PreGIP: Watermarking the Pretraining of Graph Neural Networks for Deep Intellectual Property Protection

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Dai, Enyan, Lin, Minhua, Wang, Suhang
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866908386773172224
author Dai, Enyan
Lin, Minhua
Wang, Suhang
author_facet Dai, Enyan
Lin, Minhua
Wang, Suhang
contents Pretraining on Graph Neural Networks (GNNs) has shown great power in facilitating various downstream tasks. As pretraining generally requires huge amount of data and computational resources, the pretrained GNNs are high-value Intellectual Properties (IP) of the legitimate owner. However, adversaries may illegally copy and deploy the pretrained GNN models for their downstream tasks. Though initial efforts have been made to watermark GNN classifiers for IP protection, these methods require the target classification task for watermarking, and thus are not applicable to self-supervised pretraining of GNN models. Hence, in this work, we propose a novel framework named PreGIP to watermark the pretraining of GNN encoder for IP protection while maintain the high-quality of the embedding space. PreGIP incorporates a task-free watermarking loss to watermark the embedding space of pretrained GNN encoder. A finetuning-resistant watermark injection is further deployed. Theoretical analysis and extensive experiments show the effectiveness of {\method} in IP protection and maintaining high-performance for downstream tasks.
format Preprint
id arxiv_https___arxiv_org_abs_2402_04435
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle PreGIP: Watermarking the Pretraining of Graph Neural Networks for Deep Intellectual Property Protection
Dai, Enyan
Lin, Minhua
Wang, Suhang
Machine Learning
Artificial Intelligence
Pretraining on Graph Neural Networks (GNNs) has shown great power in facilitating various downstream tasks. As pretraining generally requires huge amount of data and computational resources, the pretrained GNNs are high-value Intellectual Properties (IP) of the legitimate owner. However, adversaries may illegally copy and deploy the pretrained GNN models for their downstream tasks. Though initial efforts have been made to watermark GNN classifiers for IP protection, these methods require the target classification task for watermarking, and thus are not applicable to self-supervised pretraining of GNN models. Hence, in this work, we propose a novel framework named PreGIP to watermark the pretraining of GNN encoder for IP protection while maintain the high-quality of the embedding space. PreGIP incorporates a task-free watermarking loss to watermark the embedding space of pretrained GNN encoder. A finetuning-resistant watermark injection is further deployed. Theoretical analysis and extensive experiments show the effectiveness of {\method} in IP protection and maintaining high-performance for downstream tasks.
title PreGIP: Watermarking the Pretraining of Graph Neural Networks for Deep Intellectual Property Protection
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2402.04435