KinGuard: Hierarchical Kinship-Aware Fingerprinting to Defend Against Large Language Model Stealing

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Xu, Zhenhua, Tian, Xiaoning, Zeng, Wenjun, Xing, Wenpeng, Lu, Tianliang, Li, Gaolei, Chen, Chaochao, Han, Meng
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911388641787904
author Xu, Zhenhua
Tian, Xiaoning
Zeng, Wenjun
Xing, Wenpeng
Lu, Tianliang
Li, Gaolei
Chen, Chaochao
Han, Meng
author_facet Xu, Zhenhua
Tian, Xiaoning
Zeng, Wenjun
Xing, Wenpeng
Lu, Tianliang
Li, Gaolei
Chen, Chaochao
Han, Meng
contents Protecting the intellectual property of large language models requires robust ownership verification. Conventional backdoor fingerprinting, however, is flawed by a stealth-robustness paradox: to be robust, these methods force models to memorize fixed responses to high-perplexity triggers, but this targeted overfitting creates detectable statistical artifacts. We resolve this paradox with KinGuard, a framework that embeds a private knowledge corpus built on structured kinship narratives. Instead of memorizing superficial triggers, the model internalizes this knowledge via incremental pre-training, and ownership is verified by probing its conceptual understanding. Extensive experiments demonstrate KinGuard's superior effectiveness, stealth, and resilience against a battery of attacks including fine-tuning, input perturbation, and model merging. Our work establishes knowledge-based embedding as a practical and secure paradigm for model fingerprinting.
format Preprint
id arxiv_https___arxiv_org_abs_2601_12986
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle KinGuard: Hierarchical Kinship-Aware Fingerprinting to Defend Against Large Language Model Stealing
Xu, Zhenhua
Tian, Xiaoning
Zeng, Wenjun
Xing, Wenpeng
Lu, Tianliang
Li, Gaolei
Chen, Chaochao
Han, Meng
Cryptography and Security
Protecting the intellectual property of large language models requires robust ownership verification. Conventional backdoor fingerprinting, however, is flawed by a stealth-robustness paradox: to be robust, these methods force models to memorize fixed responses to high-perplexity triggers, but this targeted overfitting creates detectable statistical artifacts. We resolve this paradox with KinGuard, a framework that embeds a private knowledge corpus built on structured kinship narratives. Instead of memorizing superficial triggers, the model internalizes this knowledge via incremental pre-training, and ownership is verified by probing its conceptual understanding. Extensive experiments demonstrate KinGuard's superior effectiveness, stealth, and resilience against a battery of attacks including fine-tuning, input perturbation, and model merging. Our work establishes knowledge-based embedding as a practical and secure paradigm for model fingerprinting.
title KinGuard: Hierarchical Kinship-Aware Fingerprinting to Defend Against Large Language Model Stealing
topic Cryptography and Security
url https://arxiv.org/abs/2601.12986