arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

基于再质押的可验证推理的重复博弈安全性

Repeated-Game Security for Restaking-Based Verifiable Inference

Zhenhang Shang, Yingzhe Yu, Kani Chen

arXiv 2608.09055首次发表:更新:

AI 中文总结

本文针对基于再质押的可验证推理协议,发现其单轮罚没条件高估安全性,提出结合历史挑战、声誉加权罚没与质押归属的机制,可降低重复博弈偏差利润,减少审计率。

AI 中文摘要

基于再质押的协议可实现可验证的大语言模型(LLM)推理,无需零知识机器学习(zkML)的高证明成本,也无需可信执行环境(TEE)的硬件信任假设。其安全性通常由单轮罚没条件证明:当预期惩罚超过不诚实推理的成本节约时,理性提供者不应作弊。本文表明,当在同一质押下重复提供推理时,该条件可能高估安全性。我们将可验证推理建模为贴现重复博弈,并识别出由比例罚没导致的重复博弈缺口:检测到的偏差会减少未来的惩罚暴露,而成本节约会在多个查询中再次获得。我们推导了该缺口的闭式形式,证明其在最低质押驱逐机制下仍存在,并将其扩展至涵盖已部署设计的无记忆有界罚没协议。我们提出一种可部署机制,结合依赖历史的挑战、声誉加权罚没和质押归属,该机制可在显式贴现因子阈值以上,针对平稳混合策略偏差恢复无限期子博弈完美激励相容性,且无需每查询一次的密码学验证。对9个参数规模在0.5B至14B的开放权重模型对的评估显示,审计信号具有所需的凹可检测性响应。斯塔克尔伯格审计预算分析表明,在贴现因子为0.95时,改进的信号响应性可将基准审计率降低2.6倍。校准至已部署参数后,被调查协议通过了单轮激励相容性,但在贴现因子介于0.92至0.98时允许重复博弈偏差,偏差利润占比为1.5%至8%。我们的机制将偏差利润降低31%至54%,同时保持低延迟的经济验证。

英文摘要

Restaking-based protocols enable verifiable LLM inference without the high proving cost of zkML or the hardware trust assumptions of TEEs. Their security is commonly justified by a one-round slashing condition: a rational provider should not cheat when the expected penalty exceeds the cost saving from dishonest inference. This paper shows that this condition can overstate security when inference is supplied repeatedly under the same stake. We model verifiable inference as a discounted repeated game and identify a repeated-game gap caused by proportional slashing: detected deviations reduce future penalty exposure, while cost savings are earned again across queries. We derive the gap in closed form, show that it persists under minimum-stake ejection, and extend it to memoryless bounded-slashing protocols covering deployed designs. We propose a deployable mechanism combining history-dependent challenges, reputation-weighted slashing, and stake vesting. The mechanism restores infinite-horizon subgame-perfect incentive compatibility against stationary mixed-strategy deviations above an explicit discount-factor threshold without per-query cryptographic verification. Evaluation across nine open-weight model pairs from 0.5B to 14B parameters shows that the audit signal has the required concave detectability response. A Stackelberg audit-budget analysis shows that improved signal responsiveness reduces the baseline audit rate by 2.6x at discount factor 0.95. Calibrated to deployed parameters, surveyed protocols pass one-round incentive compatibility but admit repeated-game deviations for discount factors between 0.92 and 0.98, with deviation-profit fractions of 1.5%--8%. Our mechanism reduces deviation profits by 31%--54% while maintaining low-latency economic verification.

CommentsLength: 29 pages total (15 pages main text, plus appendix and references). Figures: 5. Artifact: https://anonymous.4open.science/r/Repeated-Slashing-8031/README.md

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑