PublicCheck: Public Integrity Verification for Services of Run-time Deep Models
Shuo Wang, Sharif Abuadbba, Sidharth Agarwal, Kristen Moore, Ruoxi Sun, Minhui Xue, Surya Nepal, Seyit Camtepe, Salil S. Kanhere
Abstract
Existing integrity verification approaches for deep models are designed for private verification (i.e., assuming the service provider is honest, with white-box access to model parameters). However, private verification approaches do not allow model users to verify the model at run-time. Instead, they must trust the service provider, who may tamper with the verification results. In contrast, a public verification approach that considers the possibility of dishonest service providers can benefit a wider range of users. In this paper, we propose PublicCheck, a practical public integrity verification solution for services of run-time deep models. PublicCheck considers dishonest service providers, and overcomes public verification challenges of being lightweight, providing anti-counterfeiting protection, and having fingerprinting samples that appear smooth. To capture and fingerprint the inherent prediction behaviors of a run-time model, PublicCheck generates smoothly transformed and augmented encysted samples that are enclosed around the model's decision boundary while ensuring that the verification queries are indistinguishable from normal queries. PublicCheck is also applicable when knowledge of the target model is limited (e.g., with no knowledge of gradients or model parameters). A thorough evaluation of PublicCheck demonstrates the strong capability for model integrity breach detection (100% detection accuracy with less than 10 black-box API queries) against various model integrity attacks and model compression attacks. PublicCheck also demonstrates the smooth appearance, feasibility, and efficiency of generating a plethora of encysted samples for fingerprinting.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f908e048-f4fb-437f-9348-ad59841a9341Cited by top-tier papers5
- Intersecting-Boundary-Sensitive Fingerprinting for Tampering Detection of DNN ModelsXiaofan Bai, Chaoxiang He, Xiaojing Ma, Bin Benjamin Zhu et al.ICML 2024 · 6 citations
- EdgeThemis: Ensuring Model Integrity for Edge IntelligenceJiyu Yang, Qiang He, Zheyu Zhou, Xiaohai Dai et al.WWW 2025 · 1 citation
- SDBF: Steep-Decision-Boundary Fingerprinting for Hard-Label Tampering Detection of DNN ModelsXiaofan Bai, Shixin Li, Xiaojing Ma, Bin Benjamin Zhu et al.CVPR 2025
- RESF: Regularized-Entropy-Sensitive Fingerprinting for Black-Box Tamper Detection of Large Language ModelsPingyi Hu, Xiaofan Bai, Xiaojing Ma, Chaoxiang He et al.EMNLP 2025
- DIPBox: A Multi-scale Testing Framework for Tracking Dataset RegenerationTian Dong, Yan Meng, Shaofeng Li, Guoxing Chen et al.CCS 2026
Builds on9
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Trojaning Attack on Neural NetworksYingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee et al.NDSS 2018 · 1,377 citations
- Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by BackdooringYossi Adi, Carsten Baum, Moustapha Cissé, Benny Pinkas et al.USENIX Security 2018 · 832 citations
- Deep Neural Network Fingerprinting by Conferrable Adversarial ExamplesNils Lukas, Yuxuan Zhang, Florian KerschbaumICLR 2021 · 182 citations
- Hidden Backdoors in Human-Centric Language ModelsShaofeng Li, Hui Liu, Tian Dong, Benjamin Zi Hao Zhao et al.CCS 2021 · 108 citations
Related papers
- Towards Stricter Black-box Integrity Verification of Deep Neural Network ModelsChaoxiang He, Xiaofan Bai, Xiaojing Ma, Bin B. Zhu et al.ACM MM 2024 · 3 citations
- Securing Graph Neural Networks in MLaaS: A Comprehensive Realization of Query-based Integrity VerificationBang Wu, Xingliang Yuan, Shuo Wang, Qi Li et al.S&P 2024 · 13 citations
- AID: Attesting the Integrity of Deep Neural NetworksOmid Aramoon, Pin-Yu Chen, Gang QuDAC 2021 · 9 citations
- Fingerprinting Deep Neural Networks Globally via Universal Adversarial PerturbationsZirui Peng, Shaofeng Li, Guoxing Chen, Cheng Zhang et al.CVPR 2022 · 66 citations
- DeepAuth: A DNN Authentication Framework by Model-Unique and Fragile Signature EmbeddingYingjie Lao, Weijie Zhao, Peng Yang, Ping LiAAAI 2022 · 34 citations
