Performance-lossless Black-box Model Watermarking
Fuente:
arXiv
Saved in:
| Main Authors: | , , , |
|---|---|
| Format: | Preprint |
| Published: |
2023
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866909168796958720 |
|---|---|
| author | Zhao, Na Chen, Kejiang Zhang, Weiming Yu, Nenghai |
| author_facet | Zhao, Na Chen, Kejiang Zhang, Weiming Yu, Nenghai |
| contents | With the development of deep learning, high-value and high-cost models have become valuable assets, and related intellectual property protection technologies have become a hot topic. However, existing model watermarking work in black-box scenarios mainly originates from training-based backdoor methods, which probably degrade primary task performance. To address this, we propose a branch backdoor-based model watermarking protocol to protect model intellectual property, where a construction based on a message authentication scheme is adopted as the branch indicator after a comparative analysis with secure cryptographic technologies primitives. We prove the lossless performance of the protocol by reduction. In addition, we analyze the potential threats to the protocol and provide a secure and feasible watermarking instance for language models. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2312_06488 |
| institution | arXiv |
| publishDate | 2023 |
| record_format | arxiv |
| spellingShingle | Performance-lossless Black-box Model Watermarking Zhao, Na Chen, Kejiang Zhang, Weiming Yu, Nenghai Cryptography and Security With the development of deep learning, high-value and high-cost models have become valuable assets, and related intellectual property protection technologies have become a hot topic. However, existing model watermarking work in black-box scenarios mainly originates from training-based backdoor methods, which probably degrade primary task performance. To address this, we propose a branch backdoor-based model watermarking protocol to protect model intellectual property, where a construction based on a message authentication scheme is adopted as the branch indicator after a comparative analysis with secure cryptographic technologies primitives. We prove the lossless performance of the protocol by reduction. In addition, we analyze the potential threats to the protocol and provide a secure and feasible watermarking instance for language models. |
| title | Performance-lossless Black-box Model Watermarking |
| topic | Cryptography and Security |
| url | https://arxiv.org/abs/2312.06488 |