Paper 2026/168

Beyond Feedforward Networks: Cryptanalytic Extraction of RNNs

Longxiang Wei, Shandong University
Hao Lei, Shandong University
Xiaokang Qi, Shandong University
Xiaohan Sun, Shandong University
Lei Gao, Shandong University
Kai Hu, Shandong University
Wei Wang, Shandong University
Meiqin Wang, Shandong University
Abstract

Recurrent neural networks (RNNs) play an important role in time series modeling, signal processing, and resource constrained applications. Their parameters encode valuable functionality and constitute proprietary intellectual property. Cryptanalytic extraction tests whether black box queries reveal functionally equivalent parameters. Such analysis is important for assessing the security of deployed RNNs. However, prior cryptanalytic attacks mainly target feedforward networks such as fully connected networks (FCNs) and convolutional neural networks (CNNs). RNNs reuse their recurrent parameters at every time step, which existing extraction pipelines do not address. We present cryptanalytic extraction of ReLU RNNs, including single-layer and stacked (a.k.a. multi-layer) RNNs, in both the hard-label and raw-output settings. To the best of our knowledge, this is the first such extraction. Using controlled inputs, we construct equivalent feedforward models whose depths depend on the number of recurrent layers, independently of the sequence length. However, parameter recovery from the equivalent models may yield recurrent weights with incompatible neuron orderings and positive scalings for the previous and current hidden states. We develop recurrent parameter alignment to make these transformations consistent and enable parameter reuse across time. Stacked RNNs are harder, because one equivalent model contains coupled branches, which prevent direct use of FCN sign recovery and complicate signature recovery. We therefore further develop two techniques, recurrent parameter recovery and folded bias difference. The former uses the recovered input weights to guide clustering and recover the remaining recurrent parameters, including their signs. The latter handles neurons that are otherwise difficult to recover. We demonstrate end-to-end extraction across five RNN architectures with up to three recurrent layers in both observation settings. An additional raw-output experiment extends the sequence length from 20 to 1024 using the same target parameters.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
ReLU-based Neural NetworksFunctionally Equivalent ExtractionRNNHard-Label
Contact author(s)
longxiang_wei @ mail sdu edu cn
310082434 @ qq com
xiaokangqi @ mail sdu edu cn
xhansun @ mail sdu edu cn
leigao @ sdu edu cn
kai hu @ sdu edu cn
weiwangsdu @ sdu edu cn
mqwang @ sdu edu cn
History
2026-09-18: last of 2 revisions
2026-02-01: received
See all versions
Short URL
https://ia.cr/2026/168
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/168,
      author = {Longxiang Wei and Hao Lei and Xiaokang Qi and Xiaohan Sun and Lei Gao and Kai Hu and Wei Wang and Meiqin Wang},
      title = {Beyond Feedforward Networks: Cryptanalytic Extraction of {RNNs}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/168},
      year = {2026},
      url = {https://eprint.iacr.org/2026/168}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.