arXiv:2503.20800cs.CRcs.AI2025-03被引 1

通过信息同位素技术,可从AI生成内容中追溯未经授权的训练数据。

Evidencing Unauthorized Training Data from AI Generated Content using Information Isotopes

  • 借鉴化学同位素原理,设计信息同位素追踪方法。
  • 在10个模型上实现99%准确率,p值<0.001,仅需论文长度数据。
  • 适合普通用户维权,无需AI专业知识即可使用。

随着规模定律的发展,许多AI机构正大规模收集高质量人类数据以构建先进AI系统。然而,在竞争压力下,部分机构可能无意或故意使用受版权或隐私保护的数据进行训练,侵犯数据所有者权利。由于现代AI服务多部署于不透明云平台,仅能获取生成输出,无法访问内部训练信息,使得数据侵权证据难以取证。本文受同位素追踪元素的启发,提出信息同位素概念,并设计一种可检测目标信息同位素的方法,用于识别和证明未经授权的数据使用。我们在10个AI模型(包括GPT-4o、Claude-3.5、DeepSeek)及四个关键领域数据集(医学数据、受版权保护书籍、新闻)上进行实验。结果表明,仅需相当于一篇研究论文长度的数据输入,该方法即可以99%准确率区分训练与非训练数据集,且具有显著证据(p值<0.001)。本工作为个人用户提供了一种无需专业背景即可维护数据权利的普适工具。

原文摘要 · Abstract (English)

In light of scaling laws, many AI institutions are intensifying efforts to construct advanced AIs on extensive collections of high-quality human data. However, in a rush to stay competitive, some institutions may inadvertently or even deliberately include unauthorized data (like privacy- or intellectual property-sensitive content) for AI training, which infringes on the rights of data owners. Compounding this issue, these advanced AI services are typically built on opaque cloud platforms, which restricts access to internal information during AI training and inference, leaving only the generated outputs available for forensics. Thus, despite the introduction of legal frameworks by various countries to safeguard data rights, uncovering evidence of data misuse in modern opaque AI applications remains a significant challenge. In this paper, inspired by the ability of isotopes to trace elements within chemical reactions, we introduce the concept of information isotopes and elucidate their properties in tracing training data within opaque AI systems. Furthermore, we propose an information isotope tracing method designed to identify and provide evidence of unauthorized data usage by detecting the presence of target information isotopes in AI generations. We conduct experiments on ten AI models (including GPT-4o, Claude-3.5, and DeepSeek) and four benchmark datasets in critical domains (medical data, copyrighted books, and news). Results show that our method can distinguish training datasets from non-training datasets with 99\% accuracy and significant evidence (p-value$<0.001$) by examining a data entry equivalent in length to a research paper. The findings show the potential of our work as an inclusive tool for empowering individuals, including those without expertise in AI, to safeguard their data rights in the rapidly evolving era of AI advancements and applications.

数据溯源隐私保护AI取证

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。