paper-with-me

홈 › Papers

Train to Defend: First Defense Against Cryptanalytic Neural Network Parameter Extraction Attacks

2025-09-20 · Ashley Kurian, Aydin Aysu arxiv

Neural networks are valuable intellectual property due to the significant computational cost, expert labor, and proprietary data involved in their development. Consequently, protecting their parameters is critical not only for maintaining a competitive advantage but also for enhancing the model's security and privacy. Prior works have demonstrated the growing capability of cryptanalytic attacks to scale to deeper models. In this paper, we present the first defense mechanism against cryptanalytic parameter extraction attacks. Our key insight is to eliminate the neuron uniqueness necessary for these attacks to succeed. We achieve this by a novel, extraction-aware training method. Specifically, we augment the standard loss function with an additional regularization term that minimizes the distance between neuron weights within a layer. Therefore, the proposed defense has zero area-delay overhead during inference. We evaluate the effectiveness of our approach in mitigating extraction attacks while analyzing the model accuracy across different architectures and datasets. When re-trained with the same model architecture, the results show that our defense incurs a marginal accuracy change of less than 1% with the modified loss function. Moreover, we present a theoretical framework to quantify the success probability of the attack. When tested comprehensively with prior attack settings, our defense demonstrated empirical success for sustained periods of extraction, whereas unprotected networks are extracted between 14 minutes to 4 hours.

📄 PDF Abstract BibTeX arXiv:2509.16546

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Two Heads are Better than One: Nested PoE for Robust Defense Against Multi-Backdoors

2024-04-02 · Victoria Graf, Qin Liu, Muhao Chen

Data poisoning backdoor attacks can cause undesirable behaviors in large language models (LLMs), and defending against them is of increasing importance. Existing defense mechanisms often assume that only one type of trig…

Data PoisoningHate Speech DetectionMixture-of-ExpertsSentiment Analysis

Overcomplete Representations Against Adversarial Videos

2020-12-08 · Shao-Yuan Lo, Jeya Maria Jose Valanarasu, Vishal M. Patel

Adversarial robustness of deep neural networks is an extensively studied problem in the literature and various methods have been proposed to defend against adversarial images. However, only a handful of defense methods h…

Adversarial RobustnessDecoderVideo Recognition

Defending Backdoor Data Poisoning Attacks by Using Noisy Label Defense Algorithm

2021-09-29 · Boyang Liu, Zhuangdi Zhu, Pang-Ning Tan, Jiayu Zhou

Training deep neural networks with data corruption is a challenging problem. One example of such corruption is the backdoor data poisoning attack, in which an adversary strategically injects a backdoor trigger to a small…

Backdoor AttackData Poisoning

A Single Set of Adversarial Clothes Breaks Multiple Defense Methods in the Physical World

2025-10-20 · Wei Zhang, Zhanhao Hu, Xiao Li, Xiaopei Zhu 외 arxiv

In recent years, adversarial attacks against deep learning-based object detectors in the physical world have attracted much attention. To defend against these attacks, researchers have proposed various defense methods ag…

Adversarial Defense

Exploring Non-additive Randomness on ViT against Query-Based Black-Box Attacks

2023-09-12 · Jindong Gu, Fangyun Wei, Philip Torr, Han Hu

Deep Neural Networks can be easily fooled by small and imperceptible perturbations. The query-based black-box attack (QBBA) is able to create the perturbations using model output probabilities of image queries requiring …