Stealing Machine Learning Models via Prediction APIs, Florian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter, and Thomas Ristenpart, 2016Proceedings of the 25th USENIX Security Symposium (USENIX Security 2016) (USENIX Association)DOI: 10.1145/2976749.2978396 - This paper is foundational in model stealing research, introducing the concept of extracting a surrogate model from a black-box prediction API.