NSmark: Null Space Based Black-box Watermarking Defense Framework for Language Models

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Zhao, Haodong, Hu, Jinming, Li, Peixuan, Li, Fangqi, Sha, Jinrui, Ju, Tianjie, Chen, Peixuan, Zhang, Zhuosheng, Liu, Gongshen
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866909472440451072
author Zhao, Haodong
Hu, Jinming
Li, Peixuan
Li, Fangqi
Sha, Jinrui
Ju, Tianjie
Chen, Peixuan
Zhang, Zhuosheng
Liu, Gongshen
author_facet Zhao, Haodong
Hu, Jinming
Li, Peixuan
Li, Fangqi
Sha, Jinrui
Ju, Tianjie
Chen, Peixuan
Zhang, Zhuosheng
Liu, Gongshen
contents Language models (LMs) have emerged as critical intellectual property (IP) assets that necessitate protection. Although various watermarking strategies have been proposed, they remain vulnerable to Linear Functionality Equivalence Attack (LFEA), which can invalidate most existing white-box watermarks without prior knowledge of the watermarking scheme or training data. This paper analyzes and extends the attack scenarios of LFEA to the commonly employed black-box settings for LMs by considering Last-Layer outputs (dubbed LL-LFEA). We discover that the null space of the output matrix remains invariant against LL-LFEA attacks. Based on this finding, we propose NSmark, a black-box watermarking scheme that is task-agnostic and capable of resisting LL-LFEA attacks. NSmark consists of three phases: (i) watermark generation using the digital signature of the owner, enhanced by spread spectrum modulation for increased robustness; (ii) watermark embedding through an output mapping extractor that preserves the LM performance while maximizing watermark capacity; (iii) watermark verification, assessed by extraction rate and null space conformity. Extensive experiments on both pre-training and downstream tasks confirm the effectiveness, scalability, reliability, fidelity, and robustness of our approach. Code is available at https://github.com/dongdongzhaoUP/NSmark.
format Preprint
id arxiv_https___arxiv_org_abs_2410_13907
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle NSmark: Null Space Based Black-box Watermarking Defense Framework for Language Models
Zhao, Haodong
Hu, Jinming
Li, Peixuan
Li, Fangqi
Sha, Jinrui
Ju, Tianjie
Chen, Peixuan
Zhang, Zhuosheng
Liu, Gongshen
Cryptography and Security
Artificial Intelligence
Computation and Language
Language models (LMs) have emerged as critical intellectual property (IP) assets that necessitate protection. Although various watermarking strategies have been proposed, they remain vulnerable to Linear Functionality Equivalence Attack (LFEA), which can invalidate most existing white-box watermarks without prior knowledge of the watermarking scheme or training data. This paper analyzes and extends the attack scenarios of LFEA to the commonly employed black-box settings for LMs by considering Last-Layer outputs (dubbed LL-LFEA). We discover that the null space of the output matrix remains invariant against LL-LFEA attacks. Based on this finding, we propose NSmark, a black-box watermarking scheme that is task-agnostic and capable of resisting LL-LFEA attacks. NSmark consists of three phases: (i) watermark generation using the digital signature of the owner, enhanced by spread spectrum modulation for increased robustness; (ii) watermark embedding through an output mapping extractor that preserves the LM performance while maximizing watermark capacity; (iii) watermark verification, assessed by extraction rate and null space conformity. Extensive experiments on both pre-training and downstream tasks confirm the effectiveness, scalability, reliability, fidelity, and robustness of our approach. Code is available at https://github.com/dongdongzhaoUP/NSmark.
title NSmark: Null Space Based Black-box Watermarking Defense Framework for Language Models
topic Cryptography and Security
Artificial Intelligence
Computation and Language
url https://arxiv.org/abs/2410.13907