提出最小信息泄露框架,实现验证与隐私保护的精准平衡。
Privacy-Preserving AI Verification via Minimal Information Disclosure

- 用条件互信息量化验证证据中的隐性泄露
- 4类物理测量+6项任务中实现零泄露或最优权衡
- 支持零知识证明,适用于可信硬件与模型验证
AI验证跨越信任边界:验证方需获取足够信息以确认授权结果,但同一证据可能暴露模型、工作负载或硬件的敏感信息。本文提出最小信息泄露(MID),从设计和量化角度衡量面向验证方证据的信息含量。MID通过条件互信息度量‘在已知授权结果后,证据仍泄露多少受保护属性’。该方法具有通用性,可适配不同验证目标、受保护属性、证据来源及部署约束。我们在四类物理测量和六项验证任务上评估MID,涵盖执行类型、硬件身份、计算规模与模型身份。实验使用三个机制设计变量——证据通道、采集策略和发布变换——但方法不限于此。所有任务均实现完全保留验证能力,其中三项达到零测得旁路泄露;其余任务给出明确的隐私-效用权衡边界。此外,我们还实现了基于Groth16 zk-SNARK的零知识证明释放,验证线性投影机制的可行性。
原文摘要 · Abstract (English)
AI verification crosses a trust boundary: a verifier must learn enough to establish an authorized claim, yet the same evidence can reveal sensitive details about the model, workload, or hardware. We introduce minimal information disclosure (MID), which designs and quantifies the information content of verifier-facing evidence itself. MID measures collateral leakage with conditional mutual information: what the release reveals about the protected property after the authorized result is known. MID is general by design: it can accommodate different verification goals, protected properties, evidence sources, and deployment constraints. To demonstrate MID's practicality, we evaluate it on four physical measurements and six verification tasks spanning execution type, hardware identity, compute scale, and model identity. These experiments use three mechanism-design variables--the evidence channel, collection policy, and release transformation--but MID is not limited to these choices and can accommodate other deployable mechanisms. Across these tasks, MID produces three releases with perfect held-out verification and zero measured collateral leakage, while the remaining tasks yield explicit privacy--utility frontiers. MID also supports ZKP-certified releases: we demonstrate our proposed linear-projection mechanism using a Groth16 zk-SNARK.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。