Model stealing attacks have been successfully used in many machine learning domains, but there is little understanding of how these work against models that perform malware detection. Malware detection and, general, security domains unique conditions. In particular, are very strong requirements for low false positive rates (FPR). Antivirus products (AVs) use complex systems to steal, binaries c...