Queries, Representation & Detection: The Next 100 Model Fingerprinting Schemes

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Godinot, Augustin, Merrer, Erwan Le, Penzo, Camilla, Taïani, François, Trédan, Gilles
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912388676059136
author Godinot, Augustin
Merrer, Erwan Le
Penzo, Camilla
Taïani, François
Trédan, Gilles
author_facet Godinot, Augustin
Merrer, Erwan Le
Penzo, Camilla
Taïani, François
Trédan, Gilles
contents The deployment of machine learning models in operational contexts represents a significant investment for any organisation. Consequently, the risk of these models being misappropriated by competitors needs to be addressed. In recent years, numerous proposals have been put forth to detect instances of model stealing. However, these proposals operate under implicit and disparate data and model access assumptions; as a consequence, it remains unclear how they can be effectively compared to one another. Our evaluation shows that a simple baseline that we introduce performs on par with existing state-of-the-art fingerprints, which, on the other hand, are much more complex. To uncover the reasons behind this intriguing result, this paper introduces a systematic approach to both the creation of model fingerprinting schemes and their evaluation benchmarks. By dividing model fingerprinting into three core components -- Query, Representation and Detection (QuRD) -- we are able to identify $\sim100$ previously unexplored QuRD combinations and gain insights into their performance. Finally, we introduce a set of metrics to compare and guide the creation of more representative model stealing detection benchmarks. Our approach reveals the need for more challenging benchmarks and a sound comparison with baselines. To foster the creation of new fingerprinting schemes and benchmarks, we open-source our fingerprinting toolbox.
format Preprint
id arxiv_https___arxiv_org_abs_2412_13021
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Queries, Representation & Detection: The Next 100 Model Fingerprinting Schemes
Godinot, Augustin
Merrer, Erwan Le
Penzo, Camilla
Taïani, François
Trédan, Gilles
Machine Learning
Cryptography and Security
The deployment of machine learning models in operational contexts represents a significant investment for any organisation. Consequently, the risk of these models being misappropriated by competitors needs to be addressed. In recent years, numerous proposals have been put forth to detect instances of model stealing. However, these proposals operate under implicit and disparate data and model access assumptions; as a consequence, it remains unclear how they can be effectively compared to one another. Our evaluation shows that a simple baseline that we introduce performs on par with existing state-of-the-art fingerprints, which, on the other hand, are much more complex. To uncover the reasons behind this intriguing result, this paper introduces a systematic approach to both the creation of model fingerprinting schemes and their evaluation benchmarks. By dividing model fingerprinting into three core components -- Query, Representation and Detection (QuRD) -- we are able to identify $\sim100$ previously unexplored QuRD combinations and gain insights into their performance. Finally, we introduce a set of metrics to compare and guide the creation of more representative model stealing detection benchmarks. Our approach reveals the need for more challenging benchmarks and a sound comparison with baselines. To foster the creation of new fingerprinting schemes and benchmarks, we open-source our fingerprinting toolbox.
title Queries, Representation & Detection: The Next 100 Model Fingerprinting Schemes
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2412.13021