- Популярные видео
- Авто
- Видео-блоги
- ДТП, аварии
- Для маленьких
- Еда, напитки
- Животные
- Закон и право
- Знаменитости
- Игры
- Искусство
- Комедии
- Красота, мода
- Кулинария, рецепты
- Люди
- Мото
- Музыка
- Мультфильмы
- Наука, технологии
- Новости
- Образование
- Политика
- Праздники
- Приколы
- Природа
- Происшествия
- Путешествия
- Развлечения
- Ржач
- Семья
- Сериалы
- Спорт
- Стиль жизни
- ТВ передачи
- Танцы
- Технологии
- Товары
- Ужасы
- Фильмы
- Шоу-бизнес
- Юмор
AI Security Lesson 29: Stealing AI Models Explained for Teams
Three API queries were enough to steal this model. In Lesson 29 of the CompTIA SecAI+ AI Security course, you will watch an attacker reconstruct a live model's weights through its public prediction API, learn how model inversion recovers faces and records from models, how membership inference tests whether a specific record trained a model, and how LLM training-data extraction scales to production models.
What you will learn:
- The black-box threat model: what an attacker gets from a prediction API
- ML05 Model Theft: equation-solving extraction (Tramer et al., 2016)
- Live demo: cloning a logistic-regression model with 3 queries
- ML03 Model Inversion: reconstructing faces from confidence scores (Fredrikson et al., 2015)
- ML04 Membership Inference: the shadow-model technique (Shokri et al., 2017)
- LLM training-data extraction: Carlini et al. 2021, and why bigger models memorize more
- The LLaMA weight leak of March 2023: why weights are the crown jewels
- Defenses: output fidelity reduction, query budgets, extraction monitoring, deduplication, weight protection
- A 5-step extraction audit you can run against your own API this week
Sources:
- OWASP ML05:2023 Model Theft: https://owasp.org/www-project-machine-learning-security-top-10/docs/ML05_2023-Model_Theft
- OWASP ML03:2023 Model Inversion Attack: https://owasp.org/www-project-machine-learning-security-top-10/docs/ML03_2023-Model_Inversion_Attack
- OWASP ML04:2023 Membership Inference Attack: https://owasp.org/www-project-machine-learning-security-top-10/docs/ML04_2023-Membership_Inference_Attack
- Tramer et al. 2016, Stealing Machine Learning Models via Prediction APIs: https://arxiv.org/abs/1609.02943
- Carlini et al. 2021, Extracting Training Data from Large Language Models: https://arxiv.org/abs/2012.07805
- Stealing Part of a Production Language Model: https://arxiv.org/abs/2403.06634
- NIST AI Risk Management Framework: https://www.nist.gov/itl/ai-risk-management-framework
- MITRE ATLAS: https://atlas.mitre.org/
Chapters:
00:00 Stealing AI models: the 3-query heist
01:06 The threat model: black-box query access
02:06 ML05: model theft by equation solving
03:12 LIVE DEMO: stealing a model in 3 queries
03:48 ML03: model inversion
04:50 ML04: membership inference
05:48 GenAI variant: LLM training-data extraction
06:49 When weights escape: the LLaMA lesson
07:30 Failure modes teams get wrong
08:22 Defenses that actually work
09:28 Your 5-step extraction audit
10:29 Knowledge check and wrap-up
Full course playlist: https://www.youtube.com/playlist?list=PLVG3-mjsRdH0
Educational content. Only test systems you own or are explicitly authorised to test.
Видео AI Security Lesson 29: Stealing AI Models Explained for Teams канала SecureTechIn
What you will learn:
- The black-box threat model: what an attacker gets from a prediction API
- ML05 Model Theft: equation-solving extraction (Tramer et al., 2016)
- Live demo: cloning a logistic-regression model with 3 queries
- ML03 Model Inversion: reconstructing faces from confidence scores (Fredrikson et al., 2015)
- ML04 Membership Inference: the shadow-model technique (Shokri et al., 2017)
- LLM training-data extraction: Carlini et al. 2021, and why bigger models memorize more
- The LLaMA weight leak of March 2023: why weights are the crown jewels
- Defenses: output fidelity reduction, query budgets, extraction monitoring, deduplication, weight protection
- A 5-step extraction audit you can run against your own API this week
Sources:
- OWASP ML05:2023 Model Theft: https://owasp.org/www-project-machine-learning-security-top-10/docs/ML05_2023-Model_Theft
- OWASP ML03:2023 Model Inversion Attack: https://owasp.org/www-project-machine-learning-security-top-10/docs/ML03_2023-Model_Inversion_Attack
- OWASP ML04:2023 Membership Inference Attack: https://owasp.org/www-project-machine-learning-security-top-10/docs/ML04_2023-Membership_Inference_Attack
- Tramer et al. 2016, Stealing Machine Learning Models via Prediction APIs: https://arxiv.org/abs/1609.02943
- Carlini et al. 2021, Extracting Training Data from Large Language Models: https://arxiv.org/abs/2012.07805
- Stealing Part of a Production Language Model: https://arxiv.org/abs/2403.06634
- NIST AI Risk Management Framework: https://www.nist.gov/itl/ai-risk-management-framework
- MITRE ATLAS: https://atlas.mitre.org/
Chapters:
00:00 Stealing AI models: the 3-query heist
01:06 The threat model: black-box query access
02:06 ML05: model theft by equation solving
03:12 LIVE DEMO: stealing a model in 3 queries
03:48 ML03: model inversion
04:50 ML04: membership inference
05:48 GenAI variant: LLM training-data extraction
06:49 When weights escape: the LLaMA lesson
07:30 Failure modes teams get wrong
08:22 Defenses that actually work
09:28 Your 5-step extraction audit
10:29 Knowledge check and wrap-up
Full course playlist: https://www.youtube.com/playlist?list=PLVG3-mjsRdH0
Educational content. Only test systems you own or are explicitly authorised to test.
Видео AI Security Lesson 29: Stealing AI Models Explained for Teams канала SecureTechIn
Комментарии отсутствуют
Информация о видео
5 октября 2026 г. 14:54:06
00:11:41
Другие видео канала
