First cryptanalytic extraction of neural networks without knowing their architecture

chaumian · x · 2026-09-15

Tsinghua researchers (including Xiaoyun Wang) present the first cryptanalytic extraction attack that recovers both architecture and parameters of ReLU fully connected networks with black-box access only. Their guess-and-determine framework exploits two architecture-sensitive traces — a zero suffix in merged weight vectors and an equality pattern in preimage-based sign recovery — plus two criteria for identifying the second-to-last layer to terminate guessing. End-to-end attacks work across expansive and non-expansive architectures.

Original post →

More from Safety

Safety channel →