Computer-implemented method and detection device for detecting whether training data used to train an examined model contains unauthorized training data
The method uses an OOD detector and prototype extraction to identify unauthorized data in machine learning models, addressing concerns about data integrity and model credibility.
Patent Information
- Application Number
- PCT/EP2024/084112
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-29
- Filing Date
- 2024-11-29
- Publication Date
- 2025-06-05
Smart Images

Figure EP2024084112_05062025_PF_FP_ABST
Abstract
Description
[0001] COMPUTER-IMPLEMENTED METHOD AND DETECTION DEVICE FOR DETECTING WHETHER TRAINING DATA USED TO TRAIN AN EXAMINED MODEL CONTAINS UNAUTHORIZED TRAINING DATA
[0002] TECHNICAL FIELD
[0003] The present invention is directed at a computer-implemented method for detecting whether training data used to train an examined model contains unauthorized training data in addition to authorized training data. The present invention is further directed at a corresponding unauthorized data addition detection device for detecting whether training data used to train an examined model contains unauthorized training data in addition to authorized training data.
[0004] BACKGROUND ART
[0005] In today’s data-driven world, data owners often entrust third parties with their valuable and private datasets to develop and train machine learning (ML) models. In such cases, concerns may emerge as to whether the model was trained exclusively on the dataset provided or whether there has been an unauthorized addition of data to the model’s training set. Such concerns raise other important issues about privacy, data sovereignty, and the model’s credibility.
[0006] An objective of the present invention is the provision of a method and device allowing to detect whether training data used to train an examined model contains unauthorized training data in addition to authorized training data.
[0007] SUMMARY OF THE INVENTION
[0008] According to a first aspect, a computer-implemented method is provided. The computer-implemented method allows detecting whether training data used to train an examined model contains unauthorized training data in addition to authorized training data, the examined model being a machine learning model. The method comprises: training an out-of-distribution (OOD) detector using the authorized training data such as to learn as much as possible about a distribution of the authorized training data, the trained OOD detector being for receiving a prototype as an input and outputting a representation of the input as an output; extracting multiple prototypes from the examined model using a prototype extraction algorithm applied on the examined model, the prototype extraction algorithm being an iterative algorithm including:
[0009] (i) providing random input data as an input of the examined model,
[0010] (ii) through multiple iterations, gradually perturbing the random input data to bring an entropy of an output of the examined model to an entropy below a predefined entropy threshold, (iii) setting the perturbed random input data of an iteration of the multiple iterations for which the entropy is below the predefined entropy threshold as one of the prototypes or setting the perturbed random input data of an n-th iteration of step (ii) as one of the prototypes when n reaches a predefined maximum iteration number, and
[0011] (iv) iteratively repeating the steps (i) to (iii), wherein a new random input data is used in each iteration of step (i) such as to obtain a new prototype forming part of the multiple prototypes in each step (iii); individually using each of the extracted multiple prototypes as the input for the trained OOD detector to calculate a dissimilarity metric for each of the extracted multiple prototypes, the dissimilarity metric expressing a disparity between each of the extracted multiple prototypes and the authorized training data; and based on the dissimilarity metric obtained for each of the extracted multiple prototypes, determining whether the examined model has been trained using unauthorized training data in addition to authorized training data.
[0012] The method of the first aspect allows accurately determining whether the training data used to train an examined model contains unauthorized data. This increases the credibility of the examined model. This method is computer-implemented, meaning that is can conveniently be performed in an automatized manner.
[0013] As used herein, the expression “computer-implemented method” indicates that the method is realized using a computer, a computer network or another programmable apparatus, wherein the method is in particular implemented by executing a computer program on such a computer, computer network or other programmable apparatus.
[0014] The examined model can be any type of machine learning model, in particular one that was programmed and / or trained by a third party provider. The detection as to whether the examined model was trained using unauthorized data is in particular done by the owner of the authorized training data (“data owner” in the following).
[0015] Authorized training data in particular corresponds to data owned by the data owner and / or provided by the data owner for the third party to train the examined model on. Ideally, the examined model should be trained using authorized training data only. “Unauthorized training data” can designate any data that is not authorized training data. In particular, unauthorized training data can be data that has been added to the training data by the third party, usually without the data owner’s knowledge. The method according to the first aspect allows the data owner who has access to the examined model and to the authorized training data to determine whether the examined model is based on the authorized training data only or also on unauthorized training data. The out-of-distribution (OOD) detector is trained using only the authorized training set (and not the unauthorized data set). The OOD detector can be a machine-learning detector which is trained with the purpose of learning as much as possible about the distribution of the authorized training data. This means that the OOD detector is trained such as to optimize and / or increase its knowledge about the distribution of the authorized training data during the training. T raining the ODD detector to learn as much as possible about the distribution of the authorized training data can correspond to overfitting the authorized training data, in particular when the ODD is an autoencoder. The trained OOD detector can be used to identify and classify specific samples not present in its training data set.
[0016] The prototype extraction can be seen as the extraction of data values reflecting the examined model. The prototype can be of the same format as input data for the examined model. The prototype can be defined as a synthesized instance that falls within the distribution parameters of the authorized training dataset. To get a more accurate representation of the examined model, multiple (at least two, preferably at least 50, more preferably at least 1000) prototypes are extracted. In particular, each prototype extraction is based on a random input to the examined model, which is perturbed until an output of the examined model has expected properties.
[0017] In more detail, the random input data can be any randomly generated data, which is for example generated by a random data generator. The step of providing random input data can include receiving or generating the random input data. Preferably, the random input data has a format corresponding to a standard format of inputs to the examined model. The random input data can have a normal distribution. With the random input data as the input, it is highly likely that the examined model outputs a high entropy confidence vector (i.e a low confidence result). The confidence vector can be seen as the result of the examined model and / or as the last layer of the examined model. For example, if the examined model is a classifier allowing to determine a digit shown on an input image forming input data, it is expected that a random input looks like white noise, which the examined model would not be able to classify with a high certainty (with a low entropy).
[0018] In order to obtain a prototype which is representative of the examined model, input data leading to an output of the examined model having a low entropy (an entropy below the predefined entropy threshold, which corresponds to a high-certainty result) should be determined. This is performed in step (ii) of the prototype extraction algorithm, in which the random input data is gradually perturbed. The gradual perturbation can be done such as to obtain an entropy of the output (the output can be a vector of probabilities or confidence vector) that increasingly gets smaller with an increasing number of iterations, preferably until an entropy reaches or is below a predefined entropy threshold. In particular, in an n-th iteration, the random input data can be perturbed based on feedback corresponding to the entropy of the output observed in an (n-1 )-th iteration. The number of iterations performed in step (ii) can be preselected (predefined maximum iteration number) or can correspond to the number of iterations required for the entropy to be below the predefined entropy threshold for the first time.
[0019] In step (Hi) of the prototype extraction algorithm, the perturbed random input data of an iteration (for example the first iteration) for which the entropy is below the predefined entropy threshold, or of an iteration having the predetermined maximum iteration number / count, is set as one of the prototypes. This prototype can be stored for subsequent use.
[0020] In step (iv) of the prototype extraction algorithm, the steps (i) to (iii) are repeated several times, such as to obtain a new prototype in each repetition of steps (i) to (iii). This repetition of steps (i) to (iii) is performed until a desired and / or predefined number of prototypes is extracted from the examined model. The predefined number of prototypes can be between 10 and 10000 prototypes, for example.
[0021] Once the prototypes have been extracted, it can be analyzed how different they are from the authorized training data. Indeed, it is expected that only prototypes being identical or nearly identical to the authorized training data provide an output having an entropy below the predefined entropy threshold. If some of the extracted prototypes provide an output having an entropy below the predefined entropy threshold but without being identical or nearly identical to the authorized training data, this is an indicator that some unauthorized training data has been used. The OOD detector can generate large reconstruction error in case of adding unauthorized data to the training data. A measurement of the difference between the extracted prototypes and the authorized training data can be obtained using the trained OOD detector. This is in particular defined in the step of calculating a dissimilarity metric defined in the method of the first aspect.
[0022] In detail, a dissimilarity metric is calculated individually for each prototype by using the prototype as an input for the trained OOD detector and observing an output of the OOD detector. An output of the OOD detector in particular indicates how close the input is from the authorized training data used for training the OOD detector. The dissimilarity metric is hence an indicator of the disparity (distance, difference) between the currently tested prototype and the authorized training data. The dissimilarity metric is calculated for each individual prototype in the same manner and an overall indicator of whether the examined model has been trained using only the authorized training data can be obtained by averaging or otherwise using all the dissimilarity metrics calculated for each individual prototype.
[0023] According to an embodiment, each iteration of perturbing the random input data in step (ii) includes subtracting a hyperparameter multiplied by a sign of a gradient of the entropy with respect to the random input data from each entry of a vector forming the random input data. That way, the prototype extraction algorithm performs, in each iteration of step (ii), a gradient update similar to the gradient updates used in adversarial examples (“Adversarial examples in the physical world” by Alexey Kurakin, Ian Goodfellow, Samy Bengio, arXiv: 1607.02533) can be used. The hyperparameter can be a constant.
[0024] According to a further embodiment, the OOD comprises an autoencoder, a variational encoder and / or a k-nearest neighbors algorithm. Autoencoders, variational encoders and k-nearest neighbor algorithms are widely used algorithms which are widely available and convenient to train.
[0025] According to a further embodiment, the method further comprises: calculating a dissimilarity metric average by averaging the dissimilarity metric obtained for each prototype, wherein it is determined that the examined model has been trained using unauthorized training data in addition to authorized training data if the dissimilarity metric average is equal to or greater than a predefined upper dissimilarity threshold and / or if the dissimilarity metric average is equal to or smaller than a predefined lower dissimilarity threshold.
[0026] The dissimilarity metrics calculated for each individual prototype can be averaged and compared to a threshold to determine whether the examined model contains unauthorized training data or not.
[0027] According to a further embodiment, the method further comprises: generating multiple shadow models using the examined model, each shadow model having a similar architecture than the examined model and being trained exclusively using the authorized training data; wherein the predefined upper dissimilarity threshold and / or the predefined lower dissimilarity threshold is calculated based on the multiple generated shadow models.
[0028] The shadow models can be seen as “clean models” which are exclusively trained using the authorized training data. Preferably, the shadow models are generated and trained by the data owner. The shadow models have a similar or identical architecture to the examined model, the information about the architecture of the examined model being extractable by the data owner.
[0029] According to a further embodiment, the predefined upper and / or lower dissimilarity threshold is specifically calculated for the examined model by: calculating the dissimilarity metric average for each of the multiple shadow models; and calculating the predefined upper and / or lower dissimilarity threshold as r = pREA ± c oREA, wherein r is the predefined upper and / or lower dissimilarity threshold, pREA is a mean of the dissimilarity metric averages of each of the multiple shadow models, oREA is a standard deviation of the dissimilarity metric averages of each of the multiple shadow models and c is a hyperparameter selected to control a sensitivity of the predefined upper and / or lower dissimilarity threshold.
[0030] This calculation increases the accuracy of the predefined upper and / or lower dissimilarity threshold, thereby allowing to determine whether the training data used to train the examined model contain unauthorized data in a more reliable manner.
[0031] According to a further embodiment, the dissimilarity metric is a mean squared error, a Wasserstein distance, and / or a Euclidean distance. In particular, the dissimilarity metric is a mean squared error, a Wasserstein distance, and / or a Euclidean distance between the input (i.e. the prototype) and the output of the OOD detector.
[0032] According to a second aspect, a computer program product stored on a machine-readable media and comprising machine readable instructions for executing the method according to the first aspect or any embodiment thereof is provided. All features described in view of the first aspect or any embodiment thereof also hold for the computer program product of the second aspect.
[0033] According to a third aspect, an unauthorized data addition detection device for detecting whether training data used to train an examined model contain unauthorized training data in addition to authorized training data is provided. The examined model is a machine learning model. The unauthorized data addition detection device comprises: a training unit for training an out-of-distribution (OOD) detector using the authorized training data such as to learn as much as possible about a distribution of the authorized training data, the trained OOD detector being for receiving a prototype as an input and outputting a representation of the input as an output; an extractor unit for extracting multiple prototypes from the examined model using a prototype extraction algorithm applied on the examined model, the prototype extraction algorithm being an iterative algorithm configured to:
[0034] (i) provide random input data as an input of the examined model,
[0035] (ii) through multiple iterations, gradually perturb the random input data to bring an entropy of an output of the examined model to an entropy below a predefined entropy threshold,
[0036] (iii) set the perturbed random input data of an iteration of the multiple iterations for which the entropy is below the predefined entropy threshold as one of the prototypes or setting the perturbed random input data of an n-th iteration of step (ii) as one of the prototypes when n reaches a predefined maximum iteration number, and
[0037] (iv) iteratively repeat the steps (i) to (iii), wherein a new random input data is used in each iteration of step (i) such as to obtain a new prototype forming part of the multiple prototypes in each step (iii); an analysis unit for individually using each of the extracted multiple prototypes as the input for the trained OOD detector to calculate a dissimilarity metric for each of the extracted multiple prototypes, the dissimilarity metric expressing a disparity between each of the extracted multiple prototypes and the authorized training data; and a determination unit for, based on the dissimilarity metric obtained for each of the extracted multiple prototypes, determining whether the examined model has been trained using unauthorized training data in addition to authorized training data.
[0038] All features described in view of the first aspect or any embodiment thereof also hold for the unauthorized data addition detection device of the third aspect. According to an embodiment, the unauthorized data addition detection device of the third aspect is configured to perform the steps of the method of the first aspect or of any embodiment thereof.
[0039] The present invention will be described more fully hereinafter with reference to the accompanying figures in which like numerals represent like element throughout the different figures, and in which prominent aspects and features of the invention are illustrated.
[0040] BRIEF DESCRIPTION OF THE FIGURES
[0041] Fig. 1 shows a computer-implemented method for detecting whether training data used to train an examined model contains unauthorized training data; and
[0042] Fig. 2 shows an unauthorized data addition detection device.
[0043] DETAILED DESCRIPTION
[0044] The computer-implemented method of Fig. 1 allows detecting whether training data used to train an examined model contains unauthorized training data.
[0045] Let M symbolize a training model (examined model) that has been trained using a specific private dataset D_p (which corresponds to authorized training data) out of the data distribution D, and potentially using unauthorized training data. An algorithm A is used to extract prototypes from the model M. In this context, we assume that the distribution of the prototypes P extracted by A from M resembles to the underlying distribution of D_p, meaning that D_p is similar to P, formally expressed as D_p ~ P.
[0046] Built upon this assumption, the method shown in Fig. 1 allows verifying that M was trained only on authorized training data D_p. The method of Fig. 1 comprises four steps S1 - S4:
[0047] 51 (OOD Detector T raining): T raining an OOD detector on D_p;
[0048] 52 (Prototype Extraction): Using an iterative method, multiple prototypes P representing a distribution D_m of the examined model M are extracted from the examined model M, 53 (Prototype Analysis): Comparing the extracted prototypes P to D_p to calculate a dissimilarity metric; and
[0049] 54 (Determining Result): determining whether training data used to train the examined model includes only authorized training data D_p.
[0050] These steps will be described in detail below.
[0051] In the step S1, an OOD detector is trained using D_p as an input. An auto-encoder (AE), which serves as the OOD detector, is trained to overfit D_p, which will yield a minimal reconstruction error on samples x e D_p. This overfitting corresponds to “learning as much as possible” about the distribution of D_p. As a result, the AE memorizes the training samples in D_p, and consequently it will output a high reconstruction error when used on a sample x' / e D_p (i.e. a sample x’ which does not belong to the authorized training data D_p). The mean squared error (MSE) between the AE’s input and output is used as the reconstruction error: (equation 1)
[0052] In equation 1 , n is the number of dimensions of the vector x. The objective of step S2 is to extract prototypes P from the examined model, so their distributions represent the distribution of the examined model’s training set, denoted as D_m. To this end, a prototype extraction algorithm is applied which can be designated as Entropy-Based Prototypes (EBP), inspired by the work of Amit et al., 2021 , “FOOD: Fast Out-Of-Distribution Detector” (arXiv:2008.06856).
[0053] The EBP algorithm is an iterative method for extracting data prototypes from the examined model M. The algorithm initializes a random sample (random input data) x ~ N(0, 1) (step (i) in Fig. 1 ) and gradually perturbs it (step (ii) in Fig. 1), so that it produces low entropy (high certainty) when proceed by M. EBP operates under the assumption that if the model indicates low entropy of the output for a given input sample, it suggests that the sample is likely similar to a sample that was part of the training set.
[0054] In each perturbation step (ii), the algorithm performs a gradient update similar to the one used in adversarial examples (“Adversarial examples in the physical world” by Alexey Kurakin, Ian Goodfellow, Samy Bengio, 2018, arXiv: 1607.02533). The algorithm stops when the predefined maximal number of steps have been performed or the required entropy for the prototype x is obtained (predefined threshold 0, wherein typically, 0 is set to 10A(~4)) and sets the obtained perturbed random input data as one of the prototypes (step (iii) in Fig. 1 ). The full pseudocode is presented in Algorithm 1 , wherein N is the normal distribution. Algorithm 1 for extracting a prototype x from a model M: procedure EXTRACTION^, M, e) x ^ N(0, 1) while Entropy(M(x)) > 0 do
[0055] E Entropy(M(x)) x <— x - e ■ sign(V^) end while end procedure
[0056] The EBP algorithm is used to extract K prototypes from M, which we assume represents the distribution of the training set D_m of M. This is done by repeating steps (i) to (iii) described above, which corresponds to step (iv) of Fig. 1.
[0057] In the step S3, the K prototypes P extracted in step S2 are individually used as inputs for the AE trained in step S1. For each of the K prototypes P, the AE assigns a corresponding reconstruction error value, which is a dissimilarity metric indication a disparity between the prototype P and the authorized training data D_p. The reconstruction error average (REA) for all of the K prototypes derived from the examined model M is calculated and compared to a predefined threshold denoted as T, which forms the predefined upper dissimilarity threshold. The REA forms a dissimilarity metric average.
[0058] If the REA exceeds the threshold r, it is inferred that the model may have been trained on a dataset comprised of the private dataset D_p (authorized training data) and data from an additional unauthorized data source (unauthorized training data). In this case, in step S4, it is determined that the examined model has been trained based on unauthorized training data. Otherwise, if the REA does not exceed the threshold r, it is inferred that the model may have been trained on a dataset comprising only the private dataset D_p (authorized training data). In this case, in step S4, it is determined that the examined model has been trained based only on authorized training data.
[0059] The threshold r is determined by training N shadow models on D_p and calculating their corresponding REA. r is derived from the relationship between the mean of the REAs and the standard deviation of the REAs. Formally, this threshold can be expressed as: r = pREA ± c ■ oREA (equation 2), where pREA is the mean of the REAs, oREA is the REA’s standard deviation, and c is a hyperparameter that controls the standard deviation weight used to determine the threshold. The choice of c depends on the application in which the method of Fig. 1 is used, and it can be adjusted to control the threshold’s sensitivity. Fig. 2 shows an unauthorized data addition detection device 100, which is a computer comprising software units 101 - 104 allowing to perform the steps S1 - S4 when executed. Namely, the unauthorized data addition detection device 100 includes a training unit 101 for performing step S1 described above, an extractor unit 102 for performing step S2 described above, an analysis unit 103 for performing step S3 described above, and a determination unit 104 for performing step S4 described above.
[0060] The above disclosed subject-matter is to be considered illustrative, and not restrictive, and serves to provide a better understanding of the invention defined by the independent claims.
[0061] REFERENCE NUMERALS
[0062] 100 unauthorized data addition detection device
[0063] 101 training unit 102 extractor unit
[0064] 103 analysis unit
[0065] 104 determination unit
Claims
CLAIMS1 . A computer-implemented method for detecting whether training data used to train an examined model contains unauthorized training data in addition to authorized training data, the examined model being a machine learning model, the method comprising: training (S1) an out-of-distribution (OOD) detector using the authorized training data such as to learn as much as possible about a distribution of the authorized training data, the trained OOD detector being for receiving a prototype as an input and outputting a representation of the input as an output; extracting (S2) multiple prototypes from the examined model using a prototype extraction algorithm applied on the examined model, the prototype extraction algorithm being an iterative algorithm including:(i) providing random input data as an input of the examined model,(ii) through multiple iterations, gradually perturbing the random input data to bring an entropy of an output of the examined model to an entropy below a predefined entropy threshold,(Hi) setting the perturbed random input data of an iteration of the multiple iterations for which the entropy is below the predefined entropy threshold as one of the prototypes or setting the perturbed random input data of an n-th iteration of step (ii) as one of the prototypes when n reaches a predefined maximum iteration number, and(iv) iteratively repeating the steps (i) to (iii), wherein a new random input data is used in each iteration of step (i) such as to obtain a new prototype forming part of the multiple prototypes in each step (iii); individually using each of the extracted multiple prototypes as the input for the trained OOD detector to calculate (S3) a dissimilarity metric for each of the extracted multiple prototypes, the dissimilarity metric expressing a disparity between each of the extracted multiple prototypes and the authorized training data; and based on the dissimilarity metric obtained for each of the extracted multiple prototypes, determining (S4) whether the examined model has been trained using unauthorized training data in addition to authorized training data.
2. The method of claim 1 , wherein each iteration of perturbing the random input data in step (ii) includes subtracting a hyperparameter multiplied by a sign of a gradient of the entropy with respect to the random input data from each entry of a vector forming the random input data.
3. The method of claim 1 or 2, wherein the OOD comprises an autoencoder, a variational encoder and / or a k-nearest neighbors algorithm.
4. The method of any one of claims 1 to 3, wherein the method further comprises:calculating a dissimilarity metric average by averaging the dissimilarity metric obtained for each prototype, wherein it is determined that the examined model has been trained using unauthorized training data in addition to authorized training data if the dissimilarity metric average is equal to or greater than a predefined upper dissimilarity threshold and / or if the dissimilarity metric average is equal to or smaller than a predefined lower dissimilarity threshold.
5. The method according to claim 4, wherein the method further comprises: generating multiple shadow models using the examined model, each shadow model having a similar architecture than the examined model and being trained exclusively using the authorized training data; wherein the predefined upper dissimilarity threshold and / or the predefined lower dissimilarity threshold is calculated based on the multiple generated shadow models.
6. The method of claim 4 and 5, wherein the predefined upper and / or lower dissimilarity threshold is specifically calculated for the examined model by: calculating the dissimilarity metric average for each of the multiple shadow models; and calculating the predefined upper and / or lower dissimilarity threshold as r = pREA ± c oREA, wherein r is the predefined upper and / or lower dissimilarity threshold, pREA is a mean of the dissimilarity metric averages of each of the multiple shadow models, oREA is a standard deviation of the dissimilarity metric averages of each of the multiple shadow models and c is a hyperparameter selected to control a sensitivity of the predefined upper and / or lower dissimilarity threshold.
7. The method of any one of claims 1 to 6, wherein the dissimilarity metric is a mean squared error, a Wasserstein distance, and / or a Euclidean distance.
8. A computer program product stored on a machine-readable media and comprising machine readable instructions for executing the method according to any one of claim 1 to 7.
9. An unauthorized data addition detection device (100) for detecting whether training data used to train an examined model contain unauthorized training data in addition to authorized training data, the examined model being a machine learning model, the unauthorized data addition detection device comprising: a training unit (101) for training an out-of-distribution (OOD) detector using the authorized training data such as to learn as much as possible about a distribution of the authorized training data, the trained OOD detector being for receiving a prototype as an input and outputting a representation of the input as an output;an extractor unit (102) for extracting multiple prototypes from the examined model using a prototype extraction algorithm applied on the examined model, the prototype extraction algorithm being an iterative algorithm configured to:(i) provide random input data as an input of the examined model,(ii) through multiple iterations, gradually perturb the random input data to bring an entropy of an output of the examined model to an entropy below a predefined entropy threshold,(Hi) set the perturbed random input data of an iteration of the multiple iterations for which the entropy is below the predefined entropy threshold as one of the prototypes or setting the perturbed random input data of an n-th iteration of step (ii) as one of the prototypes when n reaches a predefined maximum iteration number, and(iv) iteratively repeat the steps (i) to (Hi), wherein a new random input data is used in each iteration of step (i) such as to obtain a new prototype forming part of the multiple prototypes in each step (iii); an analysis unit (103) for individually using each of the extracted multiple prototypes as the input for the trained OOD detector to calculate a dissimilarity metric for each of the extracted multiple prototypes, the dissimilarity metric expressing a disparity between each of the extracted multiple prototypes and the authorized training data; and a determination unit (104) for, based on the dissimilarity metric obtained for each of the extracted multiple prototypes, determining whether the examined model has been trained using unauthorized training data in addition to authorized training data.
10. The unauthorized data addition detection device of claim 9, which is configured to perform the steps of the method of any one of claims 1 to 7.