Mechanism · Training-transcript verification (proof-of-learning)

Adversarial-example spoofs pass verification at lower cost than training

On this page

← All known flaws

SignificantDemonstrated attackDisputed

Zhang et al. construct proofs that pass the original verification "with significantly less cost than generating a proof by the prover". Their attack uses adversarial-example-style perturbations, and they demonstrate it on CIFAR-10, CIFAR-100 and an ImageNet subset 3. They suggest dynamic thresholds, or proofs built on verifiable computation, as countermeasures 3.

Response

Fang et al., who include the original PoL authors, state that the attack assumes the adversary sets the checkpoint interval k, which the verifier should set, and that the verifier can prevent it by using a small k 4.

Sources: [3] · [4]

Search

Full search page