D-ADD: An Effective Plug-In for Defending Against Model Stealing
Read the original on arXiv AI →The paper introduces D-ADD, a plug‑in defense for image classification models that protects against model‑stealing attacks. It uses a non‑parametric detector called Account‑aware Distribution Discrepancy (ADD) to identify malicious queries by modeling each class as a multivariate normal distribution and computing weighted distribution discrepancies. With an enhanced version ADD$^+$ that handles domain shifts and combined with random‑based prediction poisoning, D-ADD offers strong protection while minimally affecting benign users in both soft‑ and hard‑label settings.
Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.