“Stealing a model through its API” describes two attacks that share nothing but a name. One recovers parameters. The other recovers behaviour. They have different costs, different feasibility and different defences, and the confusion between them produces a lot of bad advice.

Two different attacks with one name

Attack

Description

parameter extraction