Stealing Models from the Cloud

Platform as a service is a growing trend in data science where services like fraud analysis and face detection can be provided via APIs. Such services turn the actual model into a black box to the consumer. But can the model be reverse engineered?

[Florian Tramèr](http://floriantramer.com/) shares his work in this episode showing that it can. The paper [Stealing Machine Learning Models via Prediction APIs](https://arxiv.org/abs/1609.02943) is definitely worth your time to read if you enjoy this episode. Related source code can be found in [https://github.com/ftramer/Steal-ML](https://github.com/ftramer/Steal-ML).

Guest

Florian Tramèr: https://www.floriantramerI am an assistant professor of Computer Science at ETH Zürich where I lead the SPY Lab. My research interests lie in Computer Security, Machine Learning and Cryptography. In my current work, I study the worst-case behavior of Large Language Models from an adversarial perspective, to understand and mitigate long-term threats to the safety and privacy of users. To learn more about our lab's work, see here or take a look at our blog. My work has been featured in The Economist, Nature, Science, Communications of the ACM, Wired and the Swiss news (in french). I received my PhD from Stanford University under the supervision of Dan Boneh. After graduating, I spent one year at Google Brain.com

Stealing Models from the Cloud