Confidential Guardian: Cryptographically Prohibiting the Abuse of Model Abstention
Rabanser, Stephan, Shamsabadi, Ali Shahin, Franzese, Olive, Wang, Xiao, Weller, Adrian, Papernot, Nicolas
Cautious predictions -- where a machine learning model abstains when uncertain -- are crucial for limiting harmful errors in safety-critical applications. In this work, we identify a novel threat: a dishonest institution can exploit these mechanisms to discriminate or unjustly deny services under the guise of uncertainty. We demonstrate the practicality of this threat by introducing an uncertainty-inducing attack called Mirage, which deliberately reduces confidence in targeted input regions, thereby covertly disadvantaging specific individuals. At the same time, Mirage maintains high predictive performance across all data points. To counter this threat, we propose Confidential Guardian, a framework that analyzes calibration metrics on a reference dataset to detect artificially suppressed confidence. Additionally, it employs zero-knowledge proofs of verified inference to ensure that reported confidence scores genuinely originate from the deployed model. This prevents the provider from fabricating arbitrary model confidence values while protecting the model's proprietary details. Our results confirm that Confidential Guardian effectively prevents the misuse of cautious predictions, providing verifiable assurances that abstention reflects genuine model uncertainty rather than malicious intent.
Jun-2-2025
- Country:
- Europe
- Austria (0.04)
- France (0.04)
- Germany > North Rhine-Westphalia
- Cologne Region > Bonn (0.04)
- Spain > Catalonia
- Barcelona Province > Barcelona (0.04)
- United Kingdom > England
- Cambridgeshire > Cambridge (0.04)
- North America
- Canada > Ontario
- Toronto (0.14)
- United States
- California > Los Angeles County
- Long Beach (0.04)
- Hawaii > Honolulu County
- Honolulu (0.04)
- Maryland > Baltimore (0.04)
- California > Los Angeles County
- Canada > Ontario
- Oceania > Australia
- New South Wales > Sydney (0.04)
- Europe
- Genre:
- Research Report > New Finding (0.68)
- Industry:
- Banking & Finance (0.67)
- Government (1.00)
- Health & Medicine (1.00)
- Information Technology > Security & Privacy (1.00)
- Law (1.00)
- Technology: