arXiv:2508.01074cs.CVcs.CR2025-08ICCV被引 5

用中间数据集和大模型,让神经网络悄悄学会偷来的数据特征。

Evading Data Provenance in Deep Neural Networks

  • 先用版权数据训练教师模型,再通过外部数据集传递无关标识的知识给学生模型。
  • 在11种版权验证方法上均消除版权痕迹,性能超越9种顶尖逃避攻击。
  • 适合关注模型隐私与数据安全的研究者,揭示现有版权保护的漏洞。

当前过度参数化的深度模型高度依赖大规模通用和领域特定数据集,但许多数据集具有专有性或包含敏感信息,无限制训练存在风险。在无法完全防止数据盗用的开放世界中,数据集所有权验证(DOV)成为保护版权的有力手段,可检测未经授权的模型训练并追踪非法行为。由于其多样性和高隐蔽性,规避DOV被认为极为困难。然而,本文指出此前研究多采用过于简化的逃避攻击评估,造成虚假安全感。我们提出一个统一的逃避框架:教师模型首先从版权数据学习,再通过分布外(OOD)数据集作为中介,将任务相关但不带标识性的领域知识转移给代理学生模型。利用视觉-语言模型和大语言模型,从OOD图库中精选最有效且可靠的子集作为最终迁移数据集,并提出选择性地传输任务导向知识,以在泛化能力与逃避效果间取得更好平衡。在涵盖十一种DOV方法的多种数据集上实验表明,该方法能同时消除所有版权标识,显著优于九种顶尖逃避攻击,在泛化性和有效性上表现优异,计算开销适中。作为概念验证,我们揭示了当前DOV方法的关键弱点,强调需长期发展以提升实际可用性。

原文摘要 · Abstract (English)

Modern over-parameterized deep models are highly data-dependent, with large scale general-purpose and domain-specific datasets serving as the bedrock for rapid advancements. However, many datasets are proprietary or contain sensitive information, making unrestricted model training problematic. In the open world where data thefts cannot be fully prevented, Dataset Ownership Verification (DOV) has emerged as a promising method to protect copyright by detecting unauthorized model training and tracing illicit activities. Due to its diversity and superior stealth, evading DOV is considered extremely challenging. However, this paper identifies that previous studies have relied on oversimplistic evasion attacks for evaluation, leading to a false sense of security. We introduce a unified evasion framework, in which a teacher model first learns from the copyright dataset and then transfers task-relevant yet identifier-independent domain knowledge to a surrogate student using an out-of-distribution (OOD) dataset as the intermediary. Leveraging Vision-Language Models and Large Language Models, we curate the most informative and reliable subsets from the OOD gallery set as the final transfer set, and propose selectively transferring task-oriented knowledge to achieve a better trade-off between generalization and evasion effectiveness. Experiments across diverse datasets covering eleven DOV methods demonstrate our approach simultaneously eliminates all copyright identifiers and significantly outperforms nine state-of-the-art evasion attacks in both generalization and effectiveness, with moderate computational overhead. As a proof of concept, we reveal key vulnerabilities in current DOV methods, highlighting the need for long-term development to enhance practicality.

模型安全版权保护数据逃逸大模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。