“Stealing a model through its API” describes two attacks that share nothing but a name. One recovers parameters. The other recovers behaviour. They have different costs, different feasibility and different defences, and the confusion between them produces a lot of bad advice.
Two different attacks with one name
Attack
Description
parameter extraction











