The δ-Gene: Inference-Time Physical Unclonable Functions from Architecture-Invariant Output Geometry
Fuente:
Zenodo
Salvato in:
| Autore principale: | |
|---|---|
| Natura: | Recurso digital |
| Lingua: | inglese |
| Pubblicazione: |
Zenodo
2026
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
| _version_ | 1866902336360677376 |
|---|---|
| author | Coslett, Anthony |
| author_facet | Coslett, Anthony |
| contents | <p>As neural language models are deployed in regulated domains, verifiable model provenance becomes a critical security requirement. We construct an Inference-Time Physical Unclonable Function (IT-PUF) that provides a challenge-response authentication protocol for neural networks, achieving zero false acceptances across 1,012 comparisons spanning 23 models and 16 vendor families.</p> <p>The IT-PUF derives its entropy from a geometrically intrinsic behavioral fingerprint—the delta-gene (the third pre-softmax logit gap)—which we prove is invariant to inference temperature and empirically validate as invariant across six distinct neural architectures. We provide a formal impossibility result for fingerprint spoofing: an interval-splitting theorem proves that no adversarial Kullback-Leibler (KL) budget can simultaneously close the fingerprint gap and avoid detection via accumulated noise.</p> <p>To establish that this security does not degrade at scale, we validate an Equation of State across three independent model families spanning a 147x parameter range (0.5B to 72B). We falsify the assumption of unbounded stiffness but discover a strict positive empirical floor (S_min = 1.1797), from which the Cramér-Rao bound guarantees a computable minimum spoofing cost. The theoretical foundation is formally verified in the Coq proof assistant: 311 theorems across 16 files, with zero uses of "Admitted" and zero vacuous definitions.</p> |
| format | Recurso digital |
| id | zenodo_https___doi_org_10_5281_zenodo_18818788 |
| institution | Zenodo |
| language | eng |
| publishDate | 2026 |
| publisher | Zenodo |
| record_format | zenodo |
| spellingShingle | The δ-Gene: Inference-Time Physical Unclonable Functions from Architecture-Invariant Output Geometry Coslett, Anthony physical unclonable functions model authentication neural network fingerprinting challenge-response protocol impossibility theorem formal verification Coq proof assistant Fisher information Cramér-Rao bound extreme value theory logit gap output geometry adversarial robustness model provenance AI security inference-time verification Computer security Cryptography Machine learning EU AI Act IT-PUF logprob fingerprinting AI intellectual property verification <p>As neural language models are deployed in regulated domains, verifiable model provenance becomes a critical security requirement. We construct an Inference-Time Physical Unclonable Function (IT-PUF) that provides a challenge-response authentication protocol for neural networks, achieving zero false acceptances across 1,012 comparisons spanning 23 models and 16 vendor families.</p> <p>The IT-PUF derives its entropy from a geometrically intrinsic behavioral fingerprint—the delta-gene (the third pre-softmax logit gap)—which we prove is invariant to inference temperature and empirically validate as invariant across six distinct neural architectures. We provide a formal impossibility result for fingerprint spoofing: an interval-splitting theorem proves that no adversarial Kullback-Leibler (KL) budget can simultaneously close the fingerprint gap and avoid detection via accumulated noise.</p> <p>To establish that this security does not degrade at scale, we validate an Equation of State across three independent model families spanning a 147x parameter range (0.5B to 72B). We falsify the assumption of unbounded stiffness but discover a strict positive empirical floor (S_min = 1.1797), from which the Cramér-Rao bound guarantees a computable minimum spoofing cost. The theoretical foundation is formally verified in the Coq proof assistant: 311 theorems across 16 files, with zero uses of "Admitted" and zero vacuous definitions.</p> |
| title | The δ-Gene: Inference-Time Physical Unclonable Functions from Architecture-Invariant Output Geometry |
| topic | physical unclonable functions model authentication neural network fingerprinting challenge-response protocol impossibility theorem formal verification Coq proof assistant Fisher information Cramér-Rao bound extreme value theory logit gap output geometry adversarial robustness model provenance AI security inference-time verification Computer security Cryptography Machine learning EU AI Act IT-PUF logprob fingerprinting AI intellectual property verification |
| url | https://doi.org/10.5281/zenodo.18818788 |