PoTS: Proof-of-Training-Steps for Backdoor Detection in Large Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Seddik, Issam, Souihi, Sami, Tamaazousti, Mohamed, Piergiovanni, Sara Tucci
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908598667313152
author Seddik, Issam
Souihi, Sami
Tamaazousti, Mohamed
Piergiovanni, Sara Tucci
author_facet Seddik, Issam
Souihi, Sami
Tamaazousti, Mohamed
Piergiovanni, Sara Tucci
contents As Large Language Models (LLMs) gain traction across critical domains, ensuring secure and trustworthy training processes has become a major concern. Backdoor attacks, where malicious actors inject hidden triggers into training data, are particularly insidious and difficult to detect. Existing post-training verification solutions like Proof-of-Learning are impractical for LLMs due to their requirement for full retraining, lack of robustness against stealthy manipulations, and inability to provide early detection during training. Early detection would significantly reduce computational costs. To address these limitations, we introduce Proof-of-Training Steps, a verification protocol that enables an independent auditor (Alice) to confirm that an LLM developer (Bob) has followed the declared training recipe, including data batches, architecture, and hyperparameters. By analyzing the sensitivity of the LLMs' language modeling head (LM-Head) to input perturbations, our method can expose subtle backdoor injections or deviations in training. Even with backdoor triggers in up to 10 percent of the training data, our protocol significantly reduces the attacker's ability to achieve a high attack success rate (ASR). Our method enables early detection of attacks at the injection step, with verification steps being 3x faster than training steps. Our results highlight the protocol's potential to enhance the accountability and security of LLM development, especially against insider threats.
format Preprint
id arxiv_https___arxiv_org_abs_2510_15106
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle PoTS: Proof-of-Training-Steps for Backdoor Detection in Large Language Models
Seddik, Issam
Souihi, Sami
Tamaazousti, Mohamed
Piergiovanni, Sara Tucci
Cryptography and Security
Machine Learning
I.2.7; I.2.6
As Large Language Models (LLMs) gain traction across critical domains, ensuring secure and trustworthy training processes has become a major concern. Backdoor attacks, where malicious actors inject hidden triggers into training data, are particularly insidious and difficult to detect. Existing post-training verification solutions like Proof-of-Learning are impractical for LLMs due to their requirement for full retraining, lack of robustness against stealthy manipulations, and inability to provide early detection during training. Early detection would significantly reduce computational costs. To address these limitations, we introduce Proof-of-Training Steps, a verification protocol that enables an independent auditor (Alice) to confirm that an LLM developer (Bob) has followed the declared training recipe, including data batches, architecture, and hyperparameters. By analyzing the sensitivity of the LLMs' language modeling head (LM-Head) to input perturbations, our method can expose subtle backdoor injections or deviations in training. Even with backdoor triggers in up to 10 percent of the training data, our protocol significantly reduces the attacker's ability to achieve a high attack success rate (ASR). Our method enables early detection of attacks at the injection step, with verification steps being 3x faster than training steps. Our results highlight the protocol's potential to enhance the accountability and security of LLM development, especially against insider threats.
title PoTS: Proof-of-Training-Steps for Backdoor Detection in Large Language Models
topic Cryptography and Security
Machine Learning
I.2.7; I.2.6
url https://arxiv.org/abs/2510.15106