LATIDIA · Ciberseguridad
Extracción de CNN en un entorno de arquitectura desconocida e independiente de la retroalimentación.
arXiv:2609.27427v1 Anuncio Tipo: nuevo Resumen: Este artículo estudia la extracción criptoanalítica de redes neuronales convolucionales (CNN). Los ataques de extracción criptoanalítica existentes en CNN asumen que el arquitecto de la red
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.27427v1 Announce Type: new Abstract: This paper studies the cryptanalytic extraction of convolutional neural networks (CNNs). Existing cryptanalytic extraction attacks on CNNs assume that the network architecture is known, and try to recover model parameters.In this paper, we prove for the first time that the architecture assumption can be removed for CNNs with both max and average pooling. Our core finding is that the spatial geometry of the weight vectors recovered by existing parameter-recovery attacks naturally leaks the architecture. We formalize this geometry and establish its correspondence with the architectural knowledge of a convolutional layer: (1) The sparsity consistency with the convolution receptive field reveals the layer type, the kernel