Upcoming Colloquium

Can You Recover a Deep Neural Network From Its Answers?

Adi Shamir (Weizmann Institute of Science)

đź“… Thursday 15.10.2026  |  ⏰ 16:15 – 17:45  |  📍 Dejvice Campus, Room T9:105

Adi Shamir

Adi Shamir is a world-renowned computer scientist and mathematician. He is one of the three authors of the RSA cryptosystem, a foundational result in asymmetric cryptography that is used every day in Internet communication. His next breakthrough results include Shamir’s Secret Sharing scheme, breaking of the Merkle-Hellman knapsack cryptosystem, and proving that the complexity classes IP and PSPACE are equal. He received with several awards including the ACM Turing Award (jointly with Rivest and Adleman), the Wolf Prize in Mathematics, the Levchin Prize and the Erdős Prize in Mathematics.

Abstract of the Colloquium
Billions of dollars and countless GPU hours are currently spent on training Deep Neural Networks (DNNs) for a variety of tasks. Such networks are typically made available as "black boxes" with which the public can interact. Thus, it is essential to determine the difficulty of extracting all the parameters of such neural networks when given access only to their inputs and outputs.

In this talk I will use cryptographic ideas and techniques to show that for ReLU-based DNN's, this can be done in polynomial time (as a function of the number of neurons). This attack was practically demonstrated by applying it successfully to extract all the 1.2 million parameters of an 8-layer network for classifying CIFAR10 images. In the last part of the talk I will describe how to extend the result to the hardest model in which the only outputs provided to the attacker are the final labels (such as cat/dog) rather than the numeric values of the output logits, and where the architecture of the network is also unknown.

This paper had just been accepted for publication at the Journal of Cryptology, after receiving Eurocrypt's best paper award. The talk will be self contained, and will be accessible to a broad-based audience.