Mechanism · Training-transcript verification (proof-of-learning)
Small data changes and masked hyperparameters may go undetected
On this page
SignificantOpen questionOpen
Choi et al. state that their protocol cannot yet detect modest data additions, such as inserted backdoors. They note that attacks could be hidden with "cleverly chosen hyperparameters", such as a temporarily lower learning rate than reported, and that the protocol does not apply to online or reinforcement learning 6.
Sources: [6]