Hard-Label Cryptanalytic Extraction of Neural Network Models
Yi Chen, Xiaoyang Dong, Jian Guo, Yantian Shen, Anyu Wang, Xiaoyun, Wang

TL;DR
This paper introduces the first theoretical attack capable of extracting neural network parameters under the hard-label setting, validated on real datasets with practical efficiency.
Contribution
It presents a novel attack method that achieves functionally equivalent extraction in the hard-label setting for ReLU neural networks, a previously unresolved challenge.
Findings
Effective extraction on networks with 10^5 parameters within hours
Validated on MNIST and CIFAR10 datasets
Works under realistic hard-label access constraints
Abstract
The machine learning problem of extracting neural network parameters has been proposed for nearly three decades. Functionally equivalent extraction is a crucial goal for research on this problem. When the adversary has access to the raw output of neural networks, various attacks, including those presented at CRYPTO 2020 and EUROCRYPT 2024, have successfully achieved this goal. However, this goal is not achieved when neural networks operate under a hard-label setting where the raw output is inaccessible. In this paper, we propose the first attack that theoretically achieves functionally equivalent extraction under the hard-label setting, which applies to ReLU neural networks. The effectiveness of our attack is validated through practical experiments on a wide range of ReLU neural networks, including neural networks trained on two real benchmarking datasets (MNIST, CIFAR10) widely used…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsStatistical and Computational Modeling · Neural Networks and Applications · Scientific Computing and Data Management
Methods*Communicated@Fast*How Do I Communicate to Expedia?
