model provenance tracing

Designs and implements tools and analyses to trace and verify the lineage and provenance of machine learning models and their artifacts, including recording and detecting provenance marks in parameters and tracing data and intermediate derivation steps across training, fine‑tuning, pruning, and other transformations. Produces methods for attributing contributions to specific actors or datasets and for incremental multi‑user verification of model provenance.

modelprovenancetracing

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.58
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Recommended Survey Paper

Quick overview of the field
View more

Must-Read Papers

Most classic and influential ideas
View more

Model Provenance Testing for Large Language Models

Feb 02, 2025
IN
Ivica Nikolić
🏛️ National University of Singapore | Georgia Institute of Technology

To address the challenge of tracing derivative relationships among large language models (LLMs), this paper introduces the first black-box model provenance verification framework. Unlike prior approaches, it requires no access to model weights or training data—only API-based output queries—and leverages statistical similarity of output distributions to perform model provenance inference. Crucially, it is the first to formalize this task as a multiple hypothesis testing problem, enabling high-confidence detection of derivative relationships. Evaluated on two real-world benchmarks encompassing over 600 models spanning 30M–4B parameters, the framework achieves 90–95% precision and 80–90% recall. Its core contribution is establishing a rigorous black-box provenance paradigm, supporting intellectual property protection, accountability for model misuse, and identification of foundational model issues—thereby providing a deployable technical foundation for LLM governance.

Intellectual PropertyLanguage Model ProvenanceModel Governance

This work addresses the lack of fine-grained provenance tracing in existing multimodal tool-using agents, which renders their reasoning unverifiable due to insufficient linkage between claims in generated answers and the underlying tool observations. To resolve this, the authors propose TRACER, a framework that simultaneously generates responses and constructs sentence-level structured provenance records, explicitly annotating for each statement the corresponding tool invocation round, evidence units, and semantic relations—such as quotation, compression, or inference. TRACER introduces a multi-dimensional verification mechanism to ensure provenance reliability and, for the first time, enables verifiable generation with traceable provenance in multimodal tool use. The framework encodes provenance information as traceable constraints and localized rewards within a reinforcement learning paradigm and introduces TRACE-Bench, a new evaluation benchmark. Experiments show that TRACER achieves 78.23% answer accuracy and 95.72% summary accuracy on this benchmark, outperforming the strongest closed-source baseline by 23.80 percentage points while reducing tool calls by 30%.

claim-level dependencymultimodal tool-using agentsprovenance gap

This study addresses the longstanding challenge of treating machine learning interpretability as a non-functional requirement lacking quantifiable metrics and validation mechanisms. To bridge this gap, the work proposes an innovative approach that reframes interpretability as a verifiable functional requirement through the integration of data and model provenance. By synergizing principles from requirements engineering and machine learning engineering, the authors develop a systematic and operational verification framework. This framework enables, for the first time, the explicit specification and empirical validation of interpretability requirements, thereby substantially enhancing the engineering rigor and trustworthiness of machine learning system development.

interpretabilitymachine learningnon-functional requirements

This work addresses security concerns in open-weight model repositories—such as unauthorized redistribution and falsified provenance—by proposing a model lineage authentication method that integrates knowledge evolution tracking with parameter editing analysis. The approach employs a probe-sample-based knowledge vectorization mechanism to quantify parameter modifications through model editing techniques and introduces an adaptive probing strategy to generate robust knowledge embeddings. This enables consistent lineage verification across diverse model families. By jointly modeling the trajectories of knowledge evolution and parameter modification paths for the first time, the method demonstrates strong and reliable lineage authentication capabilities across classifiers, diffusion models, and large language models, effectively resisting a range of realistic adversarial attacks.

lineage verificationmodel lineagemodel provenance

Atlas: A Framework for ML Lifecycle Provenance&Transparency

Feb 26, 2025
MS
Marcin Spoczynski
🏛️ Intel Labs

The widespread adoption of open-source machine learning (ML) datasets and models has intensified risks including data poisoning, supply-chain attacks, and regulatory non-compliance. Method: This paper proposes the first verifiable, end-to-end ML provenance framework integrating Trusted Execution Environments (TEEs) and transparent logging—built upon SPDX/SLSA standards and leveraging Intel SGX, hash-chain-based immutable logging, and zero-knowledge proofs. Contribution/Results: The framework enables provable artifact authenticity, auditable end-to-end lineage, and co-guaranteed confidentiality and integrity—without compromising intellectual property rights over data or models. Evaluated on two real-world ML pipelines, it achieves 100% metadata tampering detection, full verifiable traceability from training to deployment, and negligible runtime overhead—demonstrating practical viability for secure, compliant ML operations.

Addresses risks in ML lifecycle transparencyBalances regulatory needs with confidentialityEnhances metadata integrity and data security

Latest Papers

What's happening recently
View more

This study addresses the opacity of AI-generated code, which often hinders traceability to its origins and underlying rationale. The work presents the first systematic formulation of a four-dimensional traceability problem for AI-generated code and introduces a novel research framework that integrates causal inference with explainability techniques. This framework enables an automated post-hoc tracing mechanism that links generated code to its prompt, specific training data instances, global data characteristics, and internal model components. Through large-scale empirical evaluation and user studies, the research not only substantiates the necessity of explainable provenance tracing but also identifies key challenges and outlines a feasible technical pathway toward realizing a new paradigm for CodeGenAI.

AI-generated codecode generationexplainable provenance

Existing query-first data synthesis approaches struggle to generate valid and executable tool-use sequences. This work proposes SyntheticAgentTraceQA, a novel framework that introduces an "execution-first" paradigm: it first constructs high-level workflows, maps and validates feasible tool trajectories, and then synthesizes corresponding natural language tasks and reference answers. The method integrates dependency-aware tool assignment, trajectory validation in a controlled environment, and reasoning-augmented annotation generation, followed by fine-tuning and evaluation using the Qwen model. Experimental results demonstrate that this framework substantially improves large language model (LLM) agents’ tool execution accuracy, trajectory consistency, and answer quality. Furthermore, the study reveals that masked supervision outperforms full supervision for models at the 9B scale.

execution traceLLM agentssupervision data

This work addresses the challenge of effectively tracing contributions from multiple parties across successive model derivations—such as fine-tuning, quantization, and pruning—where existing watermarking methods often fail. The authors propose a multi-user white-box watermarking framework tailored for model derivation chains, which, for the first time, enables incremental embedding of watermarks from multiple users while preserving the identifiability and integrity of each watermark throughout the derivation process. Leveraging projection-based encoding, the method selects stable model parameters as carriers, represents watermark bits via projection statistics, and incorporates boundary constraints to limit perturbation magnitude. Experimental results demonstrate that the proposed scheme robustly retains embedded watermarks and accurately attributes contributions across multiple re-watermarking rounds and diverse model compression or optimization operations.

contribution tracingintellectual property protectionmodel derivation chains

Existing approaches struggle to effectively audit the provenance of skill reuse by large language model agents in multimodal, fragmented scenarios, as evidence is dispersed across textual, code, and operational structures. This work proposes SkillTrace, a novel framework that formulates skill reuse auditing as a multi-trajectory provenance problem. SkillTrace constructs a Skill Operation Graph (SOG) by extracting three types of trajectories—expressive, implementational, and operational—and leverages large language models solely during ingestion for efficient, deterministic trajectory matching. The method incorporates a negative-sample calibration mechanism, achieving an AUROC of 0.938 and an F1 score of 0.898 on SkillTrace-Bench. Evaluation on 36,446 real-world skills reveals actionable instances of skill reuse that surpass repository-level baselines.

LLM-agentmulti-traceoperational graph

Industrial research agents often generate experimental trajectories containing invalid or incomplete information, rendering them unreliable for direct decision-making. This work proposes an evidence-oriented framework that automatically transforms such trajectories into structured evidence through a context-isolated generate–verify–repair pipeline. The approach introduces intervention-level claim categorization—distinguishing actionable repairs, diagnostic safeguards, and retained discoveries—and incorporates end-to-end provenance tracking to enable claim scoping and auditability. Experimental results demonstrate that the resulting candidate solutions outperform existing baselines. Audits further reveal that trajectory evolution is non-monotonic, and that applicability assessment constitutes a key performance bottleneck for the controller.

auditable recordsevidence validationindustrial machine learning

Hot Scholars

ZZ

Zibin Zheng

IEEE Fellow, Highly Cited Researcher, Sun Yat-sen University, China
BlockchainSmart ContractServices ComputingSoftware Reliability
MX

Mingwei Xu

Computer Science, Tsinghua University
Internet architecture
IS

Inderjit S. Dhillon

VP, Google Fellow at Google & Professor of Computer Science at UT Austin, Ex-VP at Amazon
Machine LearningDeep LearningLarge Language ModelsNumerical Linear Algebra
JP

Junsong Pu

School of Software Engineering, Sun Yat-sen University
Software EngineerProgramming Language
VA

Vaastav Anand

PhD Student, Max Planck Institute for Software Systems
Distributed SystemsSoftware Engineering