arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.01781cs.SEcs.CR

Modelstamp:机器学习制品的反序列化前验证与运行时环境状态

Modelstamp: Pre-Deserialization Verification of Machine-Learning Artifacts and Runtime Environment State

Anagha Dhekne

AI总结:

Modelstamp 是一款轻量级 Python 库,可在反序列化前验证机器学习制品完整性与运行时环境状态,经多场景评估具备良好性能,可作为相关安全控制的补充。

AI中文摘要:

持久化的机器学习模型在字节层面保持完全一致的同时,其加载所用的软件环境可能发生演变,由此产生的验证问题仅靠制品完整性检查无法暴露。本文提出 Modelstamp,这是一个轻量级 Python 持久化库,用于在反序列化前验证制品完整性及所代表的运行时环境状态。在持久化阶段,Modelstamp 会将序列化制品与一个附带的 JSON 清单关联,该清单包含 SHA-256 摘要、运行时元数据,以及来自受限跟踪包集合的已安装版本;单独记录的与模型相关的子集决定了哪些包版本会参与漂移比较。可选的 HMAC 认证支持生产者和验证者共享密钥的工作流。在验证阶段,会在模型反序列化前,根据记录的证据检查制品和当前代表环境。通过 14 个受控环境漂移场景、8 个受控信任边界场景,以及从 10 MiB 到 1 GiB 的制品规模扩展基准测试对 Modelstamp 进行评估。受控漂移实验在相关依赖变更、未变更环境、无关环境变更(包括更广泛的噪声控制)中均表现符合预期。信任边界实验同样确认了预期的检测能力和预期限制,包括共享密钥伪造与重放。基准环境中,中位数验证时间从 10 MiB 时的 0.032 秒增加到 1 GiB 时的 3.334 秒,测量吞吐量约为 307-312 MiB/s。这些结果表明,Modelstamp 是一种互补性的反序列化前参考状态验证控制,而非依赖管理系统、恶意模型检测、安全反序列化或公共发布者认证的替代品。

英文摘要:

Persisted machine-learning models can remain byte-identical while the software environments in which they are loaded evolve, creating a verification problem that artifact integrity checks alone cannot expose. This paper presents Modelstamp, a lightweight Python persistence library for verifying artifact integrity and represented runtime-environment state before deserialization. At persistence time, Modelstamp associates a serialized artifact with a sidecar JSON manifest containing a SHA-256 digest, runtime metadata, and installed versions from a bounded tracked-package set; a separately recorded model-relevant subset determines which package versions participate in drift comparison. Optional HMAC authentication supports workflows in which the producer and verifier share a secret key. At verification time, the artifact and represented current environment are checked against this recorded evidence before the model is deserialized. Modelstamp is evaluated using 14 controlled environment-drift scenarios, eight controlled trust-boundary scenarios, and an artifact-size scaling benchmark from 10 MiB to 1 GiB. The controlled drift experiments behaved as specified across relevant dependency changes, unchanged environments, and unrelated environmental changes, including broader noise controls. The trust-boundary experiments similarly confirmed both intended detections and expected limitations, including shared-key forgery and replay. Median verification time increased from 0.032 s at 10 MiB to 3.334 s at 1 GiB, with measured throughput of approximately 307-312 MiB/s in the benchmark environment. These results characterize Modelstamp as a complementary pre-deserialization reference-state verification control rather than as a replacement for dependency-management systems, malicious-model detection, safe deserialization, or public publisher authentication.

补充信息

↑