arXiv:2503.10269cs.CRcs.LG2025-03被引 3

用微调音频数据标记水印,可验证模型是否训练过受保护数据。

Targeted Data Poisoning for Black-Box Audio Datasets Ownership Verification

  • 通过悄悄修改1%数据生成可追踪的‘密钥’行为
  • 在语音命令和ESC50上检测准确率高且不影响模型性能
  • 对常见数据增强手段有鲁棒性,适合实际应用

保护音频数据集的使用是数据所有者的重要关切,尤其在音频深度学习模型兴起的背景下。尽管水印可用于保护数据本身,但无法识别基于受保护数据集训练的模型。本文将近期提出的“数据标记物”方法适配至音频数据,该方法可在仅访问模型前k个预测结果的情况下,验证神经网络是否在受保护的图像数据集上训练过。我们采用有针对性的数据投毒策略,仅改动1%的样本,使其在分布外数据上产生无害但可识别的行为(即‘密钥’)。我们在SpeechCommands和ESC50数据集上,结合主流Transformer模型进行了评估,结果表明该方法能以高置信度检测出数据使用情况,且不降低模型性能。同时,该方法对常见的数据增强技术具有鲁棒性,具备实际部署潜力。

原文摘要 · Abstract (English)

Protecting the use of audio datasets is a major concern for data owners, particularly with the recent rise of audio deep learning models. While watermarks can be used to protect the data itself, they do not allow to identify a deep learning model trained on a protected dataset. In this paper, we adapt to audio data the recently introduced data taggants approach. Data taggants is a method to verify if a neural network was trained on a protected image dataset with top-$k$ predictions access to the model only. This method relies on a targeted data poisoning scheme by discreetly altering a small fraction (1%) of the dataset as to induce a harmless behavior on out-of-distribution data called keys. We evaluate our method on the Speechcommands and the ESC50 datasets and state of the art transformer models, and show that we can detect the use of the dataset with high confidence without loss of performance. We also show the robustness of our method against common data augmentation techniques, making it a practical method to protect audio datasets.

音频安全数据投毒模型溯源水印

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。