First cryptanalytic extraction of neural networks without knowing their architecture
chaumian · x · 2026-09-15
Tsinghua researchers (including Xiaoyun Wang) present the first cryptanalytic extraction attack that recovers both architecture and parameters of ReLU fully connected networks with black-box access only. Their guess-and-determine framework exploits two architecture-sensitive traces — a zero suffix in merged weight vectors and an equality pattern in preimage-based sign recovery — plus two criteria for identifying the second-to-last layer to terminate guessing. End-to-end attacks work across expansive and non-expansive architectures.
More from Safety
- Cisco's VLoc Bench: even GPT-5.5 hits only 0.221 F1 at repo-scale vulnerability localization — aminkarbasi · 2026-09-15
- AistyMCP: open-source per-tool permissions for MCP servers, deny-by-default — iamjoehoward · 2026-09-15
- Anthropic co-founder backs mandatory AI 'kill switch'; commenter says make it law — srimisra · 2026-09-15
- Rejecting today's AI is demanding better tech, not resisting technology, argues philosopher — CarissaVeliz · 2026-09-15
- Lawmaker proposes one-month global AI safety stand-down to set red lines — DavidSKrueger · 2026-09-15
- User claims Claude Artifacts silently uploads drafts to cloud with toggle locked — maier_ak · 2026-09-15