arXiv:2509.07879cs.CVcs.AI2025-09ICCV被引 4

通过多任务学习提升模型审计能力,精准识别训练数据来源。

Active Membership Inference Test (aMINT): Enhancing Model Auditability with Multi-Task Learning

  • 设计双模型多任务学习框架,同时训练主模型与审计模型。
  • 在5个公开基准上检测准确率超80%,显著优于已有方法。
  • 适用于模型安全审计,保障隐私与版权,适合监管与合规场景。

主动成员推断测试(aMINT)是一种用于检测特定数据是否被用于机器学习模型训练的方法。在aMINT中,我们提出一种新型多任务学习机制,同时训练两个模型:原始的被审计模型和一个名为MINT模型的辅助模型,后者负责识别被审计模型的训练数据。该方法将模型可审计性作为神经网络训练过程中的优化目标,引入中间激活图作为MINT层的输入,以增强训练数据的检测能力。我们在从轻量级MobileNet到复杂Vision Transformers的多种神经网络架构上进行了测试,并在5个公开基准上评估了性能。结果表明,所提出的aMINT在检测数据是否参与训练时,准确率超过80%,显著优于现有方法。aMINT及其方法论进展有助于提升AI模型的透明度,为实现更强的安全、隐私和版权保护提供支持。

原文摘要 · Abstract (English)

Active Membership Inference Test (aMINT) is a method designed to detect whether given data were used during the training of machine learning models. In Active MINT, we propose a novel multitask learning process that involves training simultaneously two models: the original or Audited Model, and a secondary model, referred to as the MINT Model, responsible for identifying the data used for training the Audited Model. This novel multi-task learning approach has been designed to incorporate the auditability of the model as an optimization objective during the training process of neural networks. The proposed approach incorporates intermediate activation maps as inputs to the MINT layers, which are trained to enhance the detection of training data. We present results using a wide range of neural networks, from lighter architectures such as MobileNet to more complex ones such as Vision Transformers, evaluated in 5 public benchmarks. Our proposed Active MINT achieves over 80% accuracy in detecting if given data was used for training, significantly outperforming previous approaches in the literature. Our aMINT and related methodological developments contribute to increasing transparency in AI models, facilitating stronger safeguards in AI deployments to achieve proper security, privacy, and copyright protection.

模型审计数据隐私多任务学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。