Paper 2026/2161

Extracting CNNs in the Unknown-Architecture and Feedback-Agnostic Setting

Jiashuo Liu, Information Engineering University, Zhengzhou, China
Ruijie Ma, Department of Computer Science and Technology, Tsinghua University, Beijing, China
Manman Li, Information Engineering University, Zhengzhou, China
Yi Chen, Institute for Advanced Study, Tsinghua University, Beijing, China
Shaozhen Chen, Information Engineering University, Zhengzhou, China
Abstract

This paper studies the cryptanalytic extraction of convolutional neural networks (CNNs). Existing cryptanalytic extraction attacks on CNNs assume that the network architecture is known, and try to recover model parameters. In this paper, we prove for the first time that the architecture assumption can be removed for CNNs with both max and average pooling. Our core finding is that the spatial geometry of the weight vectors recovered by existing parameter-recovery attacks naturally leaks the architecture. We formalize this geometry and establish its correspondence with the architectural knowledge of a convolutional layer: (1) The sparsity consistency with the convolution receptive field reveals the layer type, the kernel size, and the stride; (2) The numerical consistency with the kernel parameters reveals the padding mode and the output-channel number; (3) The structural consistency with the pooling operation reveals the pooling type, the window size, and the stride. Although the recovered vectors are obtained using different methods in the raw-output and hard-label settings, their spatial geometry remains the same. Therefore, our architecture recovery is feedback-agnostic: combined with a parameter-recovery attack, it yields a complete cryptanalytic extraction framework that recovers both the architecture and the parameters in the black-box setting. Extensive experiments, including both layer-wise and end-to-end ones, on a wide range of CNNs demonstrate that simultaneously recovering the network architecture and the model parameters is practical.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Cryptanalytic ExtractionConvolutional Neural NetworksNetwork Architecture Recovery
Contact author(s)
jiashuoliu @ 126 com
marj21 @ mails tsinghua edu cn
limanman15 @ 163 com
chenyi2023 @ tsinghua edu cn
chenshaozhen @ vip sina com
History
2026-09-25: approved
2026-09-22: received
See all versions
Short URL
https://ia.cr/2026/2161
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2161,
      author = {Jiashuo Liu and Ruijie Ma and Manman Li and Yi Chen and Shaozhen Chen},
      title = {Extracting {CNNs} in the Unknown-Architecture and Feedback-Agnostic Setting},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2161},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2161}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.