提出可抵抗伪造主张的模型指纹技术,防止他人冒充所有者。
FIT-Print: Towards False-claim-resistant Model Ownership Verification via Targeted Fingerprint
- 用定向优化生成可验证的唯一指纹签名
- 对伪造主张攻击防御率100%,无误报
- 适合保护开源模型知识产权的开发者
模型指纹已成为保护开源模型知识产权的关键机制,提供无需修改模型的非侵入式方案。然而,我们分析发现现有方法在面对伪造主张攻击时存在根本性漏洞:攻击者可虚假声称拥有第三方独立模型。该漏洞源于当前方法缺乏针对性,其模型相似性评估基于任意样本输出,而非与特定预设参考的一致性。为解决此问题,我们提出FIT-Print,一种主动抵御伪造主张攻击的定向指纹范式。通过优化将指纹转化为可验证的定向签名,我们进一步设计两种黑盒指纹方法:基于输出距离的位级FIT-ModelDiff,以及基于特征归因的列表级FIT-LIME。在基准模型和数据集上的广泛评估表明,该框架完全消除伪造主张攻击(100%防御成功率),对独立模型零误报(0.0%),同时对多种模型重用技术保持100%的所有权验证率。
原文摘要 · Abstract (English)
Model fingerprinting has emerged as a crucial mechanism for safeguarding the intellectual property of open-source models, offering a non-intrusive approach that requires no modifications to the protected model. However, our analysis reveals that existing fingerprinting techniques are fundamentally vulnerable to false claim attacks, wherein adversaries can fraudulently assert ownership over independent third-party models. We demonstrate that this vulnerability stems from the untargeted nature of current methods, which evaluate model similarity based on arbitrary sample outputs rather than alignment with a specific, predefined reference. To mitigate this vulnerability, we introduce FIT-Print, a targeted fingerprinting paradigm that actively counters false claim attacks. Specifically, FIT-Print leverages optimization to transform the fingerprint into a verifiable, targeted signature. Building upon this foundation, we propose two black-box fingerprinting methods, the bit-wise FIT-ModelDiff and the list-wise FIT-LIME, which utilize output distances and feature attributions as robust model signatures, respectively. Extensive evaluations across benchmark models and datasets show that our framework perfectly neutralizes false claim attacks (100% defense success rate) and eliminates false alarms on independent models (0.0%), all while maintaining a 100% ownership verification rate against diverse model reuse techniques.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。