Paper 2026/2127
Polynomial Time Cryptanalytic Extraction of Deep Neural Networks in the Limited Architecture Knowledge Setting
Abstract
Deep Neural Networks (DNNs) have emerged as a cornerstone of modern AI systems, rendering their internal parameters highly valuable intellectual property. Consequently, the security of DNNs against model extraction attacks has garnered significant research attention. Recent cryptanalytic extraction methods have demonstrated that recovering DNN parameters is feasible in polynomial time, both when attackers have exact logit access and in the more restrictive hard-label setting. However, a critical limitation of these state-of-the-art frameworks is the assumption that the attacker possesses a complete architecture knowledge of the target network, including the exact depth and width of the hidden layers. To date, the efficacy of parameter extraction algorithms under limited architecture knowledge remains unexplored. This paper demonstrates that in the limited architecture knowledge scenario, existing cryptanalytic attacks suffer from neuron omission, which causes subsequent parameter recovery to fail entirely. To address this, we propose a general adaptive extraction workflow integrated with a novel error detection algorithm capable of identifying missing neuron anomalies and successfully recovering the correct parameters. Through experiment, we achieve the first successful extraction of a four-hidden-layer ReLU network (comprising over 1.1 million parameters) trained on CIFAR-10 under the limited architecture knowledge setting, while maintaining a 100% error detection recall.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- ReLU-Based Deep Neural NetworksNeural Network ExtractionLimited Architecture Knowledge Attack
- Contact author(s)
-
51275902064 @ stu ecnu edu cn
glwang @ sei ecnu edu cn - History
- 2026-09-22: approved
- 2026-09-20: received
- See all versions
- Short URL
- https://ia.cr/2026/2127
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2127,
author = {Yiqing Li and Gaoli Wang},
title = {Polynomial Time Cryptanalytic Extraction of Deep Neural Networks in the Limited Architecture Knowledge Setting},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2127},
year = {2026},
url = {https://eprint.iacr.org/2026/2127}
}