EmMark: Robust Watermarks for IP Protection of Embedded Quantized Large Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Ruisi, Koushanfar, Farinaz
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913245789421568
author Zhang, Ruisi
Koushanfar, Farinaz
author_facet Zhang, Ruisi
Koushanfar, Farinaz
contents This paper introduces EmMark,a novel watermarking framework for protecting the intellectual property (IP) of embedded large language models deployed on resource-constrained edge devices. To address the IP theft risks posed by malicious end-users, EmMark enables proprietors to authenticate ownership by querying the watermarked model weights and matching the inserted signatures. EmMark's novelty lies in its strategic watermark weight parameters selection, nsuring robustness and maintaining model quality. Extensive proof-of-concept evaluations of models from OPT and LLaMA-2 families demonstrate EmMark's fidelity, achieving 100% success in watermark extraction with model performance preservation. EmMark also showcased its resilience against watermark removal and forging attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2402_17938
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle EmMark: Robust Watermarks for IP Protection of Embedded Quantized Large Language Models
Zhang, Ruisi
Koushanfar, Farinaz
Cryptography and Security
Computation and Language
This paper introduces EmMark,a novel watermarking framework for protecting the intellectual property (IP) of embedded large language models deployed on resource-constrained edge devices. To address the IP theft risks posed by malicious end-users, EmMark enables proprietors to authenticate ownership by querying the watermarked model weights and matching the inserted signatures. EmMark's novelty lies in its strategic watermark weight parameters selection, nsuring robustness and maintaining model quality. Extensive proof-of-concept evaluations of models from OPT and LLaMA-2 families demonstrate EmMark's fidelity, achieving 100% success in watermark extraction with model performance preservation. EmMark also showcased its resilience against watermark removal and forging attacks.
title EmMark: Robust Watermarks for IP Protection of Embedded Quantized Large Language Models
topic Cryptography and Security
Computation and Language
url https://arxiv.org/abs/2402.17938