acceptodds
Under review as a conference paper at ICLR 2027

Architecture-Agnostic Hard-Label Cryptanalytic Extraction of CNNs

Abstract

Cryptanalytic model extraction attacks aim to recover the exact weights of a neural network given only black-box access and partial architectural knowledge, posing significant risks to model confidentiality and intellectual property. Prior cryptanalytic attacks against convolutional neural networks (CNNs) have demonstrated exact recovery in the hard-label setting, but require detailed architectural knowledge, including the number, size, and types of each layer, channel counts, kernel sizes, strides, and padding. These requirements limit their applicability in realistic black-box settings. In this work, we show that such detailed architectural knowledge is not necessary by considering a significantly weaker threat model in which the attacker does not know any additional architecture knowledge besides what is necessary to query the model. Under this threat model, we develop procedures to recover convolutional hyperparameters directly from extracted weight blocks, infer channel counts, account for sequential linear layers such as average pooling and batch normalization, and extract convolutional layers that are followed by max-pool operations. Our results demonstrate that exact cryptanalytic extraction of CNNs remains feasible in this architecture agnostic setting, narrowing the gap between prior cryptanalytic extraction attacks and practical black-box extraction settings.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.