通过最小信息披露实现隐私保护的AI验证
Privacy-Preserving AI Verification via Minimal Information Disclosure
浏览论文内容
中文总结 AI 辅助
该研究提出最小信息披露(MID)方法,通过条件互信息衡量AI验证中的附带泄露,在多项验证任务中实现完美验证且零附带泄露,并支持基于Groth16 zk-SNARK的ZKP认证发布。
中文摘要 AI 辅助
AI验证跨越信任边界:验证者必须获取足够信息以确立授权主张,但相同证据可能泄露关于模型、工作负载或硬件的敏感细节。我们引入最小信息披露(Minimal Information Disclosure,MID),其设计并量化面向验证者的证据本身的信息内容。MID通过条件互信息衡量附带泄露:即授权结果已知后,所发布内容对受保护属性的泄露程度。MID具有通用性,可适配不同的验证目标、受保护属性、证据源和部署约束。为验证MID的实用性,我们在4项物理测量和6项验证任务上对其进行评估,这些任务涵盖执行类型、硬件身份、计算规模和模型身份。这些实验使用3种机制设计变量——证据通道、收集策略和发布转换,但MID并不受限于这些选择,可适配其他可部署机制。在这些任务中,MID生成的3种发布实现了完美的保留验证和零测量附带泄露,而其余任务则产生了明确的隐私-效用前沿。MID还支持零知识证明(Zero-Knowledge Proof,ZKP)认证的发布:我们使用Groth16 zk-SNARK演示了所提出的线性投影机制。
英文摘要
AI verification crosses a trust boundary: a verifier must learn enough to establish an authorized claim, yet the same evidence can reveal sensitive details about the model, workload, or hardware. We introduce minimal information disclosure (MID), which designs and quantifies the information content of verifier-facing evidence itself. MID measures collateral leakage with conditional mutual information: what the release reveals about the protected property after the authorized result is known. MID is general by design: it can accommodate different verification goals, protected properties, evidence sources, and deployment constraints. To demonstrate MID's practicality, we evaluate it on four physical measurements and six verification tasks spanning execution type, hardware identity, compute scale, and model identity. These experiments use three mechanism-design variables--the evidence channel, collection policy, and release transformation--but MID is not limited to these choices and can accommodate other deployable mechanisms. Across these tasks, MID produces three releases with perfect held-out verification and zero measured collateral leakage, while the remaining tasks yield explicit privacy--utility frontiers. MID also supports ZKP-certified releases: we demonstrate our proposed linear-projection mechanism using a Groth16 zk-SNARK.
发表机构
- Rice University(莱斯大学)
- Intelligence Security Laboratories(情报安全实验室)
机构由 AI 辅助整理,请以论文原文为准。