{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T10:59:29Z","timestamp":1778065169165,"version":"3.51.4"},"publisher-location":"Cham","reference-count":20,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031911064","type":"print"},{"value":"9783031911071","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-91107-1_13","type":"book-chapter","created":{"date-parts":[[2025,4,26]],"date-time":"2025-04-26T15:29:07Z","timestamp":1745681347000},"page":"364-396","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Polynomial Time Cryptanalytic Extraction of\u00a0Deep Neural Networks in\u00a0the\u00a0Hard-Label Setting"],"prefix":"10.1007","author":[{"given":"Nicholas","family":"Carlini","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jorge","family":"Ch\u00e1vez-Saab","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anna","family":"Hambitzer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Francisco","family":"Rodr\u00edguez-Henr\u00edquez","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Adi","family":"Shamir","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,4,27]]},"reference":[{"key":"13_CR1","doi-asserted-by":"publisher","unstructured":"Baum, E.B.: A polynomial time algorithm that learns two hidden unit nets. Neural Comput. 2(4), 510\u2013522 (1990). https:\/\/doi.org\/10.1162\/neco.1990.2.4.510","DOI":"10.1162\/neco.1990.2.4.510"},{"key":"13_CR2","doi-asserted-by":"publisher","unstructured":"Baum, E.B.: Neural net algorithms that learn in polynomial time from examples and queries. IEEE Trans. Neural Networks 2(1), 5\u201319 (1991). https:\/\/doi.org\/10.1109\/72.80287","DOI":"10.1109\/72.80287"},{"key":"13_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"9","DOI":"10.1007\/3-540-56483-7_20","volume-title":"Machine Learning: From Theory to Applications","author":"AL Blum","year":"1993","unstructured":"Blum, A.L., Rivest, R.L.: Training a 3-node neural network is NP-complete. In: Hanson, S.J., Remmele, W., Rivest, R.L. (eds.) Machine Learning: From Theory to Applications. LNCS, vol. 661, pp. 9\u201328. Springer, Heidelberg (1993). https:\/\/doi.org\/10.1007\/3-540-56483-7_20"},{"key":"13_CR4","doi-asserted-by":"crossref","unstructured":"Canales-Martinez, I.A., Ch\u00e1vez-Saab, J., Hambitzer, A., Rodr\u00edguez-Henr\u00edquez, F., Satpute, N., Shamir, A.: Polynomial time cryptanalytic extraction of neural network models. In: Joye, M., Leander, G. (eds.) Advances in Cryptology - EUROCRYPT 2024, Proceedings, Part III. Lecture Notes in Computer Science, vol. 14653, pp. 3\u201333. Springer, Cham (2024)","DOI":"10.1007\/978-3-031-58734-4_1"},{"key":"13_CR5","doi-asserted-by":"crossref","unstructured":"Carlini, N., Jagielski, M., Mironov, I.: Cryptanalytic extraction of neural network models. In: Micciancio, D., Ristenpart, T. (eds.) Advances in Cryptology - CRYPTO 2020, Proceedings, Part III. Lecture Notes in Computer Science, vol. 12172, pp. 189\u2013218. Springer, Cham (2020)","DOI":"10.1007\/978-3-030-56877-1_7"},{"key":"13_CR6","doi-asserted-by":"crossref","unstructured":"Chen, Y., Dong, X., Guo, J., Shen, Y., Wang, A., Wang, X.: Hard-label cryptanalytic extraction of neural network models. In: Chung, K., Sasaki, Y. (eds.) Advances in Cryptology - ASIACRYPT 2024, Proceedings, Part VIII. Lecture Notes in Computer Science, vol. 15491, pp. 207\u2013236. Springer, Cham (2024)","DOI":"10.1007\/978-981-96-0944-4_7"},{"key":"13_CR7","unstructured":"Daniely, A., Granot, E.: An exact poly-time membership-queries algorithm for extracting a three-layer ReLU network. In: The Eleventh International Conference on Learning Representations, ICLR 2023, Kigali, Rwanda, 1\u20135 May 2023. OpenReview.net (2023)"},{"key":"13_CR8","unstructured":"Dosovitskiy, A., et al.: An image is worth 16x16 words: transformers for image recognition at scale. In: 9th International Conference on Learning Representations, ICLR 2021, Virtual Event, Austria, 3\u20137 May 2021. OpenReview.net (2021)"},{"key":"13_CR9","doi-asserted-by":"crossref","unstructured":"Fefferman, C.: Reconstructing a neural net from its output. Revista Matem\u00e1tica Iberoamericana 10(3), 507\u2013555 (1994). http:\/\/eudml.org\/doc\/39464","DOI":"10.4171\/rmi\/160"},{"key":"13_CR10","unstructured":"Foerster, H., Mullins, R.D., Shumailov, I., Hayes, J.: Beyond slow signs in high-fidelity model extraction. In: Globersons, A., et al. (eds.) Advances in Neural Information Processing Systems 38: Annual Conference on Neural Information Processing Systems 2024, NeurIPS 2024 (2024)"},{"key":"13_CR11","doi-asserted-by":"publisher","unstructured":"Hancock, T.R., Golea, M., Marchand, M.: Learning nonoverlapping perceptron networks from examples and membership queries. Mach. Learn. 16(3), 161\u2013183 (1994). https:\/\/doi.org\/10.1007\/BF00993305","DOI":"10.1007\/BF00993305"},{"key":"13_CR12","doi-asserted-by":"crossref","unstructured":"Hoeffding, W.: Probability inequalities for sums of bounded random variables. In: The Collected Works of Wassily Hoeffding, pp. 409\u2013426 (1994)","DOI":"10.1007\/978-1-4612-0865-5_26"},{"key":"13_CR13","unstructured":"Jagielski, M., Carlini, N., Berthelot, D., Kurakin, A., Papernot, N.: High accuracy and high fidelity extraction of neural networks. In: 29th USENIX security symposium (USENIX Security 2020), pp. 1345\u20131362 (2020)"},{"key":"13_CR14","unstructured":"Lin, Z., Memisevic, R., Konda, K.: How far can we go without convolution: improving fully-connected networks. arXiv preprint arXiv:1511.02580 (2015)"},{"key":"13_CR15","unstructured":"Martinelli, F., Simsek, B., Gerstner, W., Brea, J.: Expand-and-cluster: parameter recovery of neural networks. In: Forty-First International Conference on Machine Learning, ICML 2024, Vienna, Austria, 21\u201327 July 2024. OpenReview.net (2024)"},{"key":"13_CR16","doi-asserted-by":"crossref","unstructured":"Milli, S., Schmidt, L., Dragan, A.D., Hardt, M.: Model reconstruction from model explanations. In: Boyd, D., Morgenstern, J.H. (eds.) Proceedings of the Conference on Fairness, Accountability, and Transparency, FAT* 2019, Atlanta, GA, USA, 29\u201331 January 2019, pp.\u00a01\u20139. ACM (2019)","DOI":"10.1145\/3287560.3287562"},{"key":"13_CR17","doi-asserted-by":"crossref","unstructured":"Reith, R.N., Schneider, T., Tkachenko, O.: Efficiently stealing your machine learning models. In: Cavallaro, L., Kinder, J., Domingo-Ferrer, J. (eds.) Proceedings of the 18th ACM Workshop on Privacy in the Electronic Society, WPES@CCS 2019, London, UK, 11 November 2019, pp. 198\u2013210. ACM (2019)","DOI":"10.1145\/3338498.3358646"},{"key":"13_CR18","unstructured":"Rolnick, D., K\u00f6rding, K.P.: Reverse-engineering deep ReLU networks. In: Proceedings of the 37th International Conference on Machine Learning, ICML 2020, 13\u201318 July 2020, Virtual Event. Proceedings of Machine Learning Research, vol.\u00a0119, pp. 8178\u20138187. PMLR (2020)"},{"issue":"11","key":"13_CR19","doi-asserted-by":"publisher","first-page":"1958","DOI":"10.1109\/TPAMI.2008.128","volume":"30","author":"A Torralba","year":"2008","unstructured":"Torralba, A., Fergus, R., Freeman, W.T.: 80 million tiny images: a large data set for nonparametric object and scene recognition. IEEE Trans. Pattern Anal. Mach. Intell. 30(11), 1958\u20131970 (2008)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"13_CR20","unstructured":"Tram\u00e8r, F., Zhang, F., Juels, A., Reiter, M.K., Ristenpart, T.: Stealing machine learning models via prediction $$\\{$$APIs$$\\}$$. In: 25th USENIX security symposium (USENIX Security 2016), pp. 601\u2013618 (2016)"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2025"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-91107-1_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,26]],"date-time":"2025-04-26T15:29:15Z","timestamp":1745681355000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-91107-1_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783031911064","9783031911071"],"references-count":20,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-91107-1_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"27 April 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Madrid","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Spain","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 May 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 May 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"44","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt.iacr.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}