Dropbear: Machine Learning Marketplaces made Trustworthy with Byzantine Model Agreement
Alex Shamis, Peter Pietzuch, Antoine Delignat-Lavaud, Andrew Paverd,, and Manuel Costa

TL;DR
Dropbear introduces a trustworthy ML model marketplace that ensures inference result integrity through Byzantine consensus, enabling secure, multi-model aggregation without sacrificing performance.
Contribution
It is the first marketplace to provide strong integrity guarantees for ML inference by combining Byzantine fault-tolerant consensus with model heterogeneity support.
Findings
Handles 800 requests/sec with ImageNet models across 3 cloud sites
Provides strong integrity guarantees through Byzantine consensus
Achieves performance comparable to state-of-the-art inference systems
Abstract
Marketplaces for machine learning (ML) models are emerging as a way for organizations to monetize models. They allow model owners to retain control over hosted models by using cloud resources to execute ML inference requests for a fee, preserving model confidentiality. Clients that rely on hosted models require trustworthy inference results, even when models are managed by third parties. While the resilience and robustness of inference results can be improved by combining multiple independent models, such support is unavailable in today's marketplaces. We describe Dropbear, the first ML model marketplace that provides clients with strong integrity guarantees by combining results from multiple models in a trustworthy fashion. Dropbear replicates inference computation across a model group, which consists of multiple cloud-based GPU nodes belonging to different model owners. Clients…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPrivacy-Preserving Technologies in Data · Blockchain Technology Applications and Security · Cloud Data Security Solutions
