通过微调难样本嵌入隐形水印,实现图像数据所有权的可靠验证。
HoneyImage: Verifiable, Harmless, and Stealthy Dataset Ownership Verification for Image Models
- 选择性修改难样本嵌入不可察觉的可验证痕迹
- 在多个数据集上验证准确率高且对模型性能影响小
- 适合需保护数据版权的医疗、安防等领域
基于图像的AI模型正广泛应用于医疗、安全和消费领域。然而,许多图像数据集包含敏感或专有内容,引发未经授权使用数据的担忧。因此,数据所有者亟需可靠机制来验证其数据是否被用于训练第三方模型。现有方法如后门水印和成员推断,在验证效果与数据完整性之间存在固有权衡。本文提出HoneyImage,一种用于图像识别模型的数据集所有权验证新方法。HoneyImage通过选择性修改少量难样本,嵌入不可察觉但可验证的痕迹,实现在保持数据完整性的同时实现可靠的所有权验证。在四个基准数据集和多种模型架构上的大量实验表明,HoneyImage在维持下游性能几乎不变的前提下,持续保持高验证准确率,且痕迹完全不可感知。该方法为数据所有者提供了实用的所有权保护手段,促进安全数据共享,释放数据驱动AI的全部潜力。
原文摘要 · Abstract (English)
Image-based AI models are increasingly deployed across a wide range of domains, including healthcare, security, and consumer applications. However, many image datasets carry sensitive or proprietary content, raising critical concerns about unauthorized data usage. Data owners therefore need reliable mechanisms to verify whether their proprietary data has been misused to train third-party models. Existing solutions, such as backdoor watermarking and membership inference, face inherent trade-offs between verification effectiveness and preservation of data integrity. In this work, we propose HoneyImage, a novel method for dataset ownership verification in image recognition models. HoneyImage selectively modifies a small number of hard samples to embed imperceptible yet verifiable traces, enabling reliable ownership verification while maintaining dataset integrity. Extensive experiments across four benchmark datasets and multiple model architectures show that HoneyImage consistently achieves strong verification accuracy with minimal impact on downstream performance while maintaining imperceptible. The proposed HoneyImage method could provide data owners with a practical mechanism to protect ownership over valuable image datasets, encouraging safe sharing and unlocking the full transformative potential of data-driven AI.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。