惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
SegmentFault 最新的问题
G
Google Developers Blog
H
Help Net Security
月光博客
月光博客
阮一峰的网络日志
阮一峰的网络日志
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
P
Proofpoint News Feed
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
B
Blog RSS Feed
爱范儿
爱范儿
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 三生石上(FineUI控件)
大猫的无限游戏
大猫的无限游戏
人人都是产品经理
人人都是产品经理
GbyAI
GbyAI
D
Docker
Hugging Face - Blog
Hugging Face - Blog
I
InfoQ
博客园 - 司徒正美
Last Week in AI
Last Week in AI
Microsoft Security Blog
Microsoft Security Blog
美团技术团队
Stack Overflow Blog
Stack Overflow Blog
M
MIT News - Artificial intelligence

Cryptology ePrint Archive

Interleaving Stability for Mutual Correlated Agreement and Curve Decodability Formalizing and Strengthening the Security Proof of NTOR Verifiable Anomaly and Similarity Detection Using Matrix Profile in Private Time-series Adaptor Signature Schemes with Deniable Presignatures Privacy Coins Under Viewing Key Compromise Adaptively-Secure Flexible and Identity-Based Broadcast Encryption from Decomposed LWE MERIDIAN: A Toroid-Inspired Permutation Block Cipher for Constrained Environments Toward Practical Fair Data Exchange: Eliminating In-Circuit Public-Key Operations Fault Injection Attacks Against zkSTARKs Scale, Round, Break: Simple Leakage Attacks on Secret Sharing Schemes Private Delegation of (Non-)Membership Proof Updates in Cryptographic Accumulators Beyond Binary: crosscorrelation of Cubic, Quartic and Quintic Character Sequences ZEE200: Zero Knowledge for Everything and Everyone @ 200 KHz A Post-Quantum Accountable Sanitizable Signature Scheme Based on Unbalanced Oil and Vinegar Better Usability: Leakage-Resistant AEADs from Single-length Blockciphers TieredOMap: Skewness-Aware Oblivious Map From Rerandtopia to Interceptopia, the Anamorphic Encryption Saga Rises Non-Adaptive Programmable PRFs and Applications to Stacked Garbling Practical Post-Quantum Secure Publicly Verifiable Secret Sharing and Applications Mosaic: Practical Malicious Security for Garbled Circuits on Bitcoin Efficient Bootstrapping of Matrices in FHE Decomposing Multiplication: A Vertical Packing Approach for Faster TFHE Formal Verification, Integration and Physical Evaluation of Prime-Field Masking on Silicon New Techniques for Communication-Efficient Secure Comparison Protocols Pairing-Based Verifiable Shuffles with Logarithmic-Size Proofs Verifying Provenance of Digital Media: Security Analysis of C2PA and its Implementation EQuADiSE: Efficient Quantum-safe Adaptive Distributed Symmetric-key Encryption Secure and Updatable Single Password Authentication Batch-Puncturing Circuit CP-ABE (and More) from Lattices Panther: Robust Hybrid KEM Combiners via Structural Splicing
Breaking Slope and Structure Restrictions: Broadening Har...
Ruijie Ma, Department of Computer Science and Technology, Tsingh · 2026-05-27 · via Cryptology ePrint Archive

Paper 2026/1066

Breaking Slope and Structure Restrictions: Broadening Hard-Label Cryptanalytic Extraction of PReLU Neural Networks

Yi Chen, Institute for Advanced Study, Tsinghua University

Jiarui Zhang, School of Cryptographic Science and Engineering, Shandong University

Hongbo Yu, Department of Computer Science and Technology, Tsinghua University

Xiaoyun Wang, Institute for Advanced Study, Tsinghua University

Abstract

This paper studies the problem of model parameter extraction of PReLU neural networks in the hard-label setting, the most challenging setting. Existing attacks on PReLU neural networks suffer from two fundamental restrictions: (1) the learnable slopes in PReLU activations are restricted to smaller than 1, not conforming to the standard definitions of PReLU activations; (2) they do not apply to expansive PReLU neural networks. In this paper, for the first time, we break the two restrictions by proposing a new attack in the hard-label setting. Our breakthroughs stem from two new techniques and an important finding. First, we propose a new network isomorphism, called flip-and-scaling, which helps break the slope restriction and build a new extraction framework. Second, we find that there are linear constraints on the internal states of expansive PReLU neural networks, and give the exact number of linear constraints. Third, we propose a new neuron signature recovery method for expansive PReLU neural networks, which overcomes the challenge brought by linear constraints and breaks the structure restriction. The correctness and effectiveness of our work have been fully verified by experiments on several hundred expansive PReLU neural networks. Overall, our work not only overcomes the restrictions of existing attacks but also provides some inspiration for future work.

BibTeX

@misc{cryptoeprint:2026/1066,
      author = {Ruijie Ma and Yi Chen and Jiarui Zhang and Hongbo Yu and Xiaoyun Wang},
      title = {Breaking Slope and Structure Restrictions:  Broadening Hard-Label Cryptanalytic Extraction of {PReLU} Neural Networks},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1066},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1066}
}