Functional Invariants to Watermark Large Transformers

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Fernandez, Pierre, Couairon, Guillaume, Furon, Teddy, Douze, Matthijs
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910300272328704
author Fernandez, Pierre
Couairon, Guillaume
Furon, Teddy
Douze, Matthijs
author_facet Fernandez, Pierre
Couairon, Guillaume
Furon, Teddy
Douze, Matthijs
contents The rapid growth of transformer-based models increases the concerns about their integrity and ownership insurance. Watermarking addresses this issue by embedding a unique identifier into the model, while preserving its performance. However, most existing approaches require to optimize the weights to imprint the watermark signal, which is not suitable at scale due to the computational cost. This paper explores watermarks with virtually no computational cost, applicable to a non-blind white-box setting (assuming access to both the original and watermarked networks). They generate functionally equivalent copies by leveraging the models' invariance, via operations like dimension permutations or scaling/unscaling. This enables to watermark models without any change in their outputs and remains stealthy. Experiments demonstrate the effectiveness of the approach and its robustness against various model transformations (fine-tuning, quantization, pruning), making it a practical solution to protect the integrity of large models.
format Preprint
id arxiv_https___arxiv_org_abs_2310_11446
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Functional Invariants to Watermark Large Transformers
Fernandez, Pierre
Couairon, Guillaume
Furon, Teddy
Douze, Matthijs
Cryptography and Security
Artificial Intelligence
Computation and Language
The rapid growth of transformer-based models increases the concerns about their integrity and ownership insurance. Watermarking addresses this issue by embedding a unique identifier into the model, while preserving its performance. However, most existing approaches require to optimize the weights to imprint the watermark signal, which is not suitable at scale due to the computational cost. This paper explores watermarks with virtually no computational cost, applicable to a non-blind white-box setting (assuming access to both the original and watermarked networks). They generate functionally equivalent copies by leveraging the models' invariance, via operations like dimension permutations or scaling/unscaling. This enables to watermark models without any change in their outputs and remains stealthy. Experiments demonstrate the effectiveness of the approach and its robustness against various model transformations (fine-tuning, quantization, pruning), making it a practical solution to protect the integrity of large models.
title Functional Invariants to Watermark Large Transformers
topic Cryptography and Security
Artificial Intelligence
Computation and Language
url https://arxiv.org/abs/2310.11446