Is the Hard-Label Cryptanalytic Model Extraction Really Polynomial?
Akira Ito, Takayuki Miura, Yosuke Todo
摘要
Deep Neural Networks (DNNs) have attracted significant attention, and their internal models are regarded as valuable intellectual assets. Extracting a model via oracle access to a DNN is conceptually similar to extracting a secret key via oracle access to a block cipher. Consequently, cryptanalytic techniques, particularly differential-like attacks, have been actively explored recently. ReLU-based DNNs are the most common architectures. While early works (e.g., Crypto 2020, Eurocrypt 2024) assume access to exact output logits, more recent works (e.g., Asiacrypt 2024, Eurocrypt 2025) focus on the hard-label setting, where the attacker observes only the final classification result (e.g., "dog" or "car"). Notably, Carlini et al. (Eurocrypt 2025) demonstrated that model extraction is feasible in polynomial time even under this restricted setting. In this paper, we show that a key assumption of their attack becomes increasingly unrealistic as the target depth grows. While prior works have noted neurons whose activation states rarely change, we analyze their concrete impact on hard-label extraction: even a single neuron that is (almost) always active can prevent the attack from proceeding unless its parameters are recovered, and ignoring it inevitably incurs a non-negligible error. A straightforward solution is to recover these parameters from a state switch, but observing such a switch becomes exponentially harder as the depth increases, implying that hard-label extraction is not always polynomial time. To address this limitation, we propose cross-layer extraction. Rather than extracting the secret parameters (e.g., weights and biases) directly, we exploit cross-layer interactions to recover them from deeper layers, reducing query complexity and addressing limitations of existing model extraction approaches. The source code is available at https://github.com/ECSIS-lab/hard-label-cross-layer-extraction.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper11
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh 等ICML 2021 · 被引用 47,906 次
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter 等USENIX Security 2016 · 被引用 2,088 次
- Reverse-engineering deep ReLU networksDavid Rolnick, Konrad P. KordingICML 2020 · 被引用 121 次
- Cryptanalytic Extraction of Neural Network ModelsNicholas Carlini, Matthew Jagielski, Ilya MironovCRYPTO 2020 · 被引用 109 次
- Beyond Slow Signs in High-fidelity Model ExtractionHanna Foerster, Robert Mullins, Ilia Shumailov, Jamie HayesNeurIPS 2024 · 被引用 19 次
相关 Paper
- Polynomial Time Cryptanalytic Extraction of Deep Neural Networks in the Hard-Label SettingNicholas Carlini, Jorge Chávez-Saab, Anna Hambitzer, Francisco Rodríguez-Henríquez 等EUROCRYPT 2025 · 被引用 10 次
- Polynomial Time Cryptanalytic Extraction of Neural Network ModelsIsaac Andrés Canales Martinez, Jorge Chávez-Saab, Anna Hambitzer, Francisco Rodríguez-Henríquez 等EUROCRYPT 2024 · 被引用 13 次
- Navigating the Deep: End-to-End Extraction on Deep Neural NetworksHaolin Liu, Adrien Siproudhis, Samuel Experton, Peter Lorenz 等EUROCRYPT 2026 · 被引用 2 次
- An Exact Poly-Time Membership-Queries Algorithm for Extracting a Three-Layer ReLU NetworkAmit Daniely, Elad GranotICLR 2023
- Cryptanalytic Extraction of Deep Neural Networks with Non-linear ActivationsRoderick Asselineau, Patrick Derbez, Pierre-Alain Fouque, Brice MinaudCRYPTO 2026 · 被引用 8 次
