arXiv:2510.25934cs.LGcs.CR2025-10

用图不变量隐式感知实现无触发鲁棒图神经网络水印

Robust GNN Watermarking via Implicit Perception of Topological Invariants

  • 基于图的代数连通性设计隐式水印,无需触发器
  • 在多种数据集上保持原模型精度,水印准确率更高
  • 对剪枝、量化等操作鲁棒,适合保护模型产权

图神经网络是重要知识产权,但现有水印多依赖后门触发器,在常见模型修改下失效且易引发权属争议。本文提出InvGNN-WM,将所有权绑定于模型对图不变量的隐式感知,实现无触发、黑盒验证,对任务性能影响极小。轻量级头部预测所有者私有载体集上的归一化代数连通性;符号敏感解码器输出比特,校准阈值控制误报率。在多种节点与图分类数据集及骨干网络上,InvGNN-WM保持原有准确率,水印准确率优于基于触发器和压缩的基线方法。其在非结构化剪枝、微调及训练后量化下仍保持强健性;普通知识蒸馏削弱水印,而加入水印损失的知识蒸馏(KD+WM)可恢复。我们提供了不可察觉性和鲁棒性的保障,并证明精确移除水印为NP完全问题。

原文摘要 · Abstract (English)

Graph Neural Networks (GNNs) are valuable intellectual property, yet many watermarks rely on backdoor triggers that break under common model edits and create ownership ambiguity. We present InvGNN-WM, which ties ownership to a model's implicit perception of a graph invariant, enabling trigger-free, black-box verification with negligible task impact. A lightweight head predicts normalized algebraic connectivity on an owner-private carrier set; a sign-sensitive decoder outputs bits, and a calibrated threshold controls the false-positive rate. Across diverse node and graph classification datasets and backbones, InvGNN-WM matches clean accuracy while yielding higher watermark accuracy than trigger- and compression-based baselines. It remains strong under unstructured pruning, fine-tuning, and post-training quantization; plain knowledge distillation (KD) weakens the mark, while KD with a watermark loss (KD+WM) restores it. We provide guarantees for imperceptibility and robustness, and we prove that exact removal is NP-complete.

图神经网络模型水印鲁棒性知识产权

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。