IrisFP: Adversarial-Example-based Model Fingerprinting with Enhanced Uniqueness and Robustness

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Geng, Ziye, Yang, Guang, Chen, Yihang, Luo, Changqing
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908920084168704
author Geng, Ziye
Yang, Guang
Chen, Yihang
Luo, Changqing
author_facet Geng, Ziye
Yang, Guang
Chen, Yihang
Luo, Changqing
contents We propose IrisFP, a novel adversarial-example-based model fingerprinting framework that enhances both uniqueness and robustness by leveraging multi-boundary characteristics, multi-sample behaviors, and fingerprint discriminative power assessment to generate composite-sample fingerprints. Three key innovations make IrisFP outstanding: 1) It positions fingerprints near the intersection of all decision boundaries - unlike prior methods that target a single boundary - thus increasing the prediction margin without placing fingerprints deep inside target class regions, enhancing both robustness and uniqueness; 2) It constructs composite-sample fingerprints, each comprising multiple samples close to the multi-boundary intersection, to exploit collective behavior patterns and further boost uniqueness; and 3) It assesses the discriminative power of generated fingerprints using statistical separability metrics developed based on two reference model sets, respectively, for pirated and independently-trained models, retains the fingerprints with high discriminative power, and assigns fingerprint-specific thresholds to such retained fingerprints. Extensive experiments show that IrisFP consistently outperforms state-of-the-art methods, achieving reliable ownership verification by enhancing both robustness and uniqueness.
format Preprint
id arxiv_https___arxiv_org_abs_2603_24996
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle IrisFP: Adversarial-Example-based Model Fingerprinting with Enhanced Uniqueness and Robustness
Geng, Ziye
Yang, Guang
Chen, Yihang
Luo, Changqing
Cryptography and Security
We propose IrisFP, a novel adversarial-example-based model fingerprinting framework that enhances both uniqueness and robustness by leveraging multi-boundary characteristics, multi-sample behaviors, and fingerprint discriminative power assessment to generate composite-sample fingerprints. Three key innovations make IrisFP outstanding: 1) It positions fingerprints near the intersection of all decision boundaries - unlike prior methods that target a single boundary - thus increasing the prediction margin without placing fingerprints deep inside target class regions, enhancing both robustness and uniqueness; 2) It constructs composite-sample fingerprints, each comprising multiple samples close to the multi-boundary intersection, to exploit collective behavior patterns and further boost uniqueness; and 3) It assesses the discriminative power of generated fingerprints using statistical separability metrics developed based on two reference model sets, respectively, for pirated and independently-trained models, retains the fingerprints with high discriminative power, and assigns fingerprint-specific thresholds to such retained fingerprints. Extensive experiments show that IrisFP consistently outperforms state-of-the-art methods, achieving reliable ownership verification by enhancing both robustness and uniqueness.
title IrisFP: Adversarial-Example-based Model Fingerprinting with Enhanced Uniqueness and Robustness
topic Cryptography and Security
url https://arxiv.org/abs/2603.24996