Performance-lossless Black-box Model Watermarking

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhao, Na, Chen, Kejiang, Zhang, Weiming, Yu, Nenghai
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909168796958720
author Zhao, Na
Chen, Kejiang
Zhang, Weiming
Yu, Nenghai
author_facet Zhao, Na
Chen, Kejiang
Zhang, Weiming
Yu, Nenghai
contents With the development of deep learning, high-value and high-cost models have become valuable assets, and related intellectual property protection technologies have become a hot topic. However, existing model watermarking work in black-box scenarios mainly originates from training-based backdoor methods, which probably degrade primary task performance. To address this, we propose a branch backdoor-based model watermarking protocol to protect model intellectual property, where a construction based on a message authentication scheme is adopted as the branch indicator after a comparative analysis with secure cryptographic technologies primitives. We prove the lossless performance of the protocol by reduction. In addition, we analyze the potential threats to the protocol and provide a secure and feasible watermarking instance for language models.
format Preprint
id arxiv_https___arxiv_org_abs_2312_06488
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Performance-lossless Black-box Model Watermarking
Zhao, Na
Chen, Kejiang
Zhang, Weiming
Yu, Nenghai
Cryptography and Security
With the development of deep learning, high-value and high-cost models have become valuable assets, and related intellectual property protection technologies have become a hot topic. However, existing model watermarking work in black-box scenarios mainly originates from training-based backdoor methods, which probably degrade primary task performance. To address this, we propose a branch backdoor-based model watermarking protocol to protect model intellectual property, where a construction based on a message authentication scheme is adopted as the branch indicator after a comparative analysis with secure cryptographic technologies primitives. We prove the lossless performance of the protocol by reduction. In addition, we analyze the potential threats to the protocol and provide a secure and feasible watermarking instance for language models.
title Performance-lossless Black-box Model Watermarking
topic Cryptography and Security
url https://arxiv.org/abs/2312.06488