Paper 2026/2279

A Cryptographic Perspective on Fingerprinting Machine Learning Model Weights

Huijia Lin, University of Washington
Kameron Shahabi, University of Washington
Abstract

We introduce a cryptographic framework for fingerprinting machine learning models, enabling model providers to train models that can later be attributed to them. Our framework captures an honest setting in which providers distribute base models that users may subsequently modify to adapt them to their own applications (e.g., through finetuning). We formalize three properties for fingerprinting schemes: (1) quality preservation or undetectability: fingerprinted models must remain computationally indistinguishable from models produced by an underlying training algorithm, (2) robustness: the fingerprint must remain detectable even after the model weights are subject to permitted modification, and (3) unforgeability: no computationally bounded trainer can forge the fingerprint except by applying a permitted modification to an existing fingerprinted model. Under the continuous learning with errors assumption (Bruna et al, 2021), we construct a robust and unforgeable fingerprinting scheme for modifications in $\ell_2$. The scheme achieves undetectability with respect to any given noisy training algorithm, meaning any algorithm whose output weights can be decomposed into independent Gaussian and non-Gaussian components. Along the way, we introduce two new technical tools. The first is a form of steganography; we develop a method for undetectably modifying a noisy training algorithm so that its output weights secretly encode a message. The embedded message remains decodable even after bounded $\ell_2$ perturbations to the weights. Second, we introduce the pancake alignment problem, a "semi-search" variant of homogeneous continuous learning with errors (hCLWE). Given hCLWE samples generated from a random secret, the goal is to recover a direction that is sufficiently aligned with the secret. We provide evidence for the hardness of pancake alignment in certain parameter regimes via reductions from continuous learning with errors.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
fingerprintingmachine learningsteganographyCLWE
Contact author(s)
rachel @ cs washington edu
kshahabi @ cs washington edu
History
2026-10-03: approved
2026-09-30: received
See all versions
Short URL
https://ia.cr/2026/2279
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2279,
      author = {Huijia Lin and Kameron Shahabi},
      title = {A Cryptographic Perspective on Fingerprinting Machine Learning Model Weights},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2279},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2279}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.