AI Model Lineage Not Defined by Country Labels
The security of artificial intelligence (AI) models has become a pressing concern for governments and organizations worldwide. In a recent blog post, Cisco warns that relying solely on country labels to identify AI origin can lead to inaccurate conclusions about a model's lineage and potential risks.
Cisco conducted research with VAIL and published the findings in a blog post titled 'The 'U.S. vs. China' AI Trap: An Incomplete Proxy for AI Security.' The study analyzed two AI models, Nemotron and Qwen, which were found to have inherited characteristics from each other despite having different country labels.
The researchers used two methods to analyze the model weights and behavioral patterns: Cisco's Model Provenance Kit and VAIL's Behavioral Fingerprinting. Both methods revealed that the models had survived relationships with their upstream counterparts, indicating that post-training and a new publisher name do not necessarily erase detectable relationships.
Cisco emphasizes the importance of considering AI model lineage as part of due diligence when integrating these models into tech stacks. The company suggests treating the publisher identity as one piece of the puzzle, rather than relying solely on country labels. This includes analyzing lineage, training dependencies, behavior analysis, and operational control to ensure potential risks are identified.