MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models

Published in arXiv preprint, 2025

MISLEADER formulates model protection as a bilevel optimization problem and uses an ensemble of heterogeneous distilled models to balance predictive fidelity with resistance to extraction attacks.

Code

Recommended citation: Xueqi Cheng, Minxing Zheng, Shixiang Zhu, and Yushun Dong. (2025). "MISLEADER: Defending against Model Extraction with Ensembles of Distilled Models." arXiv:2506.02362.
Download Paper