arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.08030cs.CR

针对带最大池化的卷积神经网络的代数攻击

Algebraic Attack on Convolutional Neural Networks with Max Pooling

Zirui Chen, Shi Tang, Zhengchao Gao, Yongjia Su, Lingyue Qin, Xiaoyang Dong

首次发表
浏览论文内容

中文总结 AI 辅助

本文针对带最大池化的卷积神经网络,提出首个代数参数提取攻击,通过识别新型临界点结合互补技术实现高效高精度提取,在多种CNN架构上验证了攻击的有效性,填补了CNN安全研究空白。

中文摘要 AI 辅助

通过黑盒输入输出查询恢复深度神经网络(DNN)的权重和偏置,这类参数提取攻击已被广泛研究用于基于ReLU的全连接神经网络(FCNN),但针对带最大池化函数的卷积神经网络(CNNs)的相关研究仍未被探索,而最大池化是计算机视觉和多媒体处理的核心架构。关键挑战在于CNN的最大池化层,其引入了额外的非线性并隐藏了ReLU临界点,使得现有的FCNN提取方法无法应用。为解决这一空白,我们提出了首个针对带最大池化函数的CNN的密码分析提取攻击。首先,我们建立了CNN的代数表示,正式证明CNN是分段线性函数,可扩展基于线性性的提取原理。随后,我们识别出CNN中两种新型临界点:ReLU-池化临界点(RPCPs)和池化切换点(PSPs)。我们设计了互补的提取技术:针对RPCP的模式匹配方法以恢复部分特征和符号,以及受密码学内部差分分析启发的针对PSP的内部差分提取攻击,以恢复高精度特征。鉴于PSP的数量远多于RPCP且能实现高效提取,且RPCP对于偏置恢复不可或缺,我们整合两种方法:PSP方法实现高效特征提取,而单个RPCP可恢复符号和偏置。我们在多种CNN架构上评估了我们的攻击,包括在随机数据、MNIST和CIFAR-10上训练的LeNet-5的现代变体。实验结果表明,我们的方法即使针对深层CNN层也能以多项式查询复杂度和运行时间实现高提取精度。本研究填补了CNN安全领域的研究空白。

英文摘要

Recovering the weights and biases of deep neural networks (DNNs) via black-box input-output queries, known as parameter extraction attacks, has been extensively studied for ReLU-based fully connected neural networks (FCNNs), but remains unexplored for convolutional neural networks (CNNs) with the max pooling function, a core architecture for computer vision and multimedia processing. The key challenge lies in the CNN max pooling layer, which introduces an additional non-linearity and hides ReLU critical points, rendering existing FCNN extraction methods inapplicable. To address this gap, we propose the first cryptanalytic extraction attack tailored for CNNs with the max pooling function. First, we establish an algebraic representation of CNNs, formally proving that CNNs are piecewise linear functions enabling the extension of linearity-based extraction principles. We then identify two novel types of critical points in CNNs: ReLU-Pooling Critical Points (RPCPs) and Pooling Switching Points (PSPs). We design complementary extraction techniques: a pattern matching method for RPCPs to recover partial signatures and signs, and an internal differential extraction attack for PSPs, inspired by cryptographic internal differential analysis, to recover high-accuracy signatures. Given that PSPs are far more abundant than RPCPs and yield a highly efficient extraction method, and that RPCPs are indispensable for bias recovery, we integrate both methods: the PSP method enables efficient signature extraction, while a single RPCP recovers the sign and bias. We evaluate our attack on multiple CNN architectures, including modern adaptations of LeNet-5, trained on random data, MNIST, and CIFAR-10. Experimental results demonstrate that our approach achieves high extraction accuracy with polynomial query complexity and runtime, even for deep CNN layers. This work fills a research gap in CNN security.

↑