Fine-Tuning Integrity: Structured Drift Proofs Detect Backdoors via Norm, Rank, and Sparsity Certificates
arXiv·high signal
Shang and Chen propose a cryptographic framework for verifying that fine-tuned models haven't been tampered with — using norm, rank, and sparsity certificates to produce structured drift proofs. An untrusted party can insert backdoors or change safety behavior during fine-tuning while claiming only small updates were made; this framework makes such deception detectable. Directly relevant to anyone accepting fine-tuned models from third parties.