A cryptographic study demonstrates that permutation-based model confidentiality in hybrid fully homomorphic encryption (FHE) systems can be broken with a small number of queries. The researchers show that d+1 queries suffice to recover permutation-invariant summaries of linear layers and successfully extract all layers from ResNet-20 and ImageNet-scale models, revealing that shuffling and differential privacy protections are insufficient under correctness constraints.