"Adversarial Examples" for Proof-of-Learning
Rui Zhang, Jian Liu, Yuan Ding, Zhibo Wang, Qingbiao Wu, Kui Ren
Abstract
In S&P 21, Jia et al. proposed a new concept/mechanism named proof-of-learning (PoL), which allows a prover to demonstrate ownership of a machine learning model by proving integrity of the training procedure. It guarantees that an adversary cannot construct a valid proof with less cost (in both computation and storage) than that made by the prover in generating the proof. A PoL proof includes a set of intermediate models recorded during training, together with the corresponding data points used to obtain each recorded model. Jia et al. claimed that an adversary merely knowing the final model and training dataset cannot efficiently find a set of intermediate models with correct data points. In this paper, however, we show that PoL is vulnerable to “adversarial examples”! Specifically, in a similar way as optimizing an adversarial example, we could make an arbitrarily-chosen data point “generate” a given model, hence efficiently generating intermediate models with correct data points. We demonstrate, both theoretically and empirically, that we are able to generate a valid proof with significantly less cost than generating a proof by the prover.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4be61dbf-bef1-4194-a79d-6a04995cfea2Cited by top-tier papers7
- Confidential-DPproof: Confidential Proof of Differentially Private TrainingAli Shahin Shamsabadi, Gefei Tan, Tudor Cebere, Aurélien Bellet et al.ICLR 2024 · 24 citations
- False Claims against Model Ownership ResolutionJian Liu, Rui Zhang, Sebastian Szyller, Kui Ren et al.USENIX Security 2024 · 22 citations
- Provenance of Training without Training Data: Towards Privacy-Preserving DNN Model Ownership VerificationYunpeng Liu, Kexin Li, Zhuotao Liu, Bihan Wen et al.WWW 2023 · 13 citations
- Towards Understanding and Enhancing Security of Proof-of-Training for DNN Model Ownership VerificationYijia Chang, Hanrui Jiang, Chao Lin, Xinyi Huang et al.USENIX Security 2025
- Unforgeability in Stochastic Gradient DescentTeodora Baluta, Ivica Nikolic, Racchit Jain, Divesh Aggarwal et al.CCS 2023
Builds on5
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter et al.USENIX Security 2016 · 2,088 citations
- Stealing Hyperparameters in Machine LearningBinghui Wang, Neil Zhenqiang GongS&P 2018 · 504 citations
- Proof-of-Learning: Definitions and PracticeHengrui Jia, Mohammad Yaghini, Christopher A. Choquette-Choo, Natalie Dullerud et al.S&P 2021 · 132 citations
- Unadversarial Examples: Designing Objects for Robust VisionHadi Salman, Andrew Ilyas, Logan Engstrom, Sai Vemprala et al.NeurIPS 2021 · 65 citations
Related papers
- Tools for Verifying Neural Models' Training DataDami Choi, Yonadav Shavit, David Kristjanson DuvenaudNeurIPS 2023 · 36 citations
- Breaking the Boundary Barrier: Robust Model Fingerprinting via Unlearnable Examples in Model-Parameter SpaceTianlong Xu, Zixiong Wang, Gaoyang Liu, Jian Chen et al.KDD 2026
- Increasing the Cost of Model Extraction with Calibrated Proof of WorkAdam Dziedzic, Muhammad Ahmad Kaleem, Yu Shen Lu, Nicolas PapernotICLR 2022 · 37 citations
- Identification of the Adversary from a Single Adversarial ExampleMinhao Cheng, Rui Min, Haochen Sun, Pin-Yu ChenICML 2023 · 1 citation
- Hey, That's My Model! Introducing Chain & Hash, An LLM Fingerprinting TechniqueMark Russinovich, Yanan Cai, Ahmed SalemICLR 2026 · 51 citations
