arXiv AI By Jian-Ping Mei, Weibin Zhang, Jie Chen, Xuyun Zhang, Tiantian Zhu

D-ADD: An Effective Plug-In for Defending Against Model Stealing

Read the original on arXiv AI →

The paper introduces D-ADD, a plug‑in defense for image classification models that protects against model‑stealing attacks. It uses a non‑parametric detector called Account‑aware Distribution Discrepancy (ADD) to identify malicious queries by modeling each class as a multivariate normal distribution and computing weighted distribution discrepancies. With an enhanced version ADD$^+$ that handles domain shifts and combined with random‑based prediction poisoning, D-ADD offers strong protection while minimally affecting benign users in both soft‑ and hard‑label settings.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.

arXiv Machine Learning
Jun 8

ADAGE: Active Defenses Against GNN Extraction

arXiv:2503. 00065v4 Announce Type: replace-cross Abstract: Graph Neural Networks (GNNs) achieve high performance in various real-world applications, such as drug discovery, traffic states prediction, and recommendation systems.

By Jing Xu, Franziska Boenisch, Adam Dziedzic