用零知识证明让大模型无线感知更安全可验证,防篡改还省电。
ZK-SenseLM: Verifiable Large-Model Wireless Sensing with Selective Abstention and Zero-Knowledge Attestation
- 大模型结合零知识证明,实现可审计的无线感知决策
- 在扰动下仍保持高准确率与良好风险-覆盖平衡
- 适合需要安全验证的智能家居、安防等场景
ZK-SenseLM 是一种安全且可审计的无线感知框架,将大模型编码器(用于 Wi-Fi 信道状态信息,可选毫米波雷达或 RFID)与基于策略的决策层及端到端零知识推理证明相结合。编码器采用带相位一致性正则化的掩码频谱预训练,并通过轻量级跨模态对齐将射频特征映射为紧凑的人类可读策略标记。为降低分布偏移下的不安全行为,引入校准的可选弃权头;选定的风险-覆盖操作点被注册并绑定至证明中。系统采用四阶段证明流程:(C1) 特征完整性与承诺,(C2) 阈值与版本绑定,(C3) 时间窗口绑定,(C4) 基于 PLONK 的证明,验证量化网络在已承诺窗口下生成了记录动作与置信度。微批处理证明摊薄成本,网关模式可将证明任务卸载至低功耗设备。系统兼容差分隐私联邦学习与本地个性化,且不削弱可验证性:模型哈希与注册阈值均作为公开声明的一部分。在活动识别、存在检测、入侵检测、呼吸代理与射频指纹等任务中,ZK-SenseLM 提升宏观 F1 与校准性能,扰动下展现有利的风险-覆盖曲线,并能以紧凑证明快速拒绝篡改与重放攻击。
原文摘要 · Abstract (English)
ZK-SenseLM is a secure and auditable wireless sensing framework that pairs a large-model encoder for Wi-Fi channel state information (and optionally mmWave radar or RFID) with a policy-grounded decision layer and end-to-end zero-knowledge proofs of inference. The encoder uses masked spectral pretraining with phase-consistency regularization, plus a light cross-modal alignment that ties RF features to compact, human-interpretable policy tokens. To reduce unsafe actions under distribution shift, we add a calibrated selective-abstention head; the chosen risk-coverage operating point is registered and bound into the proof. We implement a four-stage proving pipeline: (C1) feature sanity and commitment, (C2) threshold and version binding, (C3) time-window binding, and (C4) PLONK-style proofs that the quantized network, given the committed window, produced the logged action and confidence. Micro-batched proving amortizes cost across adjacent windows, and a gateway option offloads proofs from low-power devices. The system integrates with differentially private federated learning and on-device personalization without weakening verifiability: model hashes and the registered threshold are part of each public statement. Across activity, presence or intrusion, respiratory proxy, and RF fingerprinting tasks, ZK-SenseLM improves macro-F1 and calibration, yields favorable coverage-risk curves under perturbations, and rejects tamper and replay with compact proofs and fast verification.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。