Model Inversion, Stealing & Extraction Defense
Differential privacy with DP-SGD, membership inference resistance, gradient sanitization, and confidential enclave training.
Course Overview & Objectives
Protect intellectual property and confidential training data. Discover how attackers steal proprietary model weights through API query black-boxing, extract private training records via membership inference, and apply Differential Privacy (DP-SGD) to mathematically prevent data leakage.
What You Will Master
- Simulate shadow-model membership inference attacks to quantify training data leakage
- Train neural networks with Differentially Private Stochastic Gradient Descent (DP-SGD) using Opacus
- Protect model weights and gradients inside AMD SEV / Intel SGX confidential enclaves
- Detect and rate-limit model extraction queries that steal weights via API scraping
Prerequisites
- Solid understanding of deep learning training loops in PyTorch
- Basic calculus and statistics
Platforms & Tools Covered
Detailed Curriculum Modules
1 modules structured from foundational theory through complex adversarial execution.
Membership Inference & Model Inversion Theory
Analyzing loss discrepancies between training data members and non-members.
Hands-on Virtual Sandbox Labs
Zero local hardware dependencies. Provisioned in cloud containers via browser terminal.
Training with DP-SGD via PyTorch Opacus
Apply noise injection and gradient clipping to achieve epsilon=2 differential privacy guarantees.
Faculty & Lead Instructor
Direct weekly instruction, live office hours, and code-review feedback.
Ananya Roy
Thread Security EducationHead of AI Vulnerability Research
Researching privacy-preserving machine learning, differential privacy budgeting, and cryptographic enclaves.
Frequently Asked Questions
Everything you need to know about scheduling, cohort admissions, and lab access.
Is this mathematical or hands-on?
Both! You learn the epsilon-delta mathematical definitions and implement the code directly in PyTorch.
Ready to Master Model Inversion, Stealing & Extraction Defense?
Join the upcoming cohort. Seats are limited to maintain a high faculty-to-student ratio and rigorous sandbox feedback.