通过核心点区分模型盗版与同源模型,提升版权保护准确率
DeepCore: Simple Fingerprint Construction for Differentiating Homologous and Piracy Models
- 基于高置信度样本点构造远离决策边界的核点
- 在多种攻击下误检率低于10%,漏检率显著降低
- 适合模型版权保护场景,尤其对抗结构相似模型
深度模型的知识产权保护日益重要。现有水印和指纹方法忽视了使用相似结构或训练数据的同源模型问题。本文提出DeepCore方法,发现模型分类置信度与样本距决策边界距离正相关,盗版模型在高置信度点表现更相似。DeepCore通过优化少数样本点的预测置信度,构建远离决策边界的核点,并利用盗版与同源模型在核点上的行为差异进行识别。设计了两种基于相似性的方法和一种聚类方法,基于模型对核点的预测结果判断是否为盗版。大量实验表明,DeepCore能有效识别各类盗版模型,在多种攻击下实现低于10%的误检率和更低的漏检率,优于现有最优方法。
原文摘要 · Abstract (English)
As intellectual property rights, the copyright protection of deep models is becoming increasingly important. Existing work has made many attempts at model watermarking and fingerprinting, but they have ignored homologous models trained with similar structures or training datasets. We highlight challenges in efficiently querying black-box piracy models to protect model copyrights without misidentifying homologous models. To address these challenges, we propose a novel method called DeepCore, which discovers that the classification confidence of the model is positively correlated with the distance of the predicted sample from the model decision boundary and piracy models behave more similarly at high-confidence classified sample points. Then DeepCore constructs core points far away from the decision boundary by optimizing the predicted confidence of a few sample points and leverages behavioral discrepancies between piracy and homologous models to identify piracy models. Finally, we design different model identification methods, including two similarity-based methods and a clustering-based method to identify piracy models using models' predictions of core points. Extensive experiments show the effectiveness of DeepCore in identifying various piracy models, achieving lower missed and false identification rates, and outperforming state-of-the-art methods.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。