Lune

CRYPTO2020Top-tier venue

Cryptanalytic Extraction of Neural Network Models

Nicholas Carlini, Matthew Jagielski, Ilya Mironov

2020Year
109Citations
40Top-tier citations

Abstract

We argue that the machine learning problem of model extraction is actually a cryptanalytic problem in disguise, and should be studied as such. Given oracle access to a neural network, we introduce a differential attack that can efficiently steal the parameters of the remote model up to floating point precision. Our attack relies on the fact that ReLU neural networks are piecewise linear functions, and thus queries at the critical points reveal information about the model parameters. We evaluate our attack on multiple neural network models and extract models that are 2 20 times more precise and require 100× fewer queries than prior work. For example, we extract a 100,000 parameter neural network trained on the MNIST digit recognition task with 2 21.5 queries in under an hour, such that the extracted model agrees with the oracle on all inputs up to a worst-case error of 2 -25 , or a model with 4,000 parameters in 2 18.5 queries with worst-case error of 2 -40.4 . Code is available at https://github.com/google-research/cryptanalytic-model-extraction.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 4a7faf9a-578c-454f-8f00-ac1ab7e29a3f

Cited by top-tier papers40

Ask how each one uses it

Builds on14

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines