Pith. sign in

REVIEW 4 cited by

Tools for Verifying Neural Models' Training Data

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2307.00682 v1 pith:2XYD42SS submitted 2023-07-02 cs.LG cs.CR

classification cs.LGcs.CR
keywords trainingdatamodelmodelsattacksincludingmethodneural
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

It is important that consumers and regulators can verify the provenance of large neural models to evaluate their capabilities and risks. We introduce the concept of a "Proof-of-Training-Data": any protocol that allows a model trainer to convince a Verifier of the training data that produced a set of model weights. Such protocols could verify the amount and kind of data and compute used to train the model, including whether it was trained on specific harmful or beneficial data sources. We explore efficient verification strategies for Proof-of-Training-Data that are compatible with most current large-model training procedures. These include a method for the model-trainer to verifiably pre-commit to a random seed used in training, and a method that exploits models' tendency to temporarily overfit to training data in order to detect whether a given data-point was included in training. We show experimentally that our verification procedures can catch a wide variety of attacks, including all known attacks from the Proof-of-Learning literature.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. In Which Areas of Technical AI Safety Could Geopolitical Rivals Cooperate?

    cs.CY 2025-04 conditional novelty 5.0 of 10

    Based on a four-risk typology, the paper concludes that verification mechanisms and codified protocols are the least risky areas for cooperation between geopolitical rivals on technical AI safety.

  2. Towards Data Governance of Frontier AI Models

    cs.AI 2024-12 conditional novelty 5.0 of 10

    Training data can serve as a governance lever for frontier AI through five proposed mechanisms: canary tokens, mandatory filtering, dataset reporting, data security, and know-your-customer rules.

  3. International Security Applications of Flexible Hardware-Enabled Guarantees

    cs.CR 2025-06 conditional novelty 4.0 of 10

    A policy report argues that hardware-level guarantees on AI chips could make international AI governance agreements stable if states value winning only modestly and fear catastrophe sufficiently.

  4. The Societal Impact of Foundation Models: Advancing Evidence-based AI Policy

    cs.AI 2025-06 conditional novelty 2.0 of 10

    A dissertation that synthesizes prior work on foundation models into a three-part framework: conceptual framing, empirical measurement (HELM, FMTI), and evidence-based AI policy.

Pith tools