Paper 2025/1756

Are Neural Networks Collision Resistant?

Marco Benedetti, Bocconi University
Andrej Bogdanov, University of Ottawa
Enrico M. Malatesta, Bocconi University
Marc Mézard, Boconi University
Gianmarco Perrupato, Bocconi University
Alon Rosen, Bocconi University
Nikolaj I. Schwartzbach
Riccardo Zecchina, Bocconi University
Abstract

When neural networks are trained to classify a dataset, one finds a set of weights from which the network produces a label for each data point. We study the algorithmic complexity of finding a collision in a single-layer neural net, where a collision is defined as two distinct sets of weights that assign the same labels to all data. For binary perceptrons with oscillating activation functions, we establish the emergence of an overlap gap property in the space of collisions. This is a topological property believed to be a barrier to the performance of efficient algorithms. The hardness is supported by numerical experiments using approximate message passing algorithms, for which the algorithms stop working well below the value predicted by our analysis. Neural networks provide a new category of candidate collision resistant functions, which for some parameter setting depart from constructions based on lattices. Beyond relevance to cryptography, our work uncovers new forms of computational hardness emerging in large neural networks which may be of independent interest.

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Preprint.
Keywords
statistical physicscryptographyperceptronoverlap gapcollision resistancecrh
Contact author(s)
marco benedetti4 @ unibocconi it
abogdano @ uottawa ca
enrico malatesta @ unibocconi it
marc mezard @ unibocconi it
gianmarco perrupato @ unibocconi it
alon rosen @ unibocconi it
nikolaj ignatieff @ gmail com
riccardo zecchina @ unibocconi it
History
2025-09-26: approved
2025-09-25: received
See all versions
Short URL
https://ia.cr/2025/1756
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1756,
      author = {Marco Benedetti and Andrej Bogdanov and Enrico M. Malatesta and Marc Mézard and Gianmarco Perrupato and Alon Rosen and Nikolaj I. Schwartzbach and Riccardo Zecchina},
      title = {Are Neural Networks Collision Resistant?},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1756},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1756}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.