Skip to content

Latest commit

 

History

10 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Neural-network and block-cipher structural analogy

Awesome Cryptanalytic Extraction

A curated bibliography of cryptanalytic neural-network extraction, structural and parameter recovery, reproducibility code, limitations, and defenses.

中文版 · September progress · Search audit · BibTeX · Machine-readable catalog · Stage comparisons · Original code collection

Updated 2026-09-30 · 52 unique works · 13 categories. Includes preprints, selected adjacent theory, two surveys, and one explicitly labeled course report. This is a broad, source-checked collection, not a claim of exhaustive coverage of all model stealing.

Recent Developments

Source status: ePrint 2026/1025 was withdrawn on September 19. Its historical method is retained and labeled. The comparison covers all 52 records and separates stage costs, oracle assumptions and experimental scope.

Scope and Reading Guide

The cryptanalytic analogy treats weights as hidden parameters and inputs as chosen queries. Differential, geometric or algebraic leakage can expose more than ordinary test-set imitation. It is an analogy, not an assertion that a network is a secure cipher.

  1. Start with foundations, then CRYPTO 2020, EUROCRYPT 2024 and the raw-output improvements.
  2. Read hard-label extraction together with its partial-layer and polynomiality limitations.
  3. Compare CNN/pooling, activation, RNN/GNN and attention results under their exact oracle assumptions.
  4. Read finite precision and defenses before treating an idealized recovery theorem as a deployable attack.
  5. Use related theory, partial LLM extraction and side-channel work as explicitly separated context, not interchangeable threat models.
Axis Distinctions to retain
Oracle Raw real-valued outputs; probabilities/top-k scores; top-1 label only; explanations; physical leakage
Recovery Architecture; signature up to scale/sign; oriented parameters; canonical equivalent function; partial block; whole executable model
Assumptions Known structure; generic position; identifiable neurons; chosen continuous inputs; finite precision; access to intermediate blocks
Evidence Theorem under stated assumptions; query count; wall-clock time; sampled fidelity; parameter error; certified equivalence

Catalog Conventions

¹ Year is the archive/report year; venue year is shown separately. Revised titles and cross-listed ePrint/arXiv versions count once. Linked PDFs are archive copies, not necessarily publisher-final layouts. Versions, page counts and SHA-256 hashes of the reviewed PDFs are in the JSON catalog.

² Code means an author/paper-linked repository unless labeled otherwise. 404 means unavailable at checking time, not proof of deletion; anonymous 410 means the service reports expiration. Supplementary code, author forks and reading resources are distinguished from complete attack implementations. Not located means no usable author-linked URL was found, not that no code exists. Accessibility checks are not execution or reproduction of results.

Paper Catalog

Foundations (3)

Year¹ Paper and PDF Venue / status Oracle / architecture Recovery target and limits Code²
2019 Reverse-Engineering Deep ReLU Networks · PDF ICML 2020 Real-valued queries
Deep ReLU
Boundary geometry recovers structure and parameters up to network symmetries under assumptions. Not located
2019 High Accuracy and High Fidelity Extraction of Neural Networks · PDF USENIX Security 2020 Raw outputs / prediction queries
Shallow and deep NN
Separates accuracy from fidelity; functional-equivalent shallow recovery and hybrid attacks. Not located
2016 Stealing Machine Learning Models via Prediction APIs · PDF USENIX Security 2016 Prediction scores / labels
Classical ML / shallow NN
Equation-solving and early API extraction; not general deep exact recovery. Official

Raw-Output ReLU Extraction (7)

Year¹ Paper and PDF Venue / status Oracle / architecture Recovery target and limits Code²
2026 Navigating the Deep: End-to-End Extraction on Deep Neural Networks · PDF EUROCRYPT 2026 Raw outputs
Deep ReLU MLP
End-to-end extraction with techniques for deeper-layer recovery. Official
2026 Polynomial Time Cryptanalytic Extraction of Deep Neural Networks in the Limited Architecture Knowledge Setting · PDF Preprint Raw logits; limited architecture knowledge
ReLU MLP; approximate total neuron count assumed
Detects omitted neurons and backtracks parameter recovery; rough size knowledge remains necessary. Overall runtime/query costs are not reported. Paper-linked placeholder repository
2026 Geometric Critical Point Screening: Clustering-Free Cryptanalytic Extraction of Neural Network Models · PDF Withdrawn preprint; 2026-09-19 Raw outputs
ReLU networks
Historical geometric screening of early-layer signatures; withdrawn September 19, 2026. Retained for the historical record, not a current unretracted result. Official
2026 Cryptanalytic Extraction of Neural Networks Without Known Architecture Assumption · PDF Preprint Raw outputs; architecture unknown
ReLU fully connected networks
Guess-and-determine jointly recovers architecture and parameters; not arbitrary CNN/Transformer recovery. Not located
2024 Beyond Slow Signs in High-fidelity Model Extraction · PDF NeurIPS 2024 Raw outputs
ReLU MLP
Practical sign-recovery improvements; distinguish runtime from query count. Official
2023 Polynomial Time Cryptanalytic Extraction of Neural Network Models · PDF EUROCRYPT 2024 Raw outputs
ReLU MLP
Polynomial-time sign recovery improves the original cryptanalytic pipeline. Official
2020 Cryptanalytic Extraction of Neural Network Models · PDF CRYPTO 2020 Raw outputs
ReLU MLP
Differential critical-point extraction; signatures, signs and final parameter recovery. Official

Hard-Label Extraction (7)

Year¹ Paper and PDF Venue / status Oracle / architecture Recovery target and limits Code²
2026 Algebraic Cryptanalytic Extraction on Hard-Label Neural Networks · PDF Preprint Top-1 label only
FCNN / max-pooling CNN
NRC/ASV accelerates offline clustering with conditional average and worst-case bounds; experiments recover signatures including CNN kernels, not all signs/biases/output layers. Announced; placeholder URL
2026 End-to-End Hard-Label Cryptanalytic Model Extraction Using Efficient Sign Recovery · PDF Preprint Top-1 label only; known architecture
Trained ReLU MLP; width 16, four/six hidden layers
Cosine/projection sign recovery reuses intersection spaces; no dedicated queries applies to that stage. End-to-end sampled label agreement excludes dead/almost-dead neurons and does not certify exact equivalence. Not located
2026 Normal Alignment: Improved Cryptanalytic Sign Recovery on Hard-Label Networks · PDF Preprint Top-1 label only; sign-recovery stage
Deep ReLU MLP
Normal-signature alignment plus eSOE recovers 512/512 and 320/320 signs in the reported models; sign recovery, not a demonstrated complete end-to-end attack. Announced; placeholder URL
2025 Is the Hard-Label Cryptanalytic Model Extraction Really Polynomial? · PDF CRYPTO 2026 Top-1 label only
ReLU MLP
Persistent/dead neurons challenge polynomiality claims; cross-layer extraction addresses limitations. Paper-linked; 404
2025 Extracting Some Layers of Deep Neural Networks in the Hard-Label Setting · PDF LATINCRYPT 2025 Top-1 label only
ReLU MLP
Partial/output-layer recovery under structural conditions, not unrestricted end-to-end extraction. Official
2024 Polynomial Time Cryptanalytic Extraction of Deep Neural Networks in the Hard-Label Setting (Extended Version) · PDF EUROCRYPT 2025; extended version Top-1 label only
Deep ReLU MLP
Dual-point signatures/signs; extended version includes a small random-model black-box end-to-end demonstration, distinct from white-box-assisted CIFAR experiments. Official
2024 Hard-Label Cryptanalytic Extraction of Neural Network Models · PDF ASIACRYPT 2024 Top-1 label only
ReLU MLP
Label-only cryptanalytic extraction from decision-boundary geometry. Official

CNN and Pooling (5)

Year¹ Paper and PDF Venue / status Oracle / architecture Recovery target and limits Code²
2026 End-to-End Polynomial-Time Cryptanalytic Extraction of Convolutional Neural Networks in the Hard-Label Setting · PDF Preprint Top-1 label only
Average-pooling CNN; known architecture
End-to-end pipeline; retained-candidate and structural assumptions remain material. Anonymous attachment
2026 Model Extraction of Convolutional Neural Networks with Max-Pooling · PDF ToSC 2026 Raw outputs
Max-pooling CNN
Pooling-aware extraction and receptive-field structure. Official
2026 Algebraic Attack on Convolutional Neural Networks with Max Pooling · PDF CRYPTO 2026 Raw outputs
Max-pooling CNN
Algebraic extraction handles pooling switches; raw-output results do not automatically transfer to label-only access. Paper-linked; 404
2026 Cryptanalytic Extraction of Convolutional Neural Networks · PDF ACISP 2026 Top-1 label only
Average-pooling CNN
Uses convolutional structure for kernel recovery. Expired; 410
2026 Extracting CNNs in the Unknown-Architecture and Feedback-Agnostic Setting · PDF Preprint Raw outputs / top-1 labels; architecture unknown
Max-/average-pooling CNN
Spatial geometry of recovered vectors reveals convolution/pooling structure; inherits upstream parameter-recovery assumptions. Two-convolution end-to-end and three-convolution layer-wise results do not establish arbitrary CNN hard-label recovery. Not located

Activation Extensions (4)

Year¹ Paper and PDF Venue / status Oracle / architecture Recovery target and limits Code²
2026 Cryptanalytic Extraction of Deep Neural Networks with Non-Linear Activations · PDF CRYPTO 2026 Raw outputs
Smooth/non-linear activations
Higher-order/near-linear geometry enables recovery for studied non-linear activations; not every smooth function. Official
2026 Cryptanalytic Extraction of Neural Networks with Various Activation Functions · PDF ToSC 2026 Raw outputs / hard labels (variant-dependent)
PReLU / LeakyReLU / HardTanh / Step
Extends extraction to several activation families; oracle assumptions differ by variant. Official
2026 Breaking Slope and Structure Restrictions: Broadening Hard-Label Cryptanalytic Extraction of PReLU Neural Networks · PDF Preprint Top-1 label only
PReLU
Broadens allowable slopes and architectures for hard-label extraction. Not located
2025 Delving into Cryptanalytic Extraction of PReLU Neural Networks · PDF ASIACRYPT 2025 Raw outputs / top-m probabilities
PReLU
Recovers PReLU parameters under stated conditions; not a label-only result. Official

RNN and GNN (2)

Year¹ Paper and PDF Venue / status Oracle / architecture Recovery target and limits Code²
2026 Polynomial-Time Cryptanalytic Extraction of Graph Neural Networks in the Hard-Label Setting · PDF Preprint Top-1 label only
Message-passing GNN
Graph/message-passing structure supports extraction under the stated model. Official
2026 Cryptanalytic Extraction of Recurrent Neural Network Models · PDF Preprint Raw outputs / top-1 labels
RNN
Exploits recurrence; long unrollings share weights and are not independent deep layers. Not located

Attention and GLU Blocks (4)

Year¹ Paper and PDF Venue / status Oracle / architecture Recovery target and limits Code²
2026 Cryptanalytic Extraction of Multi-Head Softmax Attention Models · PDF Preprint Raw outputs / chosen continuous inputs
Multi-head softmax attention
Recovers a canonical equivalent representation; Q/K/V factors have gauge ambiguity. Not located
2026 Cryptanalytic Extraction of Isolated Bias-Free GLU Feed-Forward Blocks by Antipodal Separation · PDF Preprint Direct queries to an isolated block
Bias-free GLU FFN
Antipodal separation for isolated blocks; not extraction of a complete LLM through its token API. Not located
2026 Provably Learning Multi-Head Attention with Queries · PDF Preprint Chosen real-valued queries
Multi-head attention / restricted one-layer Transformer
Canonical head recovery; additional assumptions for the Transformer extension. Not located
2026 Provably Learning Attention with Queries · PDF ICML 2026 Chosen real-valued queries
Attention
Query-learning guarantees under attention-model assumptions. Not located

Partial LLM and Output-Space Extraction (2)

Year¹ Paper and PDF Venue / status Oracle / architecture Recovery target and limits Code²
2024 Logits of API-Protected LLMs Leak Proprietary Information · PDF COLM 2024 Logprobs / restricted API
LLM output subspace
Softmax bottleneck reveals hidden dimension and output-space information, not full-network recovery. Not located
2024 Stealing Part of a Production Language Model · PDF ICML 2024 Restricted logprobs / logit-bias API
LLM output projection
Partial projection recovery up to symmetries, not all model weights; released code is supplementary. Official supplementary

PPML and Stronger Side-Channel Oracles (5)

Year¹ Paper and PDF Venue / status Oracle / architecture Recovery target and limits Code²
2026 Cryptanalytic Extraction of Neural Networks for Privacy-Preserving Machine Learning · PDF Preprint Finite-ring/fixed-point inference; variants include top-1 + probability
PPML neural inference
Revised Sep 17: multi-point projection aggregation for expansive networks and optimal sign probes; reports 30%-74% fewer sign-recovery queries than Neuron Wiggle on its benchmark, not a universal reduction or encryption break. Anonymous attachment
2025 Activation Functions Considered Harmful: Recovering Neural Network Weights through Controlled Channels · PDF Preprint SGX controlled channels
DNN activation implementation
Activation-access leakage supports weight recovery; first-layer and deeper-layer outcomes differ. Official
2024 A Divide-and-Conquer Strategy for Hard-Label Extraction of Deep Neural Networks via Side-Channel Attacks · PDF TCHES 2026; revised title Top-1 labels + side channel
Deep NN / non-FC components
Divide-and-conquer with physical leakage; stronger than black-box label access. Official
2020 SNIFF: Reverse Engineering of Neural Networks with Fault Attacks · PDF Preprint / IEEE Transactions on Reliability Fault injection + outputs
Neural networks
Sign-bit fault attacks use a stronger attacker than ordinary API queries. Not located
2018 CSI Neural Network: Using Side-channels to Recover Your Artificial Neural Network Information · PDF USENIX Security 2019; published title differs Power / EM side channels
Embedded neural networks
Architecture/parameter leakage via physical observations; selected historical context. Not located

Finite Precision and Feasibility (1)

Year¹ Paper and PDF Venue / status Oracle / architecture Recovery target and limits Code²
2026 Finite-Precision Error Analysis of Cryptanalytic Model Extraction · PDF Preprint; ASIACRYPT 2026 acceptance author-listed Finite-precision raw outputs
Cryptanalytic signature recovery
Quantifies numerical error in extraction primitives; neither universal impossibility nor a proven generic defense. Paper-linked; 404

Defenses and Adaptive Evaluations (2)

Year¹ Paper and PDF Venue / status Oracle / architecture Recovery target and limits Code²
2026 Output Rounding Is Not a Free Defense Against Cryptanalytic Neural Network Extraction · PDF MIT 6.5610 Spring 2026 course report Rounded raw outputs
Small ReLU MLP
Step-spacing adapts to rounding; empirical small-model evidence, not a universal security threshold. Supplement mentioned; URL not located
2025 Train to Defend: First Defense Against Cryptanalytic Neural Network Parameter Extraction Attacks · PDF NeurIPS 2025 Defense against parameter extraction
ReLU MLP
Training-time neuron-similarity regularization; evaluate against adapted attacks. Official

Related Identifiability and Learning Theory (8)

Year¹ Paper and PDF Venue / status Oracle / architecture Recovery target and limits Code²
2025 Data Augmentation Techniques to Reverse-Engineer Neural Network Weights from Input-Output Queries · PDF UniReps 2025 workshop Input-output queries
Teacher-student parameter recovery
Data augmentation improves Expand-and-Cluster; linked code is the authors' extension fork. Author extension fork
2024 Model Stealing for Any Low-Rank Language Model · PDF Preprint Conditional queries
Low-rank sequence distributions / HMM
Learns low-rank output distributions, not arbitrary Transformer weights. Not located
2024 Provably learning a multi-head attention layer · PDF STOC 2025 Random examples (not chosen queries)
Multi-head attention
Learning theory under nondegeneracy; not a practical full-model API extraction demonstration. Not located
2023 Reverse Engineering Deep ReLU Networks An Optimization-based Algorithm · PDF Preprint Input-output queries
Deep ReLU
Optimization-based reverse engineering; distinguish proposed guarantees from demonstrated scalability. Not located
2023 Expand-and-Cluster: Parameter Recovery of Neural Networks · PDF ICML 2024 Input-output samples
Neural networks
Overparameterized students plus clustering recover parameters; related to, but not the same as, differential extraction. Official
2022 Finite Sample Identification of Wide Shallow Neural Networks with Biases · PDF Preprint Finite input-output samples / queries
Wide shallow networks with biases
Identification of directions and biases under model and sampling conditions. Not located
2021 An Exact Poly-Time Membership-Queries Algorithm for Extraction a three-Layer ReLU Network · PDF ICLR 2023 Membership / real-valued queries
Three-layer ReLU
Exact polynomial-query recovery under depth/generic-position assumptions. Not located
2018 Model Reconstruction from Model Explanations · PDF FAT* 2019 Gradient/explanation oracle
Neural networks
Reconstruction with explanations uses a stronger oracle than ordinary predictions. Not located

Surveys and Reading Resources (2)

Year¹ Paper and PDF Venue / status Oracle / architecture Recovery target and limits Code²
2025 A Systematic Survey of Model Extraction Attacks and Defenses: State-of-the-Art and Perspectives · PDF Preprint survey Multiple
Multiple
Broad model-extraction survey; includes surrogate stealing outside this repository's core scope. Reading list, not attack code
2025 A Survey on Model Extraction Attacks and Defenses for Large Language Models · PDF Preprint survey Multiple LLM APIs
LLM
Contextual survey of LLM extraction and defenses; not an exact-recovery attack. Reading list, not attack code

Open Questions After These Results

  • Unknown general architectures: studied ReLU fully connected and convolution/pooling models now have architecture-recovery results. Mixed operators, residual paths, weak size priors and composition still require separate evidence.
  • Hard-label max-pooling: no longer an empty category. Robust full-layer/sign/bias recovery, winner switches and event observability should be evaluated beyond small signature-recovery demonstrations.
  • Practical precision and cost: relate numerical stability to query budgets, conditioning, rate limits, abstentions and probability truncation; do not equate real-arithmetic polynomiality with cheap extraction.
  • Identifiability: report dead/persistent neurons, equivalent parameterizations and canonicalization explicitly. A failure to recover one parameterization is not automatically security.
  • Adaptive defenses: evaluate training regularization and output modifications against adapted attacks, with utility loss and attack budget fixed. Small-model experiments do not establish universal security.
  • Composition: recovering attention, output projections or isolated GLU blocks does not establish recovery of their composition through an ordinary token API.

Contributing and Maintenance

Edit data/papers.json, including official title/authors, source, venue/status, oracle, scope limits, code provenance and PDF version fingerprint. Edit the English template or Chinese template for prose, then run:

python scripts/render_catalog.py
python scripts/render_catalog.py --check
python scripts/render_comparisons.py
python scripts/validate_comparisons.py --strict

Keep preprints and course reports visibly labeled. Prefer primary sources and author-linked code; do not vendor third-party implementations or copyrighted PDFs into this repository. A local ref corpus can use the filenames, official PDF URLs and hashes in the catalog. No code release is implied by a paper's promise to publish it.

Disclaimer

For academic research and defensive analysis on authorized models and systems. Listing a paper does not independently validate its claims or endorse an attack against a third-party service.

About

A curated bilingual list of cryptanalytic neural-network model extraction papers, code, taxonomies, and open problems.

Topics

Resources

Stars

9 stars

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages