https://taxonomy.eticas.ai/risk/model-extraction
Maturity: established
Attacks that aim to recover or replicate the underlying AI model, its parameters, or its training data through queried interactions, enabling intellectual property theft or further targeted attacks against the system.
Also known as: Model stealing · Model inversion
System type: ADM and LLM systems
Lifecycle stages: Post Processing
| Framework | Reference |
|---|---|
| EU AI Act (Regulation 2024/1689) | Article 15(5) — cybersecurity (Recital 76 confidentiality attacks) |
| AIUC-1 — AI Underwriting Company Standard | Prevent AI endpoint scraping |
| NIST AI 600-1 — Generative AI Risk Profile | Information Security (exfiltration of model weights/training data) |
| NIST AI Risk Management Framework (AI 100-1) | Secure & Resilient (confidentiality attacks) |
| Framework | Reference |
|---|---|
| IBM AI Risk Atlas | Inference → Extraction attack |
| W3C Data Privacy Vocabulary — AI Extension | Model Inversion |
| MIT AI Risk Repository | AI system security vulnerabilities and attacks |