Paper 2026/2097

End-to-End Hard-Label Cryptanalytic Model Extraction Using Efficient Sign Recovery

Akira Ito, Tohoku University
Takayuki Miura, NTT Social Informatics Laboratories
Yosuke Todo, NTT Social Informatics Laboratories
Abstract

The importance of deep neural networks (DNNs) is widely recognized, and the parameters obtained through training are regarded as valuable assets. Recently, attacks that extract these parameters using only oracle queries to a DNN have been actively studied at IACR conferences. The hard-label setting is the most challenging setting for model extraction, where an adversary can observe only the final output label, such as “dog” or “cat.” At Eurocrypt 2025, Carlini et al. proposed polynomial-time hard-label extraction of ReLU-based MLPs. However, one step of this attack process, i.e., sign recovery, requires a large number of queries and substantial computation. Implementing this step in a black-box setting remains difficult. Consequently, a fully black-box end-to-end demonstration on trained deep ReLU MLPs has remained a challenge. In this paper, we propose a new sign-recovery algorithm based on a completely different principle from the existing method. Our method requires no dedicated queries for sign recovery. In our experiments, it achieves higher sign-recovery accuracy than the existing method. Consequently, it enables efficient sign recovery even for trained models. With our sign-recovery algorithm, all steps of hard-label model extraction can be implemented in a black-box setting. By combining these implementations, we demonstrate end-to-end model extraction from models trained on MNIST and Fashion-MNIST, with width 16 and 4 or 6 hidden layers, achieving over 98% label agreement.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
ReLU networkModel extractionHard-label attackSign recovery
Contact author(s)
akira ito b1 @ tohoku ac jp
tkyk miura @ ntt com
yosuke todo @ ntt com
History
2026-09-22: approved
2026-09-18: received
See all versions
Short URL
https://ia.cr/2026/2097
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2097,
      author = {Akira Ito and Takayuki Miura and Yosuke Todo},
      title = {End-to-End Hard-Label Cryptanalytic Model Extraction Using Efficient Sign Recovery},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2097},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2097}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.