Paper 2026/296

Navigating the Deep: End-to-End Extraction on Deep Neural Networks

Haolin Liu, Nanyang Technological University, Singapore and Shanghai Jiao Tong University, China
Adrien Siproudhis, Nanyang Technological University, Singapore
Samuel Experton, Université Paris Cité, France
Peter Lorenz, Nanyang Technological University, Singapore
Christina Boura, Université Paris Cité, France
Thomas Peyrin, Nanyang Technological University, Singapore
Abstract

Neural network model extraction has recently emerged as an important security concern, as adversaries attempt to recover a network’s parameters via black-box queries. Carlini et al. proposed in CRYPTO’20 a model extraction approach inspired by differential cryptanalysis, consisting of two steps: signature extraction, which extracts the absolute values of network weights layer by layer, and sign extraction, which determines the signs of these signatures. However, in practice this signature-extraction method is limited to very shallow networks only, and the proposed sign-extraction method is exponential in time. Recently, Canales-Martínez et al. (Eurocrypt’24) proposed a polynomial-time sign-extraction method, but it assumes the corresponding signatures have already been successfully extracted and can fail on so-called low-confidence neurons. In this work, we first revisit and refine the signature extraction process by systematically identifying and addressing for the first time critical limitations of Carlini et al.'s signature-extraction method. These limitations include rank deficiency and noise propagation from deeper layers. To overcome these challenges, we propose efficient algorithmic solutions for each of the identified issues, greatly improving the capabilities of signature extraction. Our approach permits the extraction of much deeper networks than previously possible. In addition, we propose new methods to improve numerical precision in signature extraction, and enhance the sign extraction part by combining two polynomial methods to avoid exponential exhaustive search in the case of low-confidence neurons. This leads to the very first end-to-end model extraction method that runs in polynomial time. We validate our attack through extensive experiments on ReLU-based neural networks, demonstrating significant improvements in extraction depth. For instance, our attack extracts consistently at least eight layers of neural networks trained on either the MNIST or CIFAR-10 datasets, while previous works could barely extract the first three layers of networks of similar width. Our results represent a crucial step toward practical attacks on larger and more complex neural network architectures.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
A major revision of an IACR publication in EUROCRYPT 2026
Keywords
ReLU-based neural networkssignature extractionweight-recoverysign extractionend-to-end attack
Contact author(s)
hliu033 @ e ntu edu sg
sipr0001 @ e ntu edu sg
samuel experton @ gmail com
peter lorenz work @ gmail com
christina boura @ irif fr
thomas peyrin @ ntu edu sg
History
2026-02-18: approved
2026-02-18: received
See all versions
Short URL
https://ia.cr/2026/296
License
Creative Commons Attribution-NonCommercial
CC BY-NC

BibTeX

@misc{cryptoeprint:2026/296,
      author = {Haolin Liu and Adrien Siproudhis and Samuel Experton and Peter Lorenz and Christina Boura and Thomas Peyrin},
      title = {Navigating the Deep: End-to-End Extraction on Deep Neural Networks},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/296},
      year = {2026},
      url = {https://eprint.iacr.org/2026/296}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.