arXiv:2501.05614cs.CRcs.AI2025-01被引 3

通过图模型解释嵌入水印,实现模型版权保护

Watermarking Graph Neural Networks via Explanations for Ownership Protection

  • 基于GNN解释的统计差异嵌入水印
  • 水印可抵抗微调与剪枝攻击
  • 支持黑盒验证,避免数据污染

图神经网络(GNN)在工业中广泛应用,其知识产权价值凸显。然而,防止未经授权使用仍具挑战。水印技术可通过向模型嵌入所有权信息提供解决方案。现有方法存在两大局限:一是极少针对图数据或GNN;二是主流基于后门的方法依赖训练数据操纵,易引发误分类导致权属模糊,并可能被数据投毒攻击破坏。本文提出的解释型水印继承了后门方法的优势(如黑盒验证),但无需修改训练数据,从而消除权属歧义和数据依赖。具体而言,通过使GNN解释具有统计显著差异来嵌入水印,所有权需通过统计显著性验证。理论证明,在完全知晓方法的情况下,定位水印属于NP难问题。实验表明,该方法对微调和剪枝攻击具有强鲁棒性。本方案显著提升了GNN知识产权保护能力。

原文摘要 · Abstract (English)

Graph Neural Networks (GNNs) are widely deployed in industry, making their intellectual property valuable. However, protecting GNNs from unauthorized use remains a challenge. Watermarking offers a solution by embedding ownership information into models. Existing watermarking methods have two limitations: First, they rarely focus on graph data or GNNs. Second, the de facto backdoor-based method relies on manipulating training data, which can introduce ownership ambiguity through misclassification and vulnerability to data poisoning attacks that can interrupt the backdoor mechanism. Our explanation-based watermarking inherits the strengths of backdoor-based methods (e.g., black-box verification) without data manipulation, eliminating ownership ambiguity and data dependencies. In particular, we watermark GNN explanations such that these explanations are statistically distinct from others, so ownership claims must be verified through statistical significance. We theoretically prove that, even with full knowledge of our method, locating the watermark is NP-hard. Empirically, our method demonstrates robustness to fine-tuning and pruning attacks. By addressing these challenges, our approach significantly advances GNN intellectual property protection.

图神经网络水印技术版权保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。