MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models
Published in arXiv preprint, 2025
MISLEADER formulates model protection as a bilevel optimization problem and uses an ensemble of heterogeneous distilled models to balance predictive fidelity with resistance to extraction attacks.
Recommended citation: Xueqi Cheng, Minxing Zheng, Shixiang Zhu, and Yushun Dong. (2025). "MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models." arXiv:2506.02362.
Download Paper
