arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.21615cs.CR

隐藏方向,泄露结构:通过低秩结构破解ArrowCloak

Hiding Directions, Leaking Structure: Breaking ArrowCloak through Low-Rank Structure

Beijie Liu, Junyi Ouyang, Haoxuan Xu, Vincent Quentin Ulitzsch, Potung Yu, Yajie Zhao, Mengyuan Li

首次发表
浏览论文内容

中文总结 AI 辅助

本文从密码学与结构角度分析并破解了轻量级防御方案ArrowCloak,提出无查询攻击可高准确率恢复其权重,证明其存在结构漏洞,为轻量级保护设计提供了新方向。

中文摘要 AI 辅助

TEE(可信执行环境)屏蔽推理将敏感状态保存在可信执行环境中,同时将线性代数运算卸载到不可信的加速器上。Wang等人在《Game of Arrows》(USENIX Security 2025)中指出,五种广泛采用的轻量级防御措施会保留向量方向,并提出ArrowMatch来利用这种泄露;随后他们提出ArrowCloak,该方法为每个向量添加一个共享掩码方向的不同倍数,并基于带错误学习(LWE)来论证其权重恢复的难度。ArrowCloak成功将ArrowMatch降低到接近黑盒水平。本文从密码学和结构角度重新审视ArrowCloak:其LWE公式本身并未确立标准LWE难度,归约方向、量化算术和联合实例分布均不满足所需条件;复用一个掩码方向会在释放的矩阵中留下可恢复的秩1分量,我们利用该结构提出了一种端到端、无查询的恢复攻击。给定公开检查点和混淆后的权重,该攻击可移除掩码子空间、恢复隐藏的一一对应关系,并在无需变换秘密、受害者查询或微调数据的情况下重构受保护权重。在涵盖分类、分割和扩散的6个模型-任务对上,该攻击可恢复99.92%-100%的隐藏向量对应关系;重构的分类模型达到94.39%-99.54%的受害者一致性,准确率差异最多为1.59个百分点;恢复的分割模型达到98.35%的输出一致性。这些发现表明,轻量级保护应同时解决每个向量的几何特性和释放权重间的联合结构问题。

英文摘要

TEE-shielded inference keeps sensitive state in a trusted execution environment (TEE) while offloading linear algebra to an untrusted accelerator. Wang et al., in Game of Arrows (USENIX Security 2025), showed that five widely adopted lightweight defenses preserve vector directions and introduced ArrowMatch to exploit this leakage. They then proposed ArrowCloak, which adds a different multiple of one shared mask direction to each vector and bases its weight-recovery hardness argument on Learning with Errors (LWE). ArrowCloak successfully reduces ArrowMatch to near-black-box levels. In this paper, we revisit ArrowCloak from cryptographic and structural perspectives. Its LWE formulation does not by itself establish standard LWE hardness: the reduction direction, quantized arithmetic, and joint instance distribution do not meet the required conditions. Reusing one mask direction leaves a recoverable rank-one component across the released matrix. We exploit this structure with our proposed attack, an end-to-end, query-free recovery attack. Given a public checkpoint and the obfuscated weights, the attack removes the masking subspace, recovers the hidden one-to-one correspondence, and reconstructs protected weights without transformation secrets, victim queries, or fine-tuning data. Across six model-task pairs spanning classification, segmentation, and diffusion, the attack recovers 99.92%-100% of hidden vector correspondences. Reconstructed classification models achieve 94.39%-99.54% victim agreement and differ by at most 1.59 percentage points in accuracy; the recovered segmentation model achieves 98.35% output agreement. These findings suggest that lightweight protection should address both per-vector geometry and joint structure across released weights.

补充信息

↑