arXiv:2508.01784cs.CRcs.AI2025-08被引 4

为专家模型合并后的知识产权归属问题提供指纹追踪方案

RouteMark: A Fingerprint for Intellectual Property Attribution in Routing-based Model Merging

  • 通过路由行为设计专家级指纹,识别任务专属专家
  • 在多种任务和架构下准确匹配重复使用的专家,区分无关专家
  • 对结构与参数篡改均具鲁棒性,适合模型版权保护场景

基于专家混合(MoE)的模型合并已成为整合多个任务专用模型的可扩展方案,其中每个专家源自特定任务微调的模型。尽管该方法有效实现多任务融合,却带来一个关键而未被充分研究的问题:合并后如何归属并保护各专家的知识产权(IP)。我们提出RouteMark框架,通过设计专家路由指纹实现合并后MoE模型的IP保护。核心洞察是:任务专属专家在探测输入下表现出稳定且独特的路由行为。为此,我们利用两种互补统计量构建专家级指纹:路由评分指纹(RSF),量化专家激活强度;路由偏好指纹(RPF),刻画使专家优先激活的输入分布。这些指纹可复现、任务可区分且轻量易建。为实现归属与篡改检测,我们引入基于相似度的匹配算法,比较可疑模型与参考(受害)模型间专家指纹。大量实验表明,无论在何种任务或基于CLIP的MoE架构中,RouteMark均能对重复使用的专家保持高相似度,与无关专家明显分离。同时,它对结构篡改(专家替换、增删)和参数篡改(微调、剪枝、排列)均保持鲁棒性,优于基于权重与激活的基线方法。本工作为基于MoE的模型合并中的知识产权验证奠定了实用且普适的基础。

原文摘要 · Abstract (English)

Model merging via Mixture-of-Experts (MoE) has emerged as a scalable solution for consolidating multiple task-specific models into a unified sparse architecture, where each expert is derived from a model fine-tuned on a distinct task. While effective for multi-task integration, this paradigm introduces a critical yet underexplored challenge: how to attribute and protect the intellectual property (IP) of individual experts after merging. We propose RouteMark, a framework for IP protection in merged MoE models through the design of expert routing fingerprints. Our key insight is that task-specific experts exhibit stable and distinctive routing behaviors under probing inputs. To capture these patterns, we construct expert-level fingerprints using two complementary statistics: the Routing Score Fingerprint (RSF), quantifying the intensity of expert activation, and the Routing Preference Fingerprint (RPF), characterizing the input distribution that preferentially activates each expert. These fingerprints are reproducible, task-discriminative, and lightweight to construct. For attribution and tampering detection, we introduce a similarity-based matching algorithm that compares expert fingerprints between a suspect and a reference (victim) model. Extensive experiments across diverse tasks and CLIP-based MoE architectures show that RouteMark consistently yields high similarity for reused experts and clear separation from unrelated ones. Moreover, it remains robust against both structural tampering (expert replacement, addition, deletion) and parametric tampering (fine-tuning, pruning, permutation), outperforming weight- and activation-based baseliness. Our work lays the foundation for RouteMark as a practical and broadly applicable framework for IP verification in MoE-based model merging.

模型合并知识产权路由指纹专家系统

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。