InferNet: Exploiting GPU Profiles to Infer DNN Architectures

InferNet uses coarse-grained GPU profiles to infer DNN architectures with 100% accuracy. A new side-channel attack on deep learning models.

jueves, 30 de julio de 2026 • 5 min read • Q2BSTUDIO Team

Cómo los perfiles GPU revelan arquitecturas de redes neuronales

In the current landscape of artificial intelligence, deep neural networks (DNNs) have become the core of critical applications, from computer vision systems to large language models. However, their proliferation has brought growing security concerns: model stealing, architecture extraction, and manipulation are real threats that can compromise intellectual property and system integrity. Traditionally, model extraction attacks required complex and fine-grained analysis, consuming large volumes of data and computational resources. But a new approach, embodied in the InferNet method, shows that even coarse-grained and non-intrusive system-level information can be sufficient to accurately identify the underlying architecture of a DNN.

InferNet relies on monitoring GPU kernel calls, memory events, and system metrics to generate a 'fingerprint' of a neural network's execution profile. By analyzing these patterns, it can determine not only the architecture family — for example, whether it is an Inception or a BERT — but also the specific variant, such as InceptionV1 versus InceptionV3. Published results show 100% accuracy even with partial GPU profiles, highlighting the vulnerability of models deployed in shared or cloud environments. This finding is particularly relevant for companies using cloud infrastructures such as AWS or Azure, where GPU resources are shared among multiple tenants, increasing the attack surface.

From a technical perspective, InferNet exploits the deterministic nature of GPU operations. Each DNN architecture executes a characteristic sequence of kernels, with unique memory patterns and execution times. Even when the attacker only has access to aggregated metrics — such as total call duration or memory bandwidth — the information is enough to train a classifier that identifies the network. The simplicity of the attack contrasts with the sophistication of current defense mechanisms, which often focus on protecting weights or model output, neglecting the hardware layer. For organizations investing in artificial intelligence, this security gap represents a strategic risk that must be addressed urgently.

The business implications are profound. A company that has developed a proprietary DNN model for competitive advantage may see a rival extract its architecture without direct access to the code. This not only affects intellectual property but can also facilitate adversarial attacks or the theft of tacit knowledge embedded in the network. Therefore, cybersecurity must be integrated into every phase of the model lifecycle: from design and training to deployment and monitoring. Q2BSTUDIO, as a software development company, recommends adopting a security-by-design approach, where custom applications include specific countermeasures against architecture extraction.

One of the most promising countermeasures is randomizing the GPU kernel sequence or injecting controlled noise into performance metrics. However, implementing these techniques effectively requires deep knowledge of the underlying hardware and the AI framework used (TensorFlow, PyTorch, etc.). This is where custom software offers advantages: it allows designing personalized protection that fits exactly the company's infrastructure, whether on local servers or in the cloud. Q2BSTUDIO has experience developing solutions that integrate obfuscation layers at the GPU level, making it harder for tools like InferNet to succeed without compromising performance.

Furthermore, continuous monitoring of GPU activity can become a defensive ally if combined with Business Intelligence systems. Power BI tools and other analytics platforms can ingest real-time GPU logs, creating dashboards that detect anomalous execution patterns. For example, an unusual increase in the frequency of certain kernels or variations in memory timings could indicate an extraction attempt. Q2BSTUDIO offers BI consulting services that enable building these early warning systems, integrated with AI agents capable of triggering automatic responses, such as key rotation or model isolation.

The emergence of InferNet also underscores the need to rethink security in cloud environments. Providers like AWS and Azure offer dedicated GPU instances, but many companies opt for shared options to reduce costs. In these scenarios, an attacker could run a lightweight process that monitors GPU behavior and extracts information about another virtual machine's model. Cloud architectures must be designed with strong hardware-level isolation and strict access policies. Q2BSTUDIO helps clients evaluate and configure their deployments on cloud AWS/Azure, ensuring that information leakage through GPU profiles is minimized.

Another key aspect is building multidisciplinary teams. Model extraction attacks require a response that combines knowledge of machine learning, computer security, and system architecture. Companies that lack these profiles internally can turn to technology partners like Q2BSTUDIO, which offers custom application development, AI agent integration, and cybersecurity audits. Our team works closely with clients to identify specific vulnerabilities and design robust solutions that protect their intellectual property.

Finally, it is important to highlight that research into attacks like InferNet not only reveals weaknesses but also drives innovation in defenses. The security community is developing new protection techniques, such as trusted execution environments (TEEs) or compiler-level kernel order randomization. However, practical implementation of these measures requires considerable engineering effort. This is where collaboration with specialized software development and cybersecurity companies makes the difference. Q2BSTUDIO is committed to helping organizations navigate this complex landscape, offering solutions ranging from strategic consulting to technical implementation.

In conclusion, InferNet demonstrates that the security of DNN models cannot be taken for granted. Seemingly innocuous information from GPU profiles can be exploited to compromise the confidentiality of architectures. Companies must act proactively, investing in custom applications that incorporate protection from design, continuously monitoring their systems with BI tools and AI agents, and adopting secure cloud architectures. If your organization deploys AI models in production, do not wait to become a victim of an attack. Contact Q2BSTUDIO to assess your risks and build a solid defense that protects your competitive advantage.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.