EmMark: Robust Watermarks for IP Protection of Embedded Quantized Large Language Models
Fuente:
arXiv
Saved in:
| Main Authors: | , |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866913245789421568 |
|---|---|
| author | Zhang, Ruisi Koushanfar, Farinaz |
| author_facet | Zhang, Ruisi Koushanfar, Farinaz |
| contents | This paper introduces EmMark,a novel watermarking framework for protecting the intellectual property (IP) of embedded large language models deployed on resource-constrained edge devices. To address the IP theft risks posed by malicious end-users, EmMark enables proprietors to authenticate ownership by querying the watermarked model weights and matching the inserted signatures. EmMark's novelty lies in its strategic watermark weight parameters selection, nsuring robustness and maintaining model quality. Extensive proof-of-concept evaluations of models from OPT and LLaMA-2 families demonstrate EmMark's fidelity, achieving 100% success in watermark extraction with model performance preservation. EmMark also showcased its resilience against watermark removal and forging attacks. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2402_17938 |
| institution | arXiv |
| publishDate | 2024 |
| record_format | arxiv |
| spellingShingle | EmMark: Robust Watermarks for IP Protection of Embedded Quantized Large Language Models Zhang, Ruisi Koushanfar, Farinaz Cryptography and Security Computation and Language This paper introduces EmMark,a novel watermarking framework for protecting the intellectual property (IP) of embedded large language models deployed on resource-constrained edge devices. To address the IP theft risks posed by malicious end-users, EmMark enables proprietors to authenticate ownership by querying the watermarked model weights and matching the inserted signatures. EmMark's novelty lies in its strategic watermark weight parameters selection, nsuring robustness and maintaining model quality. Extensive proof-of-concept evaluations of models from OPT and LLaMA-2 families demonstrate EmMark's fidelity, achieving 100% success in watermark extraction with model performance preservation. EmMark also showcased its resilience against watermark removal and forging attacks. |
| title | EmMark: Robust Watermarks for IP Protection of Embedded Quantized Large Language Models |
| topic | Cryptography and Security Computation and Language |
| url | https://arxiv.org/abs/2402.17938 |