KinGuard: Hierarchical Kinship-Aware Fingerprinting to Defend Against Large Language Model Stealing
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866911388641787904 |
|---|---|
| author | Xu, Zhenhua Tian, Xiaoning Zeng, Wenjun Xing, Wenpeng Lu, Tianliang Li, Gaolei Chen, Chaochao Han, Meng |
| author_facet | Xu, Zhenhua Tian, Xiaoning Zeng, Wenjun Xing, Wenpeng Lu, Tianliang Li, Gaolei Chen, Chaochao Han, Meng |
| contents | Protecting the intellectual property of large language models requires robust ownership verification. Conventional backdoor fingerprinting, however, is flawed by a stealth-robustness paradox: to be robust, these methods force models to memorize fixed responses to high-perplexity triggers, but this targeted overfitting creates detectable statistical artifacts. We resolve this paradox with KinGuard, a framework that embeds a private knowledge corpus built on structured kinship narratives. Instead of memorizing superficial triggers, the model internalizes this knowledge via incremental pre-training, and ownership is verified by probing its conceptual understanding. Extensive experiments demonstrate KinGuard's superior effectiveness, stealth, and resilience against a battery of attacks including fine-tuning, input perturbation, and model merging. Our work establishes knowledge-based embedding as a practical and secure paradigm for model fingerprinting. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2601_12986 |
| institution | arXiv |
| publishDate | 2026 |
| record_format | arxiv |
| spellingShingle | KinGuard: Hierarchical Kinship-Aware Fingerprinting to Defend Against Large Language Model Stealing Xu, Zhenhua Tian, Xiaoning Zeng, Wenjun Xing, Wenpeng Lu, Tianliang Li, Gaolei Chen, Chaochao Han, Meng Cryptography and Security Protecting the intellectual property of large language models requires robust ownership verification. Conventional backdoor fingerprinting, however, is flawed by a stealth-robustness paradox: to be robust, these methods force models to memorize fixed responses to high-perplexity triggers, but this targeted overfitting creates detectable statistical artifacts. We resolve this paradox with KinGuard, a framework that embeds a private knowledge corpus built on structured kinship narratives. Instead of memorizing superficial triggers, the model internalizes this knowledge via incremental pre-training, and ownership is verified by probing its conceptual understanding. Extensive experiments demonstrate KinGuard's superior effectiveness, stealth, and resilience against a battery of attacks including fine-tuning, input perturbation, and model merging. Our work establishes knowledge-based embedding as a practical and secure paradigm for model fingerprinting. |
| title | KinGuard: Hierarchical Kinship-Aware Fingerprinting to Defend Against Large Language Model Stealing |
| topic | Cryptography and Security |
| url | https://arxiv.org/abs/2601.12986 |