Assumption Gaps in Cryptographic Model Certification Allow Attacks on Privacy-Preserving ML Auditing
A new arXiv preprint demonstrates that current cryptographic model certification (CMC) schemes, which use zero-knowledge proofs to audit machine learning models, can be circumvented by providers who manipulate training data to pass audits but fail on real-world data. The authors show an empirical attack where a model achieves over 99% accuracy on an audit dataset but under 30% on fresh samples. They propose new security definitions and a protocol template to address this vulnerability.
Why it matters: This work highlights a significant vulnerability in privacy-preserving ML auditing protocols, raising concerns about the reliability of model certifications in sensitive applications.
Full story at: arXiv Cryptography and Security ↗