PAL*M: Property Attestation for Large Generative Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Chantasantitam, Prach, Caulfield, Adam Ilyas, Duddu, Vasisht, Gunn, Lachlan J., Asokan, N.
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913077664940032
author Chantasantitam, Prach
Caulfield, Adam Ilyas
Duddu, Vasisht
Gunn, Lachlan J.
Asokan, N.
author_facet Chantasantitam, Prach
Caulfield, Adam Ilyas
Duddu, Vasisht
Gunn, Lachlan J.
Asokan, N.
contents Machine learning property attestations allow provers (e.g., model providers or owners) to attest properties of their models/datasets to verifiers (e.g., regulators, customers), enabling accountability towards regulations and policies. But, current approaches do not support generative models or large datasets. We present PAL*M, a property attestation framework for large generative models, illustrated using large language models. PAL*M defines properties across training and inference, leverages confidential virtual machines with security-aware GPUs for coverage of CPU-GPU operations, and proposes using incremental multiset hashing over memory-mapped datasets to efficiently track their integrity. We implement PAL*M on Intel TDX+NVIDIA H100 and evaluate it using state-of-the-art models and datasets, showing PAL*M is efficient, incurring < 11% overhead for common operations. Finally, we use the Tamarin Prover symbolic verification tool to formally model PAL*M's property attestation protocol, confirming that its security guarantees are upheld under the defined threat model.
format Preprint
id arxiv_https___arxiv_org_abs_2601_16199
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle PAL*M: Property Attestation for Large Generative Models
Chantasantitam, Prach
Caulfield, Adam Ilyas
Duddu, Vasisht
Gunn, Lachlan J.
Asokan, N.
Cryptography and Security
Machine learning property attestations allow provers (e.g., model providers or owners) to attest properties of their models/datasets to verifiers (e.g., regulators, customers), enabling accountability towards regulations and policies. But, current approaches do not support generative models or large datasets. We present PAL*M, a property attestation framework for large generative models, illustrated using large language models. PAL*M defines properties across training and inference, leverages confidential virtual machines with security-aware GPUs for coverage of CPU-GPU operations, and proposes using incremental multiset hashing over memory-mapped datasets to efficiently track their integrity. We implement PAL*M on Intel TDX+NVIDIA H100 and evaluate it using state-of-the-art models and datasets, showing PAL*M is efficient, incurring < 11% overhead for common operations. Finally, we use the Tamarin Prover symbolic verification tool to formally model PAL*M's property attestation protocol, confirming that its security guarantees are upheld under the defined threat model.
title PAL*M: Property Attestation for Large Generative Models
topic Cryptography and Security
url https://arxiv.org/abs/2601.16199