arXiv AI

TP-CRIV: A Framework for Third-Party Challenge-Response Identity Verification of AI Models

The paper introduces TP-CRIV, a framework for verifying the identity of AI models through third‑party challenge‑response interactions without requiring white‑box or API access. TP-CRIV operates in a black‑box setting, using fresh, undisclosed challenges and network isolation to ensure that verification relies solely on the claimant’s local model. The authors demonstrate the approach on ten ImageNet‑pretrained CNNs, achieving clear separation between same and cross‑model responses with statistically calibrated thresholds.

Hugging Face Trending Papers
Sep 24

TP-CRIV: A Framework for Third-Party Challenge-Response Identity Verification of AI Models

The paper introduces TP-CRIV, a framework for verifying the identity of AI models through third‑party challenge‑response interactions. It operates without white‑box or API access, relying only on black‑box inference and fresh, undisclosed challenges to gather empirical evidence of model possession. The authors demonstrate the method on ten ImageNet‑pretrained CNNs, achieving clear separation between matching and non‑matching models with statistically calibrated thresholds.

arXiv Machine Learning
Sep 11

CertDW: Towards Certified Dataset Ownership Verification via Conformal Calibration

The paper introduces CertDW, a certified dataset watermark and ownership verification method that remains reliable even under malicious perturbations. By leveraging conformal prediction, it defines two statistical measures—principal probability (PP) and watermark robustness (WR)—to evaluate model stability on benign versus watermarked samples. The authors derive certification conditions linking WR to a PP-based threshold and provide a high‑probability bound on false positives, enabling robust ownership verification when a suspicious model’s WR exceeds the PP values of benign models.

By Ting Qiao, Yiming Li, Jianbin Li, Yingjia Wang, Leyi Qi, Junfeng Guo, Ruili Feng, Dacheng Tao
arXiv AI
Jun 2

Catch-Only-One: Non-Transferable Examples for Model-Specific Authorization

arXiv:2510. 10982v2 Announce Type: replace-cross Abstract: Recent AI regulations increasingly emphasize the need for mechanisms that preserve the utility of data for AI innovation while preventing misuse, particularly by enforcing purpose limitation in downstream AI applications.

By Zihan Wang, Zhiyong Ma, Zhongkui Ma, Shuofeng Liu, Akide Liu, Derui Wang, Minhui Xue, Guangdong Bai
arXiv AI
6d ago

Can Pixels Alone Reveal Image Origin? Minimax Limits and Learnable Interfaces for Passive Provenance

The paper investigates whether pixels alone can determine an image’s origin—human, AI class, or specific generator—under adversarial edits. It establishes a minimax limit: the best possible robust acceptance gap equals the minimum total‑variation distance between the target distribution and attacked source distributions, independent of verifier design. The study also shows that practical public verifiers can fail before reaching this theoretical ceiling, highlighting the need to evaluate both statistical limits and deployed verifier behavior separately.

By Kai Yao
arXiv Computer Vision
Aug 28

Binding Biometrics with AI Agent Identifiers for Delegation of Authority

The paper introduces BIND, a framework that binds a human’s biometric data to an AI agent’s identity and task-specific authority, enabling secure, real‑time delegation of control. By generating a token that an AI agent presents to an Identity Auditor, the system performs biometric authentication and recovers the agent’s ID and scope, providing non‑repudiable proof of human oversight. A practical implementation using face features and a fuzzy commitment scheme with turbo error‑correcting codes achieves a 96% true match rate at zero false match rate and supports 1024‑bit agent tokens.

By Joseph Geo Benjamin, Anil K Jain, Karthik Nandakumar
arXiv AI
Aug 11

Targeted Counterfactual Fingerprinting for Black-Box LLM Ownership Verification

arXiv:2608. 08195v1 Announce Type: cross Abstract: Large language models (LLMs) are high-value assets that can be derived through redeployment, fine-tuning, quantization, or further alignment.

By Yutong Wu, Xiaofan Bai, Shixin Li, Pingyi Hu, Ziqi Zhou, Zilong Wang, Xiaojing Ma, Songfeng Lu, Yuhong Li, Jin Xuan, Yi Wang, Dongmei Zhang, Bin Benjamin Zhu