arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.29264cs.CRcs.AI

TP-CRIV:AI模型第三方挑战-响应身份验证框架

TP-CRIV: A Framework for Third-Party Challenge-Response Identity Verification of AI Models

Teruki Sano, Minoru Kuribayashi, Masao Sakai, Shuji Isobe, Eisuke Koizumi, Zhang Zhang, Satoru Matsumoto

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出TP-CRIV框架,通过黑盒挑战-响应机制在无白盒或API访问下验证AI模型身份,实验证明其有效区分同模型与跨模型。

中文摘要 AI 辅助

人工智能(AI)模型越来越多地通过远程服务部署,使得模型盗用问题日益受到关注。现有方法,包括水印、指纹识别和模型相似性分析,主要依赖于预定义的证据或直接的行为比较,并未明确评估声称者当前是否拥有并能够利用与所声称模型身份相关的模型依赖信息。在本文中,我们提出了用于AI模型的第三方挑战-响应身份验证(TP-CRIV)。TP-CRIV针对第三方验证场景,其中验证者既无法白盒访问也无法通过API访问声称者的模型,只能通过其普通的黑盒推理接口与可疑的部署服务交互,并且不需要服务提供商进行协议特定的合作。在这些约束下,该框架使验证者能够获得经验性证据,证明声称者是否在本地拥有一个满足相对于部署模型预先声明身份的模型。验证在新鲜的、先前未披露的要求和网络隔离下进行,因此所展示的能力不能依赖于挑战披露后的在线外部帮助。所得证据相对于独立指定和校准的匹配与非匹配操作情境进行解释,并且是统计性的而非密码性的。我们使用基于概率控制的见证生成方法,为CNN图像分类器实例化了TP-CRIV。在十个ImageNet预训练的TorchVision模型上的实验表明,使用独立校准的阈值可以实现清晰的同模型/跨模型分离和有限挑战验证。

英文摘要

Artificial intelligence (AI) models are increasingly deployed through remote services, making model misappropriation a growing concern. Existing approaches, including watermarking, fingerprinting, and model similarity analysis, primarily rely on predefined evidence or direct behavioral comparison and do not explicitly evaluate whether the claimant currently possesses and can utilize model-dependent information relevant to the claimed model identity. In this paper, we propose Third-Party Challenge-Response Identity Verification (TP-CRIV) for AI models. TP-CRIV targets a third-party verification setting in which the verifier has neither white-box nor API access to the claimant's model, can interact with the suspicious deployed service only through its ordinary black-box inference interface, and does not require protocol-specific cooperation from the service provider. Under these constraints, the framework enables the verifier to obtain empirical evidence as to whether the claimant locally possesses a model satisfying a predeclared identity relative to the deployed model. Verification is conducted under fresh, previously undisclosed requirements and network isolation, so that the demonstrated capability cannot rely on online external assistance after challenge disclosure. The resulting evidence is interpreted relative to independently specified and calibrated matching and non-matching operating situations and is statistical rather than cryptographic. We instantiate TP-CRIV for CNN image classifiers using probability-control-based witness generation. Experiments on ten ImageNet-pretrained TorchVision models demonstrate clear same/cross-model separation and finite-challenge verification using independently calibrated thresholds.

发表机构

  • Tohoku University(东北大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑