By Grace Stanley
Ari Juels — the Weill Family Foundation and Joan and Sanford I. Weill Professor at Cornell Tech, the Cornell Ann S. Bowers College of Computing and Information Science, and the Jacobs Technion-Cornell Institute — has received the 2026 USENIX Security Test of Time Award for the paper “Stealing Machine Learning Models via Prediction APIs.” The award was announced Aug. 12 at the 35th USENIX Security Symposium in Baltimore.
The paper, originally presented at the USENIX Security Symposium in 2016, was co-authored by Florian Tramèr of ETH Zurich; Fan Zhang of Yale University; Michael K. Reiter of Duke University; and Thomas Ristenpart of the University of Toronto, who was a faculty member of Cornell Tech when the paper was published. The award recognizes research that has had a lasting and significant impact on the field over the past decade.
As AI systems become increasingly valuable, organizations often provide access to them through online services and application programming interfaces (APIs). In their paper, the researchers demonstrated that these systems could be vulnerable to “model extraction” attacks, in which someone repeatedly queries an AI model and uses its responses to create a close copy of the original system.
The team showed that, in some cases, attackers could reconstruct sophisticated machine learning models with surprising accuracy using only publicly accessible prediction tools. Their findings revealed important risks for companies and organizations seeking to protect proprietary AI systems, sensitive data, and security-focused machine learning applications.
A decade later, the paper is widely recognized as foundational to the field of AI security. Its insights helped shape research on protecting machine learning models from theft, safeguarding sensitive information, and securing the growing ecosystem of AI-powered products and services.
Juels is co-director of the Initiative for CryptoCurrencies and Contracts (IC3) and chief scientist at Chainlink Labs. His research spans cybersecurity, privacy, cryptography, and blockchain technologies, and he is the author of crypto thriller novels “The Oracle” and “Tetraktys.” Before joining Cornell Tech, he served as chief scientist of RSA and director of RSA Laboratories.
Grace Stanley is the editorial lead for Cornell Tech.
Media Highlights
Tech Policy Press
Content Moderation, Encryption, and the LawRELATED STORIES