LATIDIA · Ciberseguridad
Extracción criptoanalítica de redes neuronales sin suposición de arquitectura conocida
arXiv:2609.14379v1 Announce Type: new Resumen: Los ataques de extracción criptoanalítica recuperan los parámetros de una red neuronal dado solo acceso de caja negra a su salida sin procesar. Sin embargo, todos los ataques existentes se basan en un fundamento
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.14379v1 Announce Type: new Abstract: Cryptanalytic extraction attacks recover the parameters of a neural network given only black-box access to its raw output. However, all existing attacks rely on a fundamental assumption: the attacker knows the network architecture. For example, regarding ReLU activation-based fully connected networks, the network depth and the dimension of each hidden layer are known. In this paper, we study whether this assumption can be removed. We focus on ReLU fully connected networks and propose a guess-and-determine framework that recovers the architecture and the parameters jointly. The core of our approach is a simple but powerful observation: dimension guessing leaves architecture-sensitive traces in the parameter recovery process.