<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>Brenner Cruvinel - segurança</title>
    <subtitle>AI researcher and product designer building at the edge of computer science and mental health.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://brennercruvinel.blog/tags/seguranca/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://brennercruvinel.blog"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2026-04-08T00:00:00+00:00</updated>
    <id>https://brennercruvinel.blog/tags/seguranca/atom.xml</id>
    <entry xml:lang="en">
        <title>Model Extraction Attacks contra Redes Neurais Black-Box (2020-2026)</title>
        <published>2026-04-08T00:00:00+00:00</published>
        <updated>2026-04-08T00:00:00+00:00</updated>
        
        <author>
          <name>
            Brenner Cruvinel
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://brennercruvinel.blog/blog/model-extraction-attacks/"/>
        <id>https://brennercruvinel.blog/blog/model-extraction-attacks/</id>
        
        <content type="html" xml:base="https://brennercruvinel.blog/blog/model-extraction-attacks/">&lt;h3 id=&quot;model-extraction-attacks-on-black-box-neural-networks-2020-2026&quot;&gt;Model Extraction Attacks on Black-Box Neural Networks (2020-2026)&lt;&#x2F;h3&gt;
&lt;p&gt;monorep fresh co, ataques de extracao contra modelos black-box, surveys e literatura agregada.&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;B3: Backdoor Attacks against Black-box Machine Learning Models | ACM Transactions on Privacy and Security - https:&#x2F;&#x2F;dl.acm.org&#x2F;doi&#x2F;10.1145&#x2F;3605212&lt;&#x2F;li&gt;
&lt;li&gt;[PDF] CloudLeak: Large-Scale Deep Learning Models Stealing Through Adversarial Examples | Semantic Scholar - https:&#x2F;&#x2F;www.semanticscholar.org&#x2F;paper&#x2F;CloudLeak:-Large-Scale-Deep-Learning-Models-Through-Yu-Yang&#x2F;4d548fd21aad60e3052455e22b7a57cc1f06e3c3&lt;&#x2F;li&gt;
&lt;li&gt;Stealing Neural Networks With Model Extraction Attacks, Dr. Nicholas Carlini | Commonwealth Cyber Initiative (CCI) | Virginia Tech - https:&#x2F;&#x2F;cyberinitiative.org&#x2F;events-programs&#x2F;2020&#x2F;stealing-neural-networks-with-model-extraction-attacks-dr-nich.html&lt;&#x2F;li&gt;
&lt;li&gt;I Know What You Trained Last Summer: A Survey on Stealing Machine Learning Models and Defences | ACM Computing Surveys - https:&#x2F;&#x2F;dl.acm.org&#x2F;doi&#x2F;10.1145&#x2F;3595292&lt;&#x2F;li&gt;
&lt;li&gt;GitHub - kzhao5&#x2F;Model-Extraction-Stealing-Attacks-Machine-Learning-Literature - https:&#x2F;&#x2F;github.com&#x2F;kzhao5&#x2F;Model-Extraction-Stealing-Attacks-Machine-Learning-Literature&lt;&#x2F;li&gt;
&lt;li&gt;First Model-Stealing Attack Reveals Secrets of Black-Box Production Language Models | Synced - https:&#x2F;&#x2F;syncedreview.com&#x2F;2024&#x2F;03&#x2F;27&#x2F;first-model-stealing-attack-reveals-secrets-of-black-box-production-language-models&#x2F;&lt;&#x2F;li&gt;
&lt;li&gt;A realistic model extraction attack against graph neural networks - ScienceDirect - https:&#x2F;&#x2F;www.sciencedirect.com&#x2F;science&#x2F;article&#x2F;abs&#x2F;pii&#x2F;S0950705124007780&lt;&#x2F;li&gt;
&lt;li&gt;[1602.02697] Practical Black-Box Attacks against Machine Learning - https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;1602.02697&lt;&#x2F;li&gt;
&lt;li&gt;Practical Black-Box Attacks against Machine Learning | Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security - https:&#x2F;&#x2F;dl.acm.org&#x2F;doi&#x2F;10.1145&#x2F;3052973.3053009&lt;&#x2F;li&gt;
&lt;li&gt;Black-box targeted adversarial attacks for deep neural networks - ScienceDirect - https:&#x2F;&#x2F;www.sciencedirect.com&#x2F;science&#x2F;article&#x2F;abs&#x2F;pii&#x2F;S0925231225016893&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;h3 id=&quot;stealing-machine-learning-models-via-prediction-apis-arxiv&quot;&gt;Stealing Machine Learning Models via Prediction APIs (arxiv)&lt;&#x2F;h3&gt;
&lt;p&gt;o paper seminal do Tramer e suas variantes, mais codigo de extracao via prediction API.&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;[1609.02943] Stealing Machine Learning Models via Prediction APIs - https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;1609.02943&lt;&#x2F;li&gt;
&lt;li&gt;Stealing Machine Learning Models via Prediction APIs - https:&#x2F;&#x2F;www.usenix.org&#x2F;system&#x2F;files&#x2F;conference&#x2F;usenixsecurity16&#x2F;sec16_paper_tramer.pdf&lt;&#x2F;li&gt;
&lt;li&gt;Stealing machine learning models via prediction APIs | Proceedings of the 25th USENIX Conference on Security Symposium - https:&#x2F;&#x2F;dl.acm.org&#x2F;doi&#x2F;10.5555&#x2F;3241094.3241142&lt;&#x2F;li&gt;
&lt;li&gt;[1609.02943] Stealing Machine Learning Models via Prediction APIs (HTML version) - https:&#x2F;&#x2F;ar5iv.labs.arxiv.org&#x2F;html&#x2F;1609.02943&lt;&#x2F;li&gt;
&lt;li&gt;[1609.02943v2] Stealing Machine Learning Models via Prediction APIs (Updated version) - https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;1609.02943v2&lt;&#x2F;li&gt;
&lt;li&gt;Efficient and Effective Model Extraction - https:&#x2F;&#x2F;arxiv.org&#x2F;html&#x2F;2409.14122v1&lt;&#x2F;li&gt;
&lt;li&gt;Scholars@Duke publication: Stealing Machine Learning Models via Prediction APIs - https:&#x2F;&#x2F;scholars.duke.edu&#x2F;publication&#x2F;1493919&lt;&#x2F;li&gt;
&lt;li&gt;GitHub - ftramer&#x2F;Steal-ML: Model extraction attacks on Machine-Learning-as-a-Service platforms - https:&#x2F;&#x2F;github.com&#x2F;ftramer&#x2F;Steal-ML&lt;&#x2F;li&gt;
&lt;li&gt;[PDF] Stealing Machine Learning Models via Prediction APIs | Semantic Scholar - https:&#x2F;&#x2F;www.semanticscholar.org&#x2F;paper&#x2F;Stealing-Machine-Learning-Models-via-Prediction-Tram%C3%A8r-Zhang&#x2F;d15b21bdd117877c2d0e865b17d6a336737aea99&lt;&#x2F;li&gt;
&lt;li&gt;Stealing Machine Learning Models via Prediction APIs | USENIX - https:&#x2F;&#x2F;www.usenix.org&#x2F;conference&#x2F;usenixsecurity16&#x2F;technical-sessions&#x2F;presentation&#x2F;tramer&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;h3 id=&quot;model-inversion-attacks-2020-2025-deep-leakage-from-gradients&quot;&gt;model inversion attacks 2020-2025 (deep leakage from gradients)&lt;&#x2F;h3&gt;
&lt;p&gt;inversao de modelo e vazamento por gradiente, com foco em federated learning e training de language models.&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;Iterative and mixed-spaces image gradient inversion attack in federated learning | Cybersecurity - https:&#x2F;&#x2F;cybersecurity.springeropen.com&#x2F;articles&#x2F;10.1186&#x2F;s42400-024-00227-7&lt;&#x2F;li&gt;
&lt;li&gt;Understanding Deep Gradient Leakage via Inversion Influence Functions - PubMed - https:&#x2F;&#x2F;pubmed.ncbi.nlm.nih.gov&#x2F;38606303&#x2F;&lt;&#x2F;li&gt;
&lt;li&gt;Deep leakage from gradients | Proceedings of the 33rd International Conference on Neural Information Processing Systems - https:&#x2F;&#x2F;dl.acm.org&#x2F;doi&#x2F;10.5555&#x2F;3454287.3455610&lt;&#x2F;li&gt;
&lt;li&gt;Wasserstein Distance-Based Deep Leakage from Gradients - PMC - https:&#x2F;&#x2F;www.ncbi.nlm.nih.gov&#x2F;pmc&#x2F;articles&#x2F;PMC10217429&#x2F;&lt;&#x2F;li&gt;
&lt;li&gt;Uncovering Gradient Inversion Risks in Practical Language Model Training | Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security - https:&#x2F;&#x2F;dl.acm.org&#x2F;doi&#x2F;10.1145&#x2F;3658644.3690292&lt;&#x2F;li&gt;
&lt;li&gt;Deep Leakage from Gradients | SpringerLink - https:&#x2F;&#x2F;link.springer.com&#x2F;chapter&#x2F;10.1007&#x2F;978-3-030-63076-8_2&lt;&#x2F;li&gt;
&lt;li&gt;Understanding Deep Gradient Leakage via Inversion Influence Functions - https:&#x2F;&#x2F;arxiv.org&#x2F;html&#x2F;2309.13016&lt;&#x2F;li&gt;
&lt;li&gt;[1906.08935] Deep Leakage from Gradients - https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;1906.08935&lt;&#x2F;li&gt;
&lt;li&gt;Inverting Gradient Attacks Naturally Makes Data Poisons: An Availability Attack on Neural Networks - https:&#x2F;&#x2F;arxiv.org&#x2F;html&#x2F;2410.21453v1&lt;&#x2F;li&gt;
&lt;li&gt;A Survey of the Implementations of Model Inversion Attacks | SpringerLink - https:&#x2F;&#x2F;link.springer.com&#x2F;chapter&#x2F;10.1007&#x2F;978-3-031-30648-8_1&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;h3 id=&quot;onnx-safetensors-serializacao-de-pesos&quot;&gt;ONNX, SafeTensors, serializacao de pesos&lt;&#x2F;h3&gt;
&lt;p&gt;formatos de armazenamento de peso de rede neural e conversao entre eles. relevante pra entender superficie de ataque na serializacao.&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;ONNX - https:&#x2F;&#x2F;huggingface.co&#x2F;docs&#x2F;transformers&#x2F;en&#x2F;serialization&lt;&#x2F;li&gt;
&lt;li&gt;Safetensors, CKPT, ONNX, GGUF, and Other Key AI Model Formats | NEDNEX - https:&#x2F;&#x2F;nednex.com&#x2F;en&#x2F;what-are-safetensors&#x2F;&lt;&#x2F;li&gt;
&lt;li&gt;Model Weights File Formats in Machine Learning - https:&#x2F;&#x2F;learnopencv.com&#x2F;model-weights-file-formats-in-machine-learning&#x2F;&lt;&#x2F;li&gt;
&lt;li&gt;Export to ONNX - https:&#x2F;&#x2F;huggingface.co&#x2F;docs&#x2F;transformers&#x2F;v4.36.1&#x2F;serialization&lt;&#x2F;li&gt;
&lt;li&gt;justinchuby&#x2F;onnx-safetensors | DeepWiki - https:&#x2F;&#x2F;deepwiki.com&#x2F;justinchuby&#x2F;onnx-safetensors&lt;&#x2F;li&gt;
&lt;li&gt;Common AI Model Formats - https:&#x2F;&#x2F;huggingface.co&#x2F;blog&#x2F;ngxson&#x2F;common-ai-model-formats&lt;&#x2F;li&gt;
&lt;li&gt;python - How to convert safetensors model to onnx model? - Stack Overflow - https:&#x2F;&#x2F;stackoverflow.com&#x2F;questions&#x2F;77855742&#x2F;how-to-convert-safetensors-model-to-onnx-model&lt;&#x2F;li&gt;
&lt;li&gt;GitHub - justinchuby&#x2F;onnx-safetensors: Use safetensors with ONNX - https:&#x2F;&#x2F;github.com&#x2F;justinchuby&#x2F;onnx-safetensors&lt;&#x2F;li&gt;
&lt;li&gt;Save external data as safetensors - onnx&#x2F;onnx - Discussion #5461 - https:&#x2F;&#x2F;github.com&#x2F;onnx&#x2F;onnx&#x2F;discussions&#x2F;5461&lt;&#x2F;li&gt;
&lt;li&gt;GitHub - huggingface&#x2F;safetensors: Simple, safe way to store and distribute tensors - https:&#x2F;&#x2F;github.com&#x2F;huggingface&#x2F;safetensors&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;h3 id=&quot;distributed-training-e-sharding-fsdp&quot;&gt;distributed training e sharding (FSDP)&lt;&#x2F;h3&gt;
&lt;p&gt;tecnicas de sharding de modelo em treino distribuido, FSDP no centro.&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;Fully Sharded Data Parallel: faster AI training with fewer GPUs Engineering at Meta - https:&#x2F;&#x2F;engineering.fb.com&#x2F;2021&#x2F;07&#x2F;15&#x2F;open-source&#x2F;fsdp&#x2F;&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;ol start=&quot;2&quot;&gt;
&lt;li&gt;Sharding, Model Parallelism on the IPU with TensorFlow: Sharding and Pipelining - https:&#x2F;&#x2F;docs.graphcore.ai&#x2F;projects&#x2F;tf-model-parallelism&#x2F;en&#x2F;latest&#x2F;sharding.html&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;Sharded Data Parallelism - Amazon SageMaker AI - https:&#x2F;&#x2F;docs.aws.amazon.com&#x2F;sagemaker&#x2F;latest&#x2F;dg&#x2F;model-parallel-extended-features-pytorch-sharded-data-parallelism.html&lt;&#x2F;li&gt;
&lt;li&gt;[2305.01868] Pre-train and Search: Efficient Embedding Table Sharding with Pre-trained Neural Cost Models - https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;2305.01868&lt;&#x2F;li&gt;
&lt;li&gt;Introducing PyTorch Fully Sharded Data Parallel (FSDP) API, PyTorch - https:&#x2F;&#x2F;pytorch.org&#x2F;blog&#x2F;introducing-pytorch-fully-sharded-data-parallel-api&#x2F;&lt;&#x2F;li&gt;
&lt;li&gt;An Introduction to FSDP (Fully Sharded Data Parallel) for Distributed Training. | by Siddhartha Shrestha | Medium - https:&#x2F;&#x2F;medium.com&#x2F;@siddharthashrestha&#x2F;an-introduction-to-fsdp-fully-sharded-data-parallel-for-distributed-training-5e67adfa1712&lt;&#x2F;li&gt;
&lt;li&gt;Decentralized and Distributed Machine Learning Model - https:&#x2F;&#x2F;www.scs.stanford.edu&#x2F;17au-cs244b&#x2F;labs&#x2F;projects&#x2F;addair.pdf&lt;&#x2F;li&gt;
&lt;li&gt;[2407.19775] Model Agnostic Hybrid Sharding For Heterogeneous Distributed Inference - https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;2407.19775&lt;&#x2F;li&gt;
&lt;li&gt;Fully Sharded Data Parallelism (FSDP) - Edge AI and Vision Alliance - https:&#x2F;&#x2F;www.edge-ai-vision.com&#x2F;2024&#x2F;05&#x2F;fully-sharded-data-parallelism-fsdp&#x2F;&lt;&#x2F;li&gt;
&lt;li&gt;Getting Started with Fully Sharded Data Parallel (FSDP2), PyTorch Tutorials 2.8.0+cu128 documentation - https:&#x2F;&#x2F;docs.pytorch.org&#x2F;tutorials&#x2F;intermediate&#x2F;FSDP_tutorial.html&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;h3 id=&quot;model-serving-checkpoints-e-weight-storage&quot;&gt;model serving, checkpoints e weight storage&lt;&#x2F;h3&gt;
&lt;p&gt;vulnerabilidades de serving, formatos de checkpoint e armazenamento de peso em escala. inclui o RAND sobre seguranca de pesos de modelos de fronteira.&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;Save and load models | TensorFlow Core - https:&#x2F;&#x2F;www.tensorflow.org&#x2F;tutorials&#x2F;keras&#x2F;save_and_load&lt;&#x2F;li&gt;
&lt;li&gt;Architecting scalable checkpoint storage for large-scale ML training on AWS | Amazon Web Services - https:&#x2F;&#x2F;aws.amazon.com&#x2F;blogs&#x2F;storage&#x2F;architecting-scalable-checkpoint-storage-for-large-scale-ml-training-on-aws&#x2F;&lt;&#x2F;li&gt;
&lt;li&gt;Model Weights File Formats in Machine Learning - https:&#x2F;&#x2F;learnopencv.com&#x2F;model-weights-file-formats-in-machine-learning&#x2F;&lt;&#x2F;li&gt;
&lt;li&gt;What is Machine Learning Checkpointing? Deep Learning Models - https:&#x2F;&#x2F;www.deepchecks.com&#x2F;glossary&#x2F;machine-learning-checkpointing&#x2F;&lt;&#x2F;li&gt;
&lt;li&gt;Training checkpoints | TensorFlow Core - https:&#x2F;&#x2F;www.tensorflow.org&#x2F;guide&#x2F;checkpoint&lt;&#x2F;li&gt;
&lt;li&gt;What is Machine Learning Checkpointing | Giskard - https:&#x2F;&#x2F;www.giskard.ai&#x2F;glossary&#x2F;machine-learning-checkpointing&lt;&#x2F;li&gt;
&lt;li&gt;deep learning - what happens to model weights and how does checkpointing work? - Stack Overflow - https:&#x2F;&#x2F;stackoverflow.com&#x2F;questions&#x2F;75368038&#x2F;what-happens-to-model-weights-and-how-does-checkpointing-work&lt;&#x2F;li&gt;
&lt;li&gt;Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models | RAND - https:&#x2F;&#x2F;www.rand.org&#x2F;pubs&#x2F;research_reports&#x2F;RRA2849-1.html&lt;&#x2F;li&gt;
&lt;li&gt;Saving and Loading Checkpoints, Ray 2.49.0 - https:&#x2F;&#x2F;docs.ray.io&#x2F;en&#x2F;latest&#x2F;train&#x2F;user-guides&#x2F;checkpoints.html&lt;&#x2F;li&gt;
&lt;li&gt;Tips and tricks for performing large model checkpointing - https:&#x2F;&#x2F;nebius.com&#x2F;blog&#x2F;posts&#x2F;model-pre-training&#x2F;large-ml-model-checkpointing-tips&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;h3 id=&quot;knockoffnets-activethief-codigo-de-extracao&quot;&gt;KnockoffNets &#x2F; ActiveThief (codigo de extracao)&lt;&#x2F;h3&gt;
&lt;p&gt;extracao de modelo via active learning sobre dados publicos nao anotados.&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;ActiveThief: Model Extraction Using Active Learning and Unannotated Public Data | Request PDF - https:&#x2F;&#x2F;www.researchgate.net&#x2F;publication&#x2F;341891796_ActiveThief_Model_Extraction_Using_Active_Learning_and_Unannotated_Public_Data&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;h3 id=&quot;serving-infrastructure-security-e-upload-de-modelos&quot;&gt;serving infrastructure security e upload de modelos&lt;&#x2F;h3&gt;
&lt;p&gt;seguranca de infra de serving de redes neurais, vulnerabilidades e upload de modelos.&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;How Effective Are Neural Networks for Fixing Security Vulnerabilities | Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis - https:&#x2F;&#x2F;dl.acm.org&#x2F;doi&#x2F;10.1145&#x2F;3597926.3598135&lt;&#x2F;li&gt;
&lt;li&gt;[2305.18607] How Effective Are Neural Networks for Fixing Security Vulnerabilities - https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;2305.18607&lt;&#x2F;li&gt;
&lt;li&gt;One Step Ahead in Cyber Hide-and-Seek: Automating Malicious Infrastructure Discovery With Graph Neural Networks - https:&#x2F;&#x2F;unit42.paloaltonetworks.com&#x2F;graph-neural-networks&#x2F;&lt;&#x2F;li&gt;
&lt;li&gt;A survey on neural networks for (cyber-) security and (cyber-) security of neural networks - ScienceDirect - https:&#x2F;&#x2F;www.sciencedirect.com&#x2F;science&#x2F;article&#x2F;pii&#x2F;S0925231222007184&lt;&#x2F;li&gt;
&lt;li&gt;Extremely boosted neural network for more accurate multi-stage Cyber attack prediction in cloud computing environment | Journal of Cloud Computing - https:&#x2F;&#x2F;journalofcloudcomputing.springeropen.com&#x2F;articles&#x2F;10.1186&#x2F;s13677-022-00356-9&lt;&#x2F;li&gt;
&lt;li&gt;How Effective Are Neural Networks for Fixing Security Vulnerabilities - https:&#x2F;&#x2F;arxiv.org&#x2F;html&#x2F;2305.18607v2&lt;&#x2F;li&gt;
&lt;li&gt;[2011.05976] The Vulnerability of the Neural Networks Against Adversarial Examples in Deep Learning Algorithms - https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;2011.05976&lt;&#x2F;li&gt;
&lt;li&gt;Exploring the Security Vulnerabilities of Neural Networks - https:&#x2F;&#x2F;opendatascience.com&#x2F;exploring-the-security-vulnerabilities-of-neural-networks&#x2F;&lt;&#x2F;li&gt;
&lt;li&gt;Machine Learning in Security: Detecting Suspicious Processes Using Recurrent Neural Networks | Splunk - https:&#x2F;&#x2F;www.splunk.com&#x2F;en_us&#x2F;blog&#x2F;security&#x2F;machine-learning-in-security-detecting-suspicious-processes-using-recurrent-neural-networks.html&lt;&#x2F;li&gt;
&lt;li&gt;Security Assessment of Software Design using Neural - https:&#x2F;&#x2F;arxiv.org&#x2F;pdf&#x2F;1303.2017&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
</content>
        
    </entry>
</feed>
