USENIX Security2026Top-tier venue
Trusting What You Cannot See: Auditable Fine-Tuning and Inference for Proprietary AI
Heng Jin, Chaoyu Zhang, Hexuan Yu, Shanghao Shi, Ning Zhang, Y. Thomas Hou, Wenjing Lou
Abstract
Cloud-based infrastructure has become the dominant platform for deploying large models, particularly large language models (LLMs). Fine-tuning and inference are increasingly delegated to cloud providers for simplified deployment and access to proprietary models, yet this creates a fundamental trust gap. Although cryptographic and TEE-based verification approaches exist, prohibitive proving costs and limited TEE memory prevent them from scaling to modern LLMs, leaving clients unable to practically audit these processes. This lack of transparency creates concrete security risks that can silently compromise service integrity. We present AFTUNE, an auditable and verifiable framework that ensures the computational integrity of cloud-based fine-tuning and inference. AFTUNE incorporates a lightweight recording and spot-check mechanism that produces verifiable traces of execution. These traces enable clients to later audit whether the fine-tuning and inference processes followed the agreed configurations, by verifying sampled execution blocks inside a TEE, each covering only a small portion of the model and the execution trace. Our evaluation shows that AFTUNE adds modest overhead and makes auditing practical for clients.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3af66136-ce91-4cb5-9b7c-b5db60490f35Builds on10
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
- Enabling Execution Assurance of Federated Learning at Untrusted ParticipantsXiaoli Zhang, Fengting Li, Zeyu Zhang, Qi Li et al.INFOCOM 2020 · 87 citations
- Scalable Zero-knowledge Proofs for Non-linear Functions in Machine LearningMeng Hao, Hanxiao Chen, Hongwei Li, Chenkai Weng et al.USENIX Security 2024 · 29 citations
- Zero-Knowledge Proofs of Training for Deep Neural NetworksKasra Abbaszadeh, Christodoulos Pappas, Jonathan Katz, Dimitrios PapadopoulosCCS 2024 · 24 citations
- Gramine-TDX: A Lightweight OS Kernel for Confidential VMsDmitrii Kuvaiskii, Dimitrios Stavrakakis, Kailun Qin, Cedric Xing et al.CCS 2024 · 10 citations
Related papers
- TOPLOC: A Locality Sensitive Hashing Scheme for Trustless Verifiable InferenceJack Min Ong, Matthew Di Ferrante, Aaron Pazdera, Ryan Garner et al.ICML 2025
- DeepProve: Verifiable End-to-End Large Language Model InferenceNicolas Gailly, Ismael Hishon-Rezaizadeh, Tianyi Liu, Nicholas Mainardi et al.CCS 2026
- Your Inference Request Will Become a Black Box: Confidential Inference for Cloud-based Large Language ModelsChung-ju Huang, Huiqiang Zhao, Yuanpeng He, Lijian Li et al.ACL 2026
- AegisGuard: RL-Guided Adapter Tuning for TEE-Based Efficient & Secure On-Device InferenceChe Wang, Ziqi Zhang, Yinggui Wang, Tiantong Wang et al.NeurIPS 2025
- SLIM: Secure and Efficient Inference for Large Language Models on Untrusted Devices via TEEsWei Wang, Zihao Guan, Xing Zhou, Yan Ding et al.ICML 2026
