Abstract
Model as a Service (MaaS) is a cloud computing-based service model that enables users to access the functionalities of machine learning (ML) models via the Internet. With the rapid development of large language models (LLMs), this paradigm has significantly facilitated the practical deployment and application of models in real-world scenarios. However, while this service paradigm offers significant convenience, it may render models vulnerable to query-based model extraction attacks (QBMEAs). QBMEAs involve submitting strategically designed input queries to the target model and leveraging its input–output pairs to extract core elements (denoted as exact attacks) or reconstruct a functionality similar to the surrogate model (denoted as approximate attacks). Although significant progress has been made in QBMEAs, existing research lacks a clear definition of attacker capabilities, with insufficient analysis of different attack methods. To deepen understanding of current QBMEAs and provide clear references for defense research, we first construct a novel three-dimensional threat model (attack objectives, attack knowledge, and query types) to define attackers’ capabilities. Second, we propose an exact attack classification system based on extraction objectives, analyzing the applicability and limitations of existing methods. Subsequently, we systematically organize approximate attacks through a four-stage workflow, introducing state-of-the-art methods while analyzing optimization strategies at each stage. Finally, we discuss existing defense methods against QBMEAs, providing a reference for future research on both attacks and defenses. This paper reveals the characteristics of current attacks in terms of effectiveness and efficiency, analyzes the limitations of existing works, and points out future research directions, which facilitates a more profound understanding of QBMEAs for defense method developers.
| Original language | English |
|---|---|
| Article number | 114523 |
| Journal | Pattern Recognition |
| Volume | 180 |
| DOIs | |
| State | Published - Dec 2026 |
| Externally published | Yes |
Keywords
- AI security
- Model extraction attack
- Model privacy
Fingerprint
Dive into the research topics of 'Query-based model extraction attack: A survey'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver