Cryptanalytic Extraction of Deep Neural Networks with Non-linear Activations
Roderick Asselineau, Patrick Derbez, Pierre-Alain Fouque, Brice Minaud
Abstract
Deep neural networks (DNNs) are today’s central machine learning engines, yet their parameters represent valuable intellectual prop- erty exposed to extraction through black-box queries. While existing cryptanalytic attacks have primarily targeted ReLU-based architectures, this work extends model-stealing techniques to a broad class of non-linear activation functions, including GELU, SiLU, SELU, Sigmoid, and oth- ers. We present the first universal black-box attack capable of recovering both weights and biases from networks whose activations converge to lin- ear behavior outside narrow non-linear regions. Our method generalizes prior geometric approaches by leveraging higher-order derivatives and ad- jacent linear zone analysis, bypassing the need for non-differentiability. We show that, for several activations, neuron signatures can be recov- ered more easily than in the ReLU case, and we further demonstrate that activation functions themselves can be identified when not publicly known. Our results broaden the scope of cryptanalytic model extraction, revealing that the secrecy of activation functions or smoothness of nonlin- earities does not provide effective protection against black-box recovery attacks.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 150853bc-7fd7-485c-89cd-5ffccbb8c273Cited by top-tier papers1
Ask how each one uses itRelated papers
- Polynomial Time Cryptanalytic Extraction of Deep Neural Networks in the Hard-Label SettingNicholas Carlini, Jorge Chávez-Saab, Anna Hambitzer, Francisco Rodríguez-Henríquez et al.EUROCRYPT 2025 · 10 citations
- Is the Hard-Label Cryptanalytic Model Extraction Really Polynomial?Akira Ito, Takayuki Miura, Yosuke TodoCRYPTO 2026
- Reverse-engineering deep ReLU networksDavid Rolnick, Konrad P. KordingICML 2020 · 121 citations
- Cryptanalytic Extraction of Neural Network ModelsNicholas Carlini, Matthew Jagielski, Ilya MironovCRYPTO 2020 · 109 citations
- Polynomial Time Cryptanalytic Extraction of Neural Network ModelsIsaac Andrés Canales Martinez, Jorge Chávez-Saab, Anna Hambitzer, Francisco Rodríguez-Henríquez et al.EUROCRYPT 2024 · 13 citations
