Curvature Cryptanalysis of Smooth Transformer Feed-Forward Networks
Researchers show that smooth activation functions like GELU in transformer feed-forward layers leak structural information exploitable for model extraction — a new side channel relevant to IP-sensitive ML deployments.
Summary written by editorial AI · Source link below
arXiv:2608.28843v1 Announce Type: cross Abstract: We show that smooth two-layer feed-forward networks (FFNs) expose an additional structural model extraction channel under a chosen-input raw-output oracle at the FFN branch; consider transformer FFN branches with GELU or SiLU activations under chosen-input raw-output access, without access to parameters, gradients, or internal activations; exploit a second-order leakage channel in which projected input Hessians form different mixtures of the sam
Editorial Analysis
Enterprises deploying proprietary transformer models via APIs risk intellectual-property theft through this novel curvature-based extraction technique.
Review API output policies for ML models to ensure raw intermediate representations are not exposed to untrusted callers.
A newly demonstrated attack can extract proprietary ML model details through the mathematical properties of common neural-network components.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the AI Security Desk
- OpenAI admits it didn't disclose rogue AI wiki hijacking incident2d
- Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel3d
- Using a VM to Contain an AI Agent3d
- Companies Have 6 Months to Prepare for Automated Attacks3d
- [NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen3d