arXiv:2501.02704cs.LGcs.CR2025-01中稿 · IEEE Transactions …被引 7

研究后门水印在微调后的持久性,提出无需触发集即可恢复水印的新方法。

Persistence of Backdoor-based Watermarks for Neural Networks: A Comprehensive Evaluation

  • 通过引入训练数据实现水印恢复,不依赖原始触发样本。
  • 微调后若参数变化小,水印可恢复至最高100%触发准确率。
  • 适合关注模型版权保护的开发者与研究人员。

深度神经网络(DNN)因卓越性能广受关注,但其训练成本高昂,常被视为模型所有者的知识产权。在云计算时代,高性能DNN被广泛部署于互联网,催生了基于后门的水印技术以保护专利权。然而,现有水印方案在面对微调等操作时鲁棒性存疑。本文系统评估了近期后门水印在微调场景下的持久性,提出一种无需暴露触发集的数据驱动恢复机制。实验表明,仅在微调后引入训练数据,若模型参数未发生显著偏移,水印可成功恢复;根据触发样本类型,触发准确率最高可达100%。研究还通过损失景观可视化分析恢复机制,并验证在微调阶段引入训练数据有助于缓解水印消失问题。

原文摘要 · Abstract (English)

Deep Neural Networks (DNNs) have gained considerable traction in recent years due to the unparalleled results they gathered. However, the cost behind training such sophisticated models is resource intensive, resulting in many to consider DNNs to be intellectual property (IP) to model owners. In this era of cloud computing, high-performance DNNs are often deployed all over the internet so that people can access them publicly. As such, DNN watermarking schemes, especially backdoor-based watermarks, have been actively developed in recent years to preserve proprietary rights. Nonetheless, there lies much uncertainty on the robustness of existing backdoor watermark schemes, towards both adversarial attacks and unintended means such as fine-tuning neural network models. One reason for this is that no complete guarantee of robustness can be assured in the context of backdoor-based watermark. In this paper, we extensively evaluate the persistence of recent backdoor-based watermarks within neural networks in the scenario of fine-tuning, we propose/develop a novel data-driven idea to restore watermark after fine-tuning without exposing the trigger set. Our empirical results show that by solely introducing training data after fine-tuning, the watermark can be restored if model parameters do not shift dramatically during fine-tuning. Depending on the types of trigger samples used, trigger accuracy can be reinstated to up to 100%. Our study further explores how the restoration process works using loss landscape visualization, as well as the idea of introducing training data in fine-tuning stage to alleviate watermark vanishing.

水印后门攻击模型保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。