Search papers, labs, and topics across Lattice.
To address model exfiltration in decentralized settings, the authors introduce ZK-Trace, a framework combining recipient-specific Tardos fingerprints, public identity marks, and zero-knowledge credential verification for offline collusion tracing. The system provides mathematically certified false-accusation bounds via an executable interval-arithmetic checker that balances tampering and accusation budgets. Evaluated on federated GNSS interference and CIFAR-10 tasks, it identified 100% of single-owner leaks and 712 of 720 two-party collusions under a 0.001 error budget, surviving cross-architecture transfer while exposing fundamental limits against function-only distillation.
Distributed neural network weights can now be cryptographically audited for multi-party collusion using zero-knowledge proofs, achieving certified sub-0.1% false-accusation rates across hundreds of leaked model mixtures.
Federated global navigation satellite system (GNSS) monitoring distributes a proprietary classifier to partly trusted stations, any of which may leak its copy. ZK-Trace combines public identity marks, recipient-specific Tardos fingerprints, and zero-knowledge credential verification. The registry supports offline tracing without the leaker's cooperation. We establish conditional false-accusation bounds for arbitrary recovered bit patterns, a finite completeness bound under a hidden-bias residual channel, and a deterministic tracing-score bound for correlated feature-distillation errors. An interval-arithmetic checker makes the conditional bound executable and allocates a common budget across accusation and tamper decisions. Under innocent-row independence, the certificate-based evaluation uses a false-naming budget of 0.001 per investigation. It isolates all 160 single-owner copies and traces 712 of 720 two-owner mixtures without naming an innocent. Experiments use a simulated GNSS federation and CIFAR-10. Feature matching preserves the feature mark in 20/20 runs and cross-architecture transfer in 19/20, at copy-accuracy costs of 4.8 and 6.1 percentage points on GNSS and CIFAR-10. Function-only distillation erases the feature mark, and distillation also removes weight-space marks. These results support verifiable tracing under explicit statistical and cryptographic assumptions. Credential knowledge and recipient evidence serve distinct roles.