arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

针对硬标签神经网络的代数密码分析提取

Algebraic Cryptanalytic Extraction on Hard-Label Neural Networks

Zirui Chen, Shi Tang, Zhengchao Gao, Yongjia Su, Lingyue Qin, Xiaoyang Dong

arXiv 2608.05736首次发表:更新:

发表机构

Tsinghua University; Shandong University(清华大学; 山东大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究针对硬标签神经网络的模型提取攻击计算瓶颈,提出近似签名向量(ASV)方法,将Carlini等人的几何攻击转化为代数框架,实现FCNN及带最大池化的CNN的高效参数提取,大幅提升了模型提取效率。

AI 中文摘要

尽管Carlini等人在EUROCRYPT 2025提出的硬标签场景下的最先进神经网络模型提取攻击在理论上具有多项式时间复杂度,但其双点聚类依赖奇异值分解(SVD),时间复杂度为$\u214c(n^2 \u00b7 (d^{(k)})^3)$,导致实际运行时间极长。为解决这一计算瓶颈,本研究将Carlini等人基于几何视角的硬标签攻击转化为代数框架,并提出一种新颖的近似签名向量(ASV)方法,通过利用两个关键观察结果实现全连接神经网络(FCNN)的高效参数提取:高维随机向量几乎正交,且实际深度神经网络(DNN)中的神经元倾向于学习解耦特征。所提ASV方法用简单的内积运算替代基于SVD的秩检查,将平均聚类复杂度降至$\u214c(n \u00b7 (d^{(k)})^3)$。此外,本文提出了针对硬标签最大池化卷积神经网络(CNN)的首个模型提取攻击,通过提出一种以核为中心而非以神经元为中心的高级ASV聚类方案,充分利用卷积中的权重共享特性,填补了密码分析空白。在64-64×4-10 FCNN和带最大池化的LeNet-5(CNN)上的实验表明,我们的ASV方法大幅缩短了聚类时间,并提高了模型提取的整体效率。

英文摘要

Although the state-of-the-art model extraction attack on the hard-label Fully-connected Neural Network (FCN) by Carlini et al. at EUROCRYPT 2025 has polynomial-time complexity in theory, its dual-point clustering relies on singular value decomposition (SVD) with a time complexity of $\mathcal{O}(n^2 (d^{(k)})^3)$, resulting in huge runtime in practice. To address this computational bottleneck, this work transforms Carlini et al.'s geometric-view hard-label attack into an algebraic framework, and proposes two efficient clustering methods: Normal Rank Check (NRC) and Approximate Signature Vector (ASV). The NRC and ASV methods replace Carlini et al.'s heavy SVD-based rank checking with simple rank checking or inner-product operations, reducing the clustering complexity to $\mathcal{O}(n (d^{(k)})^3)$ on average. Furthermore, this paper presents the first model extraction attack against hard-label max-pooling Convolutional Neural Networks (CNNs) by combining the ASV method with the kernel-centric clustering scheme instead of the neuron-centric clustering, which fully exploits the property of weight sharing in convolutions and fills a cryptanalysis gap. Experiments on FCNs and the max-pooling LeNet-5 demonstrate that our NRC/ASV methods drastically cut clustering time, and improve the overall efficiency in the model extraction.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑