Sentry: Authenticating Machine Learning Artifacts on the Fly
Andrew Gan, Zahra Ghodsi
摘要
Machine learning systems increasingly rely on open-source artifacts such as datasets and models that are created or hosted by other parties. The reliance on external datasets and pre-trained models exposes the system to supply chain attacks where an artifact can be poisoned before it is delivered to the end-user. Such attacks are possible due to the lack of any authenticity verification in existing machine learning systems. Incorporating cryptographic solutions such as hashing and signing can mitigate the risk of supply chain attacks. However, existing frameworks for integrity verification based on cryptographic techniques can incur significant overhead when applied to state-of-the-art machine learning artifacts due to their scale, and are not compatible with GPU platforms. In this paper, we develop Sentry, a novel GPU-based framework that verifies the authenticity of machine learning artifacts by implementing cryptographic signing and verification for datasets and models. Sentry ties developer identities to signatures and performs authentication on the fly as artifacts are loaded on GPU memory, making it compatible with GPU data movement solutions such as NVIDIA GPUDirect that bypass the CPU. Sentry incorporates GPU acceleration of cryptographic hash constructions such as Merkle tree and lattice hashing, implementing memory optimizations and resource partitioning schemes for a high throughput performance. Our evaluations show that Sentry is a practical solution to bring authenticity to machine learning systems, achieving orders of magnitude speedup over a CPU-based baseline.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper9
- Efficient large-scale language model training on GPU clusters using megatron-LMDeepak Narayanan, Mohammad Shoeybi, Jared Casper, Patrick LeGresley 等SC 2021 · 被引用 576 次
- Poisoning Web-Scale Training Datasets is PracticalNicholas Carlini, Matthew Jagielski, Christopher A. Choquette-Choo, Daniel Paleka 等S&P 2024 · 被引用 309 次
- CryptGPU: Fast Privacy-Preserving Machine Learning on the GPUSijun Tan, Brian Knott, Yuan Tian, David J. WuS&P 2021 · 被引用 241 次
- in-toto: Providing farm-to-table guarantees for bits and bytesSantiago Torres-Arias, Hammad Afzali, Trishank Karthik Kuppusamy, Reza Curtmola 等USENIX Security 2019 · 被引用 98 次
- Sigstore: Software Signing for EverybodyZachary Newman, John Speed Meyers, Santiago Torres-AriasCCS 2022 · 被引用 35 次
相关 Paper
- SAGE: Software-based Attestation for GPU ExecutionAndrei Ivanov, Benjamin Rothenberger, Arnaud Dethise, Marco Canini 等USENIX ATC 2023 · 被引用 1 次
- EdgeThemis: Ensuring Model Integrity for Edge IntelligenceJiyu Yang, Qiang He, Zheyu Zhou, Xiaohai Dai 等WWW 2025 · 被引用 1 次
- Integrity Authentication in Tree ModelsWeijie Zhao, Yingjie Lao, Ping LiKDD 2022 · 被引用 3 次
- DarKnight: An Accelerated Framework for Privacy and Integrity Preserving Deep Learning Using Trusted HardwareHanieh Hashemi, Yongqin Wang, Murali AnnavaramMICRO 2021 · 被引用 51 次
- GPU Travelling: Efficient Confidential Collaborative Training with TEE-Enabled GPUsShixuan Zhao, Zhongshu Gu, Salman Ahmed, Enriquillo Valdez 等CCS 2025
