Model extraction

https://taxonomy.eticas.ai/risk/model-extraction

Maturity: established

Attacks that aim to recover or replicate the underlying AI model, its parameters, or its training data through queried interactions, enabling intellectual property theft or further targeted attacks against the system.

Also known as: Model stealing · Model inversion

System type: ADM and LLM systems
Lifecycle stages: Post Processing

Mappings to external frameworks

Standards & frameworks

Framework Reference
EU AI Act (Regulation 2024/1689) Article 15(5) — cybersecurity (Recital 76 confidentiality attacks)
AIUC-1 — AI Underwriting Company Standard Prevent AI endpoint scraping
NIST AI 600-1 — Generative AI Risk Profile Information Security (exfiltration of model weights/training data)
NIST AI Risk Management Framework (AI 100-1) Secure & Resilient (confidentiality attacks)

Taxonomies & vocabularies

Framework Reference
IBM AI Risk Atlas Inference → Extraction attack
W3C Data Privacy Vocabulary — AI Extension Model Inversion
MIT AI Risk Repository AI system security vulnerabilities and attacks