claim, under the stated access assumptions.
To practice separating the claims, sort each statement by what it asserts was recovered and what success would look like.
Two claim types that get conflated
Functional ...