Certified tracing method protects satellite monitoring data against leaks
ZK-Trace: Certified Collusion Tracing with Zero-Knowledge Credentials for Federated GNSS Interference Monitoring
Cryptography and SecurityMachine Learning
Summary
Sometimes, stations that monitor satellite signals share special software that could be copied and leaked without permission. The authors created a system called ZK-Trace that helps find out which station leaked the software without needing their help. Their method uses secret identity marks and special codes checked with cryptography to make sure accusations are fair and accurate. Tests show this system can correctly identify leaks while avoiding false blame, even when the data is mixed or altered. This helps keep satellite monitoring networks secure and trustworthy.
Global Navigation Satellite System (GNSS)Federated monitoringZero-knowledge credentialsCollusion tracingTardos fingerprintingFalse accusation boundsFeature distillationInterval arithmeticCryptographic verificationCopy tracing
Authors
Redwanul Karim, Nisha L. Raichur, Lucas Heublein, Tobias Feigl, Christopher Mutschler, Felix Ott
Abstract
Federated global navigation satellite system (GNSS) monitoring distributes a proprietary classifier to partly trusted stations, any of which may leak its copy. ZK-Trace combines public identity marks, recipient-specific Tardos fingerprints, and zero-knowledge credential verification. The registry supports offline tracing without the leaker's cooperation. We establish conditional false-accusation bounds for arbitrary recovered bit patterns, a finite completeness bound under a hidden-bias residual channel, and a deterministic tracing-score bound for correlated feature-distillation errors. An interval-arithmetic checker makes the conditional bound executable and allocates a common budget across accusation and tamper decisions. Under innocent-row independence, the certificate-based evaluation uses a false-naming budget of 0.001 per investigation. It isolates all 160 single-owner copies and traces 712 of 720 two-owner mixtures without naming an innocent. Experiments use a simulated GNSS federation and CIFAR-10. Feature matching preserves the feature mark in 20/20 runs and cross-architecture transfer in 19/20, at copy-accuracy costs of 4.8 and 6.1 percentage points on GNSS and CIFAR-10. Function-only distillation erases the feature mark, and distillation also removes weight-space marks. These results support verifiable tracing under explicit statistical and cryptographic assumptions. Credential knowledge and recipient evidence serve distinct roles.