machine learning models are shown to face a severe threat from Model
Extraction Attacks, where a well-trained private model owned by a service
provider can be stolen by an attacker pretending as a client. Unfortunately,
prior works focus on the models trained over the Euclidean space,