float32 evaluation can break cryptanalytic neural-network parameter extraction attacks
chaumian · x · 2026-09-14
Researchers from Xidian University and NTU published an IACR paper studying cryptanalytic model extraction — recovering neural-network parameters from black-box oracle access — under finite-precision evaluation.
- Prior attacks assume float64-precision targets, mismatching deployed float32-or-lower models.
- The paper decomposes recovery into numerical subproblems (critical-point localization, finite-difference estimation, solving perturbed linear systems) and traces how errors propagate and amplify, linking this to local linear-region geometry and parameter-gradient sensitivity.
- Key finding: at float32, oracle-induced perturbations cannot be removed by higher-precision downstream computation, causing a much higher local error floor; recovery also grows less stable as networks scale up.
- The framework extends to hard-label recovery and piecewise-affine components; smooth activations need curvature-aware error modeling.
More from Safety
- China Frames Calls to Slow Frontier AI as a 'Cold War' Strategy to Preserve US Dominance — TansuYegen · 2026-09-14
- Critics warn EA-backed third-party AI audits would give safety committees sweeping powers — beffjezos · 2026-09-14
- User alert reveals Suno data breach from November 2025 that was never announced — ChrisUniverse · 2026-09-14
- Csaba Szepesvari: Enforce Good Old Security Practices Alongside AI Safety Evals — CsabaSzepesvari · 2026-09-14
- AgentChaos: Open-Source Harness Tests Prompt Injection via MCP Tool Results — DiscussionHealthy802 · 2026-09-14
- The AI safety paradox: pausing algorithms while compute piles up could maximize risk — tszzl · 2026-09-14