Abstract

Artificial intelligence (AI) models are increasingly deployed through remote services, making model misappropriation a growing concern. Existing approaches, including watermarking, fingerprinting, and model similarity analysis, primarily rely on predefined evidence or direct behavioral comparison and do not explicitly evaluate whether the claimant currently possesses and can utilize model-dependent information relevant to the claimed model identity. In this paper, we propose Third-Party Challenge-Response Identity Verification (TP-CRIV) for AI models. TP-CRIV targets a third-party verification setting in which the verifier has neither white-box nor API access to the claimant's model, can interact with the suspicious deployed service only through its ordinary black-box inference interface, and does not require protocol-specific cooperation from the service provider. Under these constraints, the framework enables the verifier to obtain empirical evidence as to whether the claimant locally possesses a model satisfying a predeclared identity relative to the deployed model. Verification is conducted under fresh, previously undisclosed requirements and network isolation, so that the demonstrated capability cannot rely on online external assistance after challenge disclosure. The resulting evidence is interpreted relative to independently specified and calibrated matching and non-matching operating situations and is statistical rather than cryptographic. We instantiate TP-CRIV for CNN image classifiers using probability-control-based witness generation. Experiments on ten ImageNet-pretrained TorchVision models demonstrate clear same/cross-model separation and finite-challenge verification using independently calibrated thresholds.

Keywords

Subject

Publication details

DOI
10.1109/access.2026.3739696
Journal
Not available
Open access
Green open access

Cite this article

APA 7

Sano, T., Kuribayashi, M., Sakai, M., Isobe, S., Koizumi, E., Zhang, Z., & Matsumoto, S. (2026). TP-CRIV: A Framework for Third-Party Challenge-Response Identity Verification of AI Models. https://doi.org/10.1109/access.2026.3739696

MLA 9

Sano, Teruki, et al. "TP-CRIV: A Framework for Third-Party Challenge-Response Identity Verification of AI Models." https://doi.org/10.1109/access.2026.3739696.

Chicago (author–date)

Sano, Teruki, Minoru Kuribayashi, Masao Sakai, Shuji Isobe, Eisuke Koizumi, Zhang Zhang, and Satoru Matsumoto. 2026. "TP-CRIV: A Framework for Third-Party Challenge-Response Identity Verification of AI Models." https://doi.org/10.1109/access.2026.3739696.

Harvard

Sano, T., Kuribayashi, M., Sakai, M., Isobe, S., Koizumi, E., Zhang, Z. and Matsumoto, S. (2026) 'TP-CRIV: A Framework for Third-Party Challenge-Response Identity Verification of AI Models', doi:10.1109/access.2026.3739696.

Vancouver

Sano T, Kuribayashi M, Sakai M, Isobe S, Koizumi E, Zhang Z, et al. TP-CRIV: A Framework for Third-Party Challenge-Response Identity Verification of AI Models. doi:10.1109/access.2026.3739696

IEEE

T. Sano, M. Kuribayashi, M. Sakai, S. Isobe, E. Koizumi, Z. Zhang, and S. Matsumoto, "TP-CRIV: A Framework for Third-Party Challenge-Response Identity Verification of AI Models," doi: 10.1109/access.2026.3739696.