arXiv

AI Model Extraction Attacks: Bypassing Single-Client Assumptions in Defenses

Title: AI Model Extraction Attacks: Bypassing Single-Client Assumptions in Defenses

Abstract

Safeguarding Artificial Intelligence (AI) models integrated into critical infrastructure and military Command and Control (C2) systems is vital for preserving information superiority. Model Extraction Attacks (MEAs) represent a severe risk, allowing adversaries to clone proprietary models, expose sensitive data, and facilitate offline adversarial operations. However, existing countermeasures largely depend on the Single Client Assumption (SCA)—the implicit premise that malicious actors operate as isolated entities. This study systematically proves that the SCA is fundamentally flawed when facing coordinated threat actors, such as Advanced Persistent Threats (APTs). To address this, we present CerberusAI, a modular, open-source framework designed for reproducible research on model theft, which we utilize to simulate distributed attack vectors. Our empirical analysis reveals that established defenses, including Protecting Against Deep Neural Network Model Stealing Attacks (PRADA), are vulnerable to simple round-robin query distribution techniques, leading to a substantial drop in detection efficacy. Additionally, we show that adaptive traffic mixing can neutralize even global aggregation methods. These findings underscore the urgent need for a paradigm shift toward stateful, identity-independent defense architectures in the context of model extraction threats.

This paper was originally presented at the International Conference on Military Communication and Information Systems (ICMCIS), organized by the Information Systems Technology (IST) Scientific and Technical Committee, IST-224-RSY. The conference took place in Bath, United Kingdom, on May 12-13, 2026, and the work was honored with the best paper award.


Source: arXiv Generated at: 2026-06-03 00:00:00 UTC

Related Articles

TikTok Billionaire Tops Ambani as Asia’s Second-Richest
Bloomberg

TikTok Billionaire Tops Ambani as Asia’s Second-Richest

TikTok founder surpasses Mukesh Ambani to become Asia’s second-richest person, marking a significant shift in the region...

Publishers in UK can opt out of Google AI search results
BBC News

Publishers in UK can opt out of Google AI search results

UK publishers can now opt out of Google’s AI search summaries, a CMA ruling designed to boost their bargaining power and...

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.
Bloomberg

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.

Kioxia’s market cap nears Toyota’s, signaling a major shift in Japan’s corporate hierarchy. This narrowing gap highlight...

Reuters

Morning Bid: Marvell, a fitting name for the latest AI darling

Reuters highlights Marvell as a top AI stock, noting its name perfectly suits its status as the newest market darling.

Financial Times

Tim Hayward: I built the Jaguar E-Type of computer keyboards

Tim Hayward compares his bespoke keyboard designs to the Jaguar E-Type. He explores high-end customization for personal ...

Financial Times

AI Labs: Zuckerberg’s $100bn gamble

Meta’s $100 billion AI investment aims to secure AI dominance, but questions remain whether sheer spending can outpace c...