为AI模型训练生成可验证的物料清单,保障安全与合规。
AIBoMGen: Generating an AI Bill of Materials for Secure, Transparent, and Compliant Model Training
- 在训练时自动记录数据集、模型元数据和环境信息,生成带数字签名的AIBOM。
- 能可靠检测所有人工制品的未经授权修改,性能开销极低。
- 适合需要透明化、合规化的AI研发团队与监管机构使用。
复杂AI系统的快速应用已超越了确保其透明性、安全性和合规性工具的发展。本文提出人工智能物料清单(AIBOM),作为软件物料清单(SBOM)的延伸,是一种标准化、可验证的已训练AI模型及其环境的记录。我们的概念验证平台AIBoMGen通过在训练过程中捕获数据集、模型元数据和环境细节,自动化生成带签名的AIBOM。训练平台作为中立的第三方观察者和信任根,强制为每个任务生成可验证的AIBOM。系统采用加密哈希、数字签名和in-toto背书机制,确保完整性并防范恶意模型创建者篡改产物等威胁。评估表明,AIBoMGen能可靠检测所有人工制品的未经授权修改,并以可忽略的性能开销生成AIBOM。这些结果凸显了AIBoMGen作为构建安全透明AI生态基础步骤的潜力,有助于满足欧盟人工智能法案等监管框架要求。
原文摘要 · Abstract (English)
The rapid adoption of complex AI systems has outpaced the development of tools to ensure their transparency, security, and regulatory compliance. In this paper, the AI Bill of Materials (AIBOM), an extension of the Software Bill of Materials (SBOM), is introduced as a standardized, verifiable record of trained AI models and their environments. Our proof-of-concept platform, AIBoMGen, automates the generation of signed AIBOMs by capturing datasets, model metadata, and environment details during training. The training platform acts as a neutral, third-party observer and root of trust. It enforces verifiable AIBOM creation for every job. The system uses cryptographic hashing, digital signatures, and in-toto attestations to ensure integrity and protect against threats such as artifact tampering by dishonest model creators. Our evaluation demonstrates that AIBoMGen reliably detects unauthorized modifications to all artifacts and can generate AIBOMs with negligible performance overhead. These results highlight the potential of AIBoMGen as a foundational step toward building secure and transparent AI ecosystems, enabling compliance with regulatory frameworks like the EUs AI Act.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。