English

Inducing Uncertainty on Open-Weight Models for Test-Time Privacy in Image Recognition

Machine Learning 2025-10-01 v2 Artificial Intelligence Cryptography and Security

Abstract

A key concern for AI safety remains understudied in the machine learning (ML) literature: how can we ensure users of ML models do not leverage predictions on incorrect personal data to harm others? This is particularly pertinent given the rise of open-weight models, where simply masking model outputs does not suffice to prevent adversaries from recovering harmful predictions. To address this threat, which we call *test-time privacy*, we induce maximal uncertainty on protected instances while preserving accuracy on all other instances. Our proposed algorithm uses a Pareto optimal objective that explicitly balances test-time privacy against utility. We also provide a certifiable approximation algorithm which achieves (ε,δ)(\varepsilon, \delta) guarantees without convexity assumptions. We then prove a tight bound that characterizes the privacy-utility tradeoff that our algorithms incur. Empirically, our method obtains at least >3×>3\times stronger uncertainty than pretraining with marginal drops in accuracy on various image recognition benchmarks. Altogether, this framework provides a tool to guarantee additional protection to end users.

Keywords

Cite

@article{arxiv.2509.11625,
  title  = {Inducing Uncertainty on Open-Weight Models for Test-Time Privacy in Image Recognition},
  author = {Muhammad H. Ashiq and Peter Triantafillou and Hung Yun Tseng and Grigoris G. Chrysos},
  journal= {arXiv preprint arXiv:2509.11625},
  year   = {2025}
}
R2 v1 2026-07-01T05:36:15.472Z