Towards Provable (In)Secure Model Weight Release Schemes

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Yang, Xin, Tang, Bintao, Wang, Yuhao, Ji, Zimo, Zhang, Terry Jingchen, Jiang, Wenyuan
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866909660553936896
author Yang, Xin
Tang, Bintao
Wang, Yuhao
Ji, Zimo
Zhang, Terry Jingchen
Jiang, Wenyuan
author_facet Yang, Xin
Tang, Bintao
Wang, Yuhao
Ji, Zimo
Zhang, Terry Jingchen
Jiang, Wenyuan
contents Recent secure weight release schemes claim to enable open-source model distribution while protecting model ownership and preventing misuse. However, these approaches lack rigorous security foundations and provide only informal security guarantees. Inspired by established works in cryptography, we formalize the security of weight release schemes by introducing several concrete security definitions. We then demonstrate our definition's utility through a case study of TaylorMLP, a prominent secure weight release scheme. Our analysis reveals vulnerabilities that allow parameter extraction thus showing that TaylorMLP fails to achieve its informal security goals. We hope this work will advocate for rigorous research at the intersection of machine learning and security communities and provide a blueprint for how future weight release schemes should be designed and evaluated.
format Preprint
id arxiv_https___arxiv_org_abs_2506_19874
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Towards Provable (In)Secure Model Weight Release Schemes
Yang, Xin
Tang, Bintao
Wang, Yuhao
Ji, Zimo
Zhang, Terry Jingchen
Jiang, Wenyuan
Cryptography and Security
Artificial Intelligence
Recent secure weight release schemes claim to enable open-source model distribution while protecting model ownership and preventing misuse. However, these approaches lack rigorous security foundations and provide only informal security guarantees. Inspired by established works in cryptography, we formalize the security of weight release schemes by introducing several concrete security definitions. We then demonstrate our definition's utility through a case study of TaylorMLP, a prominent secure weight release scheme. Our analysis reveals vulnerabilities that allow parameter extraction thus showing that TaylorMLP fails to achieve its informal security goals. We hope this work will advocate for rigorous research at the intersection of machine learning and security communities and provide a blueprint for how future weight release schemes should be designed and evaluated.
title Towards Provable (In)Secure Model Weight Release Schemes
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2506.19874