Targeted Data Poisoning for Black-Box Audio Datasets Ownership Verification

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Bouaziz, Wassim, El-Mhamdi, El-Mahdi, Usunier, Nicolas
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866929758188601344
author Bouaziz, Wassim
El-Mhamdi, El-Mahdi
Usunier, Nicolas
author_facet Bouaziz, Wassim
El-Mhamdi, El-Mahdi
Usunier, Nicolas
contents Protecting the use of audio datasets is a major concern for data owners, particularly with the recent rise of audio deep learning models. While watermarks can be used to protect the data itself, they do not allow to identify a deep learning model trained on a protected dataset. In this paper, we adapt to audio data the recently introduced data taggants approach. Data taggants is a method to verify if a neural network was trained on a protected image dataset with top-$k$ predictions access to the model only. This method relies on a targeted data poisoning scheme by discreetly altering a small fraction (1%) of the dataset as to induce a harmless behavior on out-of-distribution data called keys. We evaluate our method on the Speechcommands and the ESC50 datasets and state of the art transformer models, and show that we can detect the use of the dataset with high confidence without loss of performance. We also show the robustness of our method against common data augmentation techniques, making it a practical method to protect audio datasets.
format Preprint
id arxiv_https___arxiv_org_abs_2503_10269
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Targeted Data Poisoning for Black-Box Audio Datasets Ownership Verification
Bouaziz, Wassim
El-Mhamdi, El-Mahdi
Usunier, Nicolas
Cryptography and Security
Machine Learning
Protecting the use of audio datasets is a major concern for data owners, particularly with the recent rise of audio deep learning models. While watermarks can be used to protect the data itself, they do not allow to identify a deep learning model trained on a protected dataset. In this paper, we adapt to audio data the recently introduced data taggants approach. Data taggants is a method to verify if a neural network was trained on a protected image dataset with top-$k$ predictions access to the model only. This method relies on a targeted data poisoning scheme by discreetly altering a small fraction (1%) of the dataset as to induce a harmless behavior on out-of-distribution data called keys. We evaluate our method on the Speechcommands and the ESC50 datasets and state of the art transformer models, and show that we can detect the use of the dataset with high confidence without loss of performance. We also show the robustness of our method against common data augmentation techniques, making it a practical method to protect audio datasets.
title Targeted Data Poisoning for Black-Box Audio Datasets Ownership Verification
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2503.10269