Paper 2026/848

Cryptanalytic Extraction of Neural Networks for Privacy-Preserving Machine Learning

Wen Zhang, Zhejiang University
Bingsheng Zhang, Zhejiang University
Tianpei Lu, Zhejiang University
Kui Ren, Zhejiang University
Abstract

Since Carlini et al. (CRYPTO'20) introduced a black-box neural network extraction method inspired by differential cryptanalysis, cryptanalytic model extraction has been extensively studied. Existing methods, however, still face three bottlenecks. \begin{itemize} \item First, these methods are largely confined to contractive architectures and generally do not extend to expansive networks because of rank deficiency. We classify the regimes for single-point and multi-point recovery and mitigate this limitation through projection-based aggregation in the multi-point case. \item Second, prior attacks fundamentally exploit the non-differentiability of activations such as ReLU. Asselineau et al. (CRYPTO'26) recently extended cryptanalytic extraction to a broad class of nonlinear activations, but their approach requires high numerical precision and may recover only a subset of the parameters. We show that privacy-preserving machine learning (PPML) unintentionally introduces a new attack surface: fixed-point arithmetic over finite rings induces silent modular wraparound, creating observable discontinuities even when the underlying activation is smooth. Exploiting these discontinuities, we recover all parameters of networks with smooth activations at much lower precision than prior work. \item Third, Neuron Wiggle, a widely used sign-recovery technique, is suboptimal. We recast it as a unified paradigm and analyze it from a signal-detection perspective. We prove that when the downstream coefficients are Gaussian, or the network is sufficiently wide, there exists an optimal probing direction, and the resulting method outperforms the original algorithm. \end{itemize} We evaluate our attack on eight CIFAR-10 DNNs and eight expansive networks with different activation functions. The attack extracts all parameters of expansive networks with smooth, unbounded activations. Our sign-recovery method further attains \(100\%\) accuracy on our benchmark while reducing the number of queries by \(30\%\)--\(74\%\) relative to Neuron Wiggle.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Model ExtractionPrivacy-Preserving Machine LearningExpansive Neural NetworkSmooth Activation Function
Contact author(s)
12421200 @ zju edu cn
bingsheng @ zju edu cn
lutianpei @ zju edu cn
kuiren @ zju edu cn
History
2026-09-17: last of 4 revisions
2026-04-30: received
See all versions
Short URL
https://ia.cr/2026/848
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/848,
      author = {Wen Zhang and Bingsheng Zhang and Tianpei Lu and Kui Ren},
      title = {Cryptanalytic Extraction of Neural Networks for Privacy-Preserving Machine Learning},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/848},
      year = {2026},
      url = {https://eprint.iacr.org/2026/848}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.