为随机森林模型设计首个水印方案,保护机器学习知识产权。
Watermarking Decision Tree Ensembles
- 在随机森林中嵌入可验证的数字水印
- 水印对常见攻击保持高鲁棒性且不影响模型精度
- 适合需版权保护的决策树模型应用者
保护机器学习模型的知识产权是当前热点,已有大量针对深度神经网络的水印技术。然而,以往研究大多忽视了其他类型模型的水印问题,尤其是用于非感知数据分类任务的决策树集成模型——这一类模型目前处于行业领先水平。本文首次提出专为决策树集成(特别是随机森林)设计的水印方案,重点讨论水印生成与验证机制,并对可能的攻击进行了全面安全分析。实验评估表明,该方案在准确率和对主要威胁的安全性方面表现优异。
原文摘要 · Abstract (English)
Protecting the intellectual property of machine learning models is a hot topic and many watermarking schemes for deep neural networks have been proposed in the literature. Unfortunately, prior work largely neglected the investigation of watermarking techniques for other types of models, including decision tree ensembles, which are a state-of-the-art model for classification tasks on non-perceptual data. In this paper, we present the first watermarking scheme designed for decision tree ensembles, focusing in particular on random forest models. We discuss watermark creation and verification, presenting a thorough security analysis with respect to possible attacks. We finally perform an experimental evaluation of the proposed scheme, showing excellent results in terms of accuracy and security against the most relevant threats.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。