Paper 2026/2095

Cryptanalytic Extraction of Neural Networks Without Known Architecture Assumption

Yantian Shen, Tsinghua University, Beijing, China
Yi Chen, Tsinghua University, Beijing, China
Anyu Wang, Tsinghua University, Beijing, China
Hongbo Yu, Tsinghua University, Beijing, China
Xiaoyun Wang, Tsinghua University, Beijing, China
Abstract

Cryptanalytic model extraction aims to reconstruct a functionally equivalent model through black-box interactions with the victim model. Under the fundamental assumption that the network architecture is completely known, existing attacks achieve the goal by recovering the model parameters. In this paper, we explore whether this assumption can be removed practically. Focusing on ReLU fully connected networks, which are widely studied in this field, we propose a guess-and-determine framework that jointly recovers the network architecture (including network depth and hidden-layer dimensions) and the model parameters. This framework is based on a simple yet effective high-level idea: after designing a parameter recovery attack under the known-architecture assumption, we can analyze the architecture-sensitive traces observed during parameter recovery to recover the network architecture. We identify two such traces in differential extraction attacks: (i) a zero suffix in the merged weight vectors produced by signature recovery, whose length reveals the hidden layer dimension; and (ii) an equality pattern in the preimage-based sign recovery, which occurs only under the true hidden layer dimension. These two signals give rise to two routes for network architecture recovery. For the second-to-last layer, we further propose two methods, one for identifying it, and one for recovering its dimension. Practical end-to-end attacks are implemented on a wide range of ReLU neural networks, including both expansive and non-expansive networks. To the best of our knowledge, this is the first time the feasibility of achieving functionally equivalent extraction on deep neural networks, after removing the known-architecture assumption, has been demonstrated in practice.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Cryptanalytic ExtractionNeural NetworksNetwork Architecture Recovery
Contact author(s)
shenyt22 @ mails tsinghua edu cn
chenyi2023 @ tsinghua edu cn
anyuwang @ tsinghua edu cn
yuhongbo @ mail tsinghua edu cn
xiaoyunwang @ tsinghua edu cn
History
2026-09-22: approved
2026-09-18: received
See all versions
Short URL
https://ia.cr/2026/2095
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2095,
      author = {Yantian Shen and Yi Chen and Anyu Wang and Hongbo Yu and Xiaoyun Wang},
      title = {Cryptanalytic Extraction of Neural Networks Without Known Architecture Assumption},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2095},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2095}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.