A paper co-authored by ZISC faculty member Florian Tramèr has received a Test of Time Award at the 2026 USENIX Security Symposium, one of the world’s leading computer security conferences.
Published in 2016, Stealing Machine Learning Models via Prediction APIs demonstrated that attackers could reproduce the functionality of confidential machine-learning models simply by interacting with them through public prediction APIs—without access to the models’ parameters or training data.
The research helped establish the field of model stealing and model extraction attacks and has had a lasting impact on AI security. Its findings remain highly relevant as organisations increasingly provide machine-learning systems through online services and APIs.
The USENIX Test of Time Award recognises papers published ten years earlier that have made a lasting contribution to computer security research and practice. The paper was co-authored by Florian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter and Thomas Ristenpart, who are now professors at ETH Zurich, Yale University, Cornell Tech, Duke University and the University of Toronto, respectively.
Tramèr’s research continues to focus on the security, privacy and trustworthiness of AI systems. As head of ETH Zurich’s Secure and Private AI (SPY) Lab, he studies how AI systems can be attacked and how these vulnerabilities can be addressed through technical and regulatory safeguards.
Congratulations on this outstanding achievement!


Congratulations to the ZISC chair 