arXiv:2409.06130cs.CRcs.AI2024-09被引 3

用 top-k 输出提升模型版权验证的鲁棒性与精度平衡

Revisiting Black-Box Model Ownership Verification through Information Theory

  • 利用模型输出的 top-k 信息增强水印嵌入能力
  • 在图像、文本、表格数据上实现更优的鲁棒-效用权衡
  • 适合关注模型版权保护的工业应用者

现代机器学习模型训练需大量计算资源和数据,是重要的知识产权。模型水印已成为黑盒版权验证的有效手段,但现有方法存在鲁棒性与预测性能之间的固有权衡。本文从信息论视角分析该限制,发现仅依赖预测标签提供的容量不足以在不损害准确率的前提下嵌入鲁棒水印。为此,我们提出一种新框架,利用模型输出的 top-k 结果,拓展水印可用的信息空间,在保持预测性能的同时显著提升有效容量。跨图像、文本和表格领域的大量实验表明,该方法在鲁棒性与实用性之间取得更优平衡,且具备实际部署可行性。

原文摘要 · Abstract (English)

Modern machine learning models require substantial computational resources and data to train, making them valuable intellectual property. Model watermarking has emerged as a practical solution for black-box ownership verification, but existing methods suffer from a persistent trade-off between robustness and predictive utility. In this work, we analyze this limitation from an information-theoretic perspective and identify a fundamental capacity crisis: relying solely on predicted labels provides insufficient capacity to embed robust ownership signals without degrading accuracy. To deal with it, we propose a new black-box ownership verification framework that leverages the top-k output. By exploiting this richer output space, our approach increases the effective capacity available for watermarking while preserving predictive performance. Extensive experiments across image, text, and tabular domains demonstrate that our method achieves a more favorable robustness--utility trade-off than existing approaches, while remaining practical for real-world deployment.

模型水印信息论黑盒验证

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。