End-to-End Hard-Label Cryptanalytic Model Extraction Using Efficient Sign Recovery
The paper claims hard-label extraction can now be shown end to end against trained ReLU MLPs using only black-box label queries.
Ito, Miura, and Todo replace the costly sign-recovery step in the Eurocrypt 2025 attack with a method that needs no dedicated sign-recovery queries. In their experiments, the new step is more accurate than the existing method and works on trained models. Combined with the other extraction steps, it recovers MNIST and Fashion-MNIST models with width 16 and 4 or 6 hidden layers at over 98% label agreement. Source: ArXiv · AI/CL/LG's note.
Ito, Miura, and Todo replace the costly sign-recovery step in the Eurocrypt 2025 attack with a method that needs no dedicated sign-recovery queries. In their experiments, the new step is more accurate than the existing method and works on trained models. Combined with the other extraction steps, it recovers MNIST and Fashion-MNIST models with width 16 and 4 or 6 hidden layers at over 98% label agreement. Source: ArXiv · AI/CL/LG's note.
score 5