arXiv Machine Learning By Ran Canetti, Shafi Goldwasser, Or Zamir

Proofs of Ownership for Machine Learning Models

Read the original on arXiv Machine Learning →

arXiv:2606. 30423v1 Announce Type: new Abstract: With the increasing adoption of Machine Learning, protecting model ownership has become an essential challenge.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv Machine Learning.

arXiv Machine Learning
Sep 10

Characterizing Privacy-Audit Alignment in Behavioral Audit of Machine Unlearning

The paper investigates the privacy risks inherent in auditing machine unlearning (MU) when the audit relies only on querying the model for behavioral signals. It shows that such generic audit schemes inevitably leak information about the retained data set, providing a geometric transfer theorem that bounds the distinguishability of retained set membership based on audit accuracy. The study also analyzes how the unlearned set, target sample, and query protocol influence the privacy‑audit transfer coefficient, with empirical evidence from both convex and non‑convex models supporting the theoretical findings.

By Liou Tang, James Joshi, Ashish Kundu
arXiv Machine Learning
Jul 27

Certified in Theory, Broken in Practice: Assumption Gaps in Cryptographic Model Certification

arXiv:2607. 21839v1 Announce Type: cross Abstract: Privacy-preserving machine learning auditing protocols allow auditors to assess models for properties such as accuracy or fairness, without revealing their internals or training data.

By Carter Luck, Olive Franzese-McLaughlin, Elisaweta Masserova, Akira Takahashi, Antigoni Polychroniadou, Nicolas Papernot
arXiv Machine Learning
Sep 11

SoK: Privacy Attacks on Machine Learning via Explainable AI

The paper surveys 25 studies that use explainable AI to compromise machine learning models, covering attacks such as model extraction, membership inference, and model inversion. It distinguishes between how explanations are obtained—through target releases, attacker-derived methods, secondary disclosure, privileged access, or global artifacts—and shows that explanations can lower extraction costs and reveal membership signals via statistics, recourse distance, and robustness. The authors compare threat models, signals, and defenses, concluding that no single explanation type is always unsafe and that protection must be tailored to the specific acquisition path and target asset.

By Abdullah Caglar Oksuz, Anisa Halimi, Erman Ayday