arXiv:2603.07466cs.CRcs.LG2026-03被引 2

让客户能验证云端大模型微调与推理是否合规

Trusting What You Cannot See: Auditable Fine-Tuning and Inference for Proprietary AI

  • 用轻量级记录与抽样检查机制生成可验证执行痕迹
  • 在可信执行环境内抽查小部分模型和执行过程,确保合规
  • 适合关注云上AI安全与透明度的开发者与企业

基于云的基础设施已成为部署大模型(尤其是大语言模型)的主要平台。微调与推理日益外包给云服务商以简化部署并访问专有模型,但由此产生根本性信任缺口。尽管存在基于密码学与可信执行环境(TEE)的验证方法,但高昂的证明开销与有限的TEE内存使其难以扩展至现代大模型,导致客户无法实际审计这些过程。这种不透明性带来具体安全风险,可能悄然破坏服务完整性。本文提出AFTUNE,一种可审计、可验证的框架,保障云端微调与推理的计算完整性。AFTUNE引入轻量级记录与抽样检查机制,生成可验证的执行轨迹。客户可在事后通过验证TEE中采样的执行片段(仅覆盖模型与轨迹的一小部分)来审计流程是否遵循约定配置。评估表明,AFTUNE仅引入适度开销,使客户端审计成为现实。

原文摘要 · Abstract (English)

Cloud-based infrastructure has become the dominant platform for deploying large models, particularly large language models (LLMs). Fine-tuning and inference are increasingly delegated to cloud providers for simplified deployment and access to proprietary models, yet this creates a fundamental trust gap. Although cryptographic and TEE-based verification approaches exist, prohibitive proving costs and limited TEE memory prevent them from scaling to modern LLMs, leaving clients unable to practically audit these processes. This lack of transparency creates concrete security risks that can silently compromise service integrity. We present AFTUNE, an auditable and verifiable framework that ensures the computational integrity of cloud-based fine-tuning and inference. AFTUNE incorporates a lightweight recording and spot-check mechanism that produces verifiable traces of execution. These traces enable clients to later audit whether the fine-tuning and inference processes followed the agreed configurations, by verifying sampled execution blocks inside a TEE, each covering only a small portion of the model and the execution trace. Our evaluation shows that AFTUNE adds modest overhead and makes auditing practical for clients.

AI安全可信执行模型审计

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。