Code for ML Doctor
-
Updated
Aug 14, 2024 - Python
Code for ML Doctor
Code for "CloudLeak: Large-Scale Deep Learning Models Stealing Through Adversarial Examples" (NDSS 2020)
Official Source Code of "Exploring Effective Data for Surrogate Training Towards Black-box Attack" and "STDatav2: Accessing Efficient Black-Box Stealing for Adversarial Attacks".
A curated bilingual list of cryptanalytic neural-network model extraction papers, code, taxonomies, and open problems.
Implementations on Security and Privacy in ML; Evasion Attack, Model Stealing, Model Poisoning, Membership Inference Attacks, ...
Official implementation of "Stealthy Imitation: Reward-guided Environment-free Policy Stealing" (ICML 2024)
Developer blind to the probes, auditor blind to the weights: a sealed-room protocol to audit AI models you can't steal. TEE + attestation + weight commitment + transparency log + extraction detector + DP noise + dual-signed transcript.
Official implementation of "Stealix: Model Stealing via Prompt Evolution" (ICML 2025)
An implementation to apply ActiveThief to steal cloud models.
Official implementation of "Medical Multimodal Model Stealing Attacks via Adversarial Domain Alignment" (AAAI-2025 oral)
An advanced, interactive educational platform focused on AI system vulnerabilities, attack vectors, and offensive security methodologies. [Prompt Injection, Model Evasion, Data Poisoning, Agent Hijacking]
Detects model-extraction campaigns by query SHAPE not volume: separates boundary-probing distillation from a heavy legitimate user, so the power user is identified and not throttled.
Repository for my Bachelor Thesis at Karlsruhe Institute of Technology.
Low-overhead execution-finality reference implementation for AI/GPU environments: bounded non-bearer authority, atomic extraction-state control, Finality Sink enforcement, RATS attestation mapping, and performance-aware paths for multi-GPU, streaming, batching, confidential computing, DPU/SmartNIC, firmware, and silicon.
Testing adversarial ML attacks (data poisoning, targeted misclassification, and model extraction) and discussing defensive tradeoffs that exist for real deployments.
Adaptive defense against unauthorized LLM distillation using risk-gated, post-generation reasoning transformations without modifying model weights.
To associate your repository with the model-stealing topic, visit your repo's landing page and select "manage topics."