Complete Security and Privacy for AI Inference in Decentralized Systems
Zhang, Hongyang, Zhao, Yue, Angione, Claudio, Yang, Harry, Buban, James, Farhan, Ahmad, Johnston, Fielding, Colangelo, Patrick
–arXiv.org Artificial Intelligence
The need for data security and model integrity has been accentuated by the rapid adoption of AI and ML in data-driven domains including healthcare, finance, and security. Large models are crucial for tasks like diagnosing diseases and forecasting finances but tend to be delicate and not very scalable. Decentralized systems solve this issue by distributing the workload and reducing central points of failure. Yet, data and processes spread across different nodes can be at risk of unauthorized access, especially when they involve sensitive information. Nesa solves these challenges with a comprehensive framework using multiple techniques to protect data and model outputs. This includes zero-knowledge proofs for secure model verification. The framework also introduces consensus-based verification checks for consistent outputs across nodes and confirms model integrity. Split Learning divides models into segments processed by different nodes for data privacy by preventing full data access at any single point. For hardware-based security, trusted execution environments are used to protect data and computations within secure zones. Nesa's state-of-the-art proofs and principles demonstrate the framework's effectiveness, making it a promising approach for securely democratizing artificial intelligence. Artificial Intelligence (AI), particularly machine learning (ML), has made significant strides in recent decades. Since the advent of large language models (LLMs) such as ChatGPT [1], Claude [2], Gemini [3], LLaMA [4] and diffusion models [5] such as DALLE-3 [6] and Sora [7], foundation models have garnered considerable attention. While these foundation models exhibit intriguing properties such as in-context learning and chain-of-thought reasoning, concerns about their security and privacy have emerged, especially in distributed or decentralized computing scenarios. For instance, in ML as a service (MLaaS), ensuring the integrity of inference results is paramount. Service providers must demonstrate to customers that the output stems from inputting the customer's prompt into a verified large language model, like GPT-4, and generating the response through model execution, rather than relying on human writers or less advanced models, such as GPT-3.5. This requirement is referred to as model security or model integrity. Meanwhile [8], service providers are reluctant to release their model weights, preferring to keep them confidential.
arXiv.org Artificial Intelligence
Jul-28-2024
- Genre:
- Research Report > Promising Solution (0.34)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology: