arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.18751cs.CR

法线对齐:硬标签网络上改进的密码分析符号恢复

Normal Alignment: Improved Cryptanalytic Sign Recovery on Hard-Label Networks

Shi Tang, Zirui Chen, Yongjia Su, Zhengchao Gao, Lingyue Qin, Xiaoyang Dong

首次发表
浏览论文内容

中文总结 AI 辅助

针对硬标签DNN符号恢复中深层错误预测导致指数枚举的问题,提出法线对齐统计方法,结合eSOE实现多项式时间完整符号恢复,在CIFAR-10和MNIST上验证有效性。

中文摘要 AI 辅助

在EUROCRYPT 2025上,Carlini等人提出了硬标签(S1)深度神经网络(DNN)密码分析提取的突破性进展,展示了多项式时间的签名和符号恢复。然而,Carlini等人的符号恢复方法(我们称之为Future Toggle)相比随机猜测仅具有微弱的优势,在更深层中会产生高置信度的错误符号预测。此类错误会触发昂贵的指数时间枚举。本工作提出了Normal Alignment,一种针对S1 DNN的新型统计符号恢复方法。利用对偶点处相邻决策面的投影法线之间的预期长度差异,我们的方法通过法线签名对齐来推断神经元符号。它提供了更高的投票准确率,并将错误预测推至低置信度排名,这进一步通过将Normal Alignment与硬标签SOE扩展相结合,实现了更高效的组合方法eSOE + Alignment。该组合策略消除了繁重的枚举开销,并实现了精确的多项式时间完整符号恢复。实验证明了我们方法的有效性,尤其是在深层。例如,使用我们的方法,CIFAR-10(架构192-64$\ imes$8-10)和MNIST(架构64-96$\ imes$3-32-10)模型的符号可以在多项式时间内完全恢复;相比之下,Carlini等人的符号恢复方法需要分别涉及$2^{52}$或$2^{82}$次符号猜测的指数时间枚举。

英文摘要

At EUROCRYPT 2025, Carlini et al. proposed a breakthrough in the cryptanalytic extraction on hard-label (S1) deep neural networks (DNNs), demonstrating polynomial-time signature and sign recovery. However, Carlini et al.'s sign-recovery method (which we call Future Toggle) suffers only a marginal advantage over random guessing, producing high-confidence wrong sign predictions in deeper layers. Such errors trigger expensive exponential-time enumeration. This work presents Normal Alignment, a novel statistical sign-recovery approach for S1 DNNs. Drawing on the expected length difference between projected normals of adjacent decision facets at dual points, our method infers neuron signs via normal-signature alignment. It delivers higher voting accuracy and pushes erroneous predictions to low-confidence ranks, which further enables a more efficient combined method, eSOE + Alignment, by combining Normal Alignment with the hard-label SOE extension. This combined strategy removes heavy enumeration overhead and realizes exact polynomial-time full sign recovery. Experiments demonstrate the effectiveness of our method, especially for deep layers. For example, with our method, the signs for CIFAR-10 (architecture 192-64$\times$8-10) and MNIST (architecture 64-96$\times$3-32-10) models can be fully recovered in polynomial time; in contrast, Carlini et al.'s sign-recovery method would require exponential-time enumerations involving $2^{52}$ or $2^{82}$ guesses of the signs, respectively.

发表机构

  • Shandong University(山东大学)
  • Tsinghua University(清华大学)

机构由 AI 辅助整理,请以论文原文为准。

↑