<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="static/style.xsl"?><OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd"><responseDate>2026-09-20T06:52:09Z</responseDate><request verb="GetRecord" identifier="oai:dspace.mit.edu:1721.1/123124" metadataPrefix="dim">https://dspace.mit.edu/server/oai/request</request><GetRecord><record><header><identifier>oai:dspace.mit.edu:1721.1/123124</identifier><datestamp>2026-06-06T01:03:15Z</datestamp><setSpec>com_1721.1_7582</setSpec><setSpec>com_1721.1_7581</setSpec><setSpec>col_1721.1_131023</setSpec></header><metadata><dim:dim xmlns:dim="http://www.dspace.org/xmlns/dspace/dim" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:doc="http://www.lyncode.com/xoai" xsi:schemaLocation="http://www.dspace.org/xmlns/dspace/dim http://www.dspace.org/schema/dim.xsd">
   <dim:field mdschema="dc" element="contributor" qualifier="advisor" lang="en_US">Aleksander Ma̧dry.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="author" lang="en_US">Venigalla, Abhinav S.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="other" lang="en_US">Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="department" lang="en_US">Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="accessioned">2019-12-05T18:04:47Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="available">2019-12-05T18:04:47Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="copyright" lang="en_US">2019</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="issued" lang="en_US">2019</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="uri">https://hdl.handle.net/1721.1/123124</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="oclc" lang="en_US">1128270896</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">This electronic version was submitted by the student author. The certified thesis is available in the Institute Archives and Special Collections.</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Thesis: M. Eng. in Computer Science and Engineering, Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science, 2019</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Cataloged from student-submitted PDF version of thesis.</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Includes bibliographical references (pages 59-60).</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="abstract" lang="en_US">Training deep neural networks requires large quantities of labeled training data, on the order of thousands of examples per class. These requirements make model training both time-consuming and expensive, which provides an incentive for adversaries to steal, or copy, other users' models. In this work, we examine a recent defense method called neural network watermarking via memorized examples, where an owner intentionally trains his model to mislabel particular inputs. We try to isolate the mechanism by which memorized examples are learned by a model in order to better evaluate their robustness. We find that memorized examples are indeed strongly embedded in trained models and actually transfer to stolen models under one form of model stealing. When access to local input-logit gradient information is used by an attacker, the stolen model also learns to mislabel the memorized examples. We show that this transfer is robust to architecture mismatch and perturbations of the query set used for stealing. We present different possible mechanisms for memorized example transfer and find that local input geometry is insufficient to explain the phenomenon. Finally, we describe a simple method for a model owner to boost the transfer rate of memorized examples, increasing their effectiveness as a defense against model stealing.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="statementofresponsibility" lang="en_US">by Abhinav S. Venigalla.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="degree" lang="en_US">M.Eng. in Computer Science and Engineering</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="collection" lang="en_US">M.Eng.inComputerScienceandEngineering Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="extent" lang="en_US">60 pages</dim:field>
   <dim:field mdschema="dc" element="language" qualifier="iso" lang="en_US">eng</dim:field>
   <dim:field mdschema="dc" element="publisher" lang="en_US">Massachusetts Institute of Technology</dim:field>
   <dim:field mdschema="dc" element="rights" lang="en_US">MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission.</dim:field>
   <dim:field mdschema="dc" element="rights" qualifier="uri" lang="en_US">http://dspace.mit.edu/handle/1721.1/7582</dim:field>
   <dim:field mdschema="dc" element="subject" lang="en_US">Electrical Engineering and Computer Science.</dim:field>
   <dim:field mdschema="dc" element="title" lang="en_US">Strongly-transferring memorized examples in deep neural networks</dim:field>
   <dim:field mdschema="dc" element="type" lang="en_US">Thesis</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="mimetype">application/pdf</dim:field>
   <dim:field mdschema="dspace" element="imported" lang="en_US">2019-12-05T18:04:46Z</dim:field>
   <dim:field mdschema="dspace" element="entity" qualifier="type">Publication</dim:field>
   <dim:field mdschema="mit" element="thesis" qualifier="degree" lang="en_US">Master</dim:field>
   <dim:field mdschema="mit" element="thesis" qualifier="department" lang="en_US">EECS</dim:field>
   <dim:field mdschema="others" element="access-status">unknown</dim:field>
   <dim:field mdschema="others" element="access-status">unknown</dim:field>
   <dim:field mdschema="cerif" element="openaire" authority="" confidence="-1">&lt;Publication xmlns="https://www.openaire.eu/cerif-profile/1.1/" id="eaedb2c3-2f01-4bdc-9691-8d6f60b334e8">
	&lt;Type xmlns="https://www.openaire.eu/cerif-profile/vocab/COAR_Publication_Types">http://purl.org/coar/resource_type/c_1843&lt;/Type>
	&lt;Language>eng&lt;/Language>
   	&lt;Title>Strongly-transferring memorized examples in deep neural networks&lt;/Title>
   	&lt;PublishedIn>
    	&lt;Publication>
      	&lt;/Publication>
   	&lt;/PublishedIn>
   	&lt;PublicationDate>2019&lt;/PublicationDate>
   	&lt;Authors>
      	&lt;Author>
        	&lt;DisplayName>Venigalla, Abhinav S.&lt;/DisplayName>
         	&lt;Affiliation>
         		&lt;OrgUnit>
         		&lt;/OrgUnit>
         	&lt;/Affiliation>
      	&lt;/Author>
	&lt;/Authors>
   	&lt;Editors>
	&lt;/Editors>
    &lt;Publishers>
        &lt;Publisher>
            &lt;DisplayName>Massachusetts Institute of Technology&lt;/DisplayName>
            &lt;OrgUnit />
        &lt;/Publisher>
    &lt;/Publishers>
    &lt;License>http://dspace.mit.edu/handle/1721.1/7582&lt;/License>
    &lt;Keyword>Electrical Engineering and Computer Science.&lt;/Keyword>
   	&lt;Abstract>Training deep neural networks requires large quantities of labeled training data, on the order of thousands of examples per class. These requirements make model training both time-consuming and expensive, which provides an incentive for adversaries to steal, or copy, other users&amp;apos; models. In this work, we examine a recent defense method called neural network watermarking via memorized examples, where an owner intentionally trains his model to mislabel particular inputs. We try to isolate the mechanism by which memorized examples are learned by a model in order to better evaluate their robustness. We find that memorized examples are indeed strongly embedded in trained models and actually transfer to stolen models under one form of model stealing. When access to local input-logit gradient information is used by an attacker, the stolen model also learns to mislabel the memorized examples. We show that this transfer is robust to architecture mismatch and perturbations of the query set used for stealing. We present different possible mechanisms for memorized example transfer and find that local input geometry is insufficient to explain the phenomenon. Finally, we describe a simple method for a model owner to boost the transfer rate of memorized examples, increasing their effectiveness as a defense against model stealing.&lt;/Abstract>
	&lt;Access xmlns="http://purl.org/coar/access_right" 
    >
    &lt;/Access>
&lt;/Publication>
</dim:field>
</dim:dim>
</metadata></record></GetRecord></OAI-PMH>