arXiv:2510.26420cs.CRcs.AI2025-10被引 2

为数据集所有权验证设计动态水印,防篡改且难察觉。

SSCL-BW: Sample-Specific Clean-Label Backdoor Watermarking for Dataset Ownership Verification

  • 为每张样本生成唯一水印,避免静态模式被识别
  • 在多个基准数据集上实现100%触发率,视觉无损
  • 适合保护高价值图像数据集的知识产权

深度神经网络的快速发展依赖于大规模高质量数据集,但未经授权的商业使用严重侵犯了数据集所有者的知识产权。现有基于后门的数据集所有权验证方法存在固有缺陷:毒化标签水印因标签不一致易被检测,而干净标签水印则技术复杂且在高分辨率图像上失效。此外,两者均采用静态水印模式,易被发现和移除。为此,本文提出样本特定的干净标签后门水印(SSCL-BW)。通过训练基于U-Net的水印样本生成器,该方法为每个样本生成唯一水印,从根本上克服静态水印模式的脆弱性。核心创新在于设计包含三部分的复合损失函数:目标样本损失确保水印有效性,非目标样本损失保证触发可靠性,感知相似性损失维持视觉不可见性。在所有权验证阶段,采用黑盒测试检查可疑模型是否表现出预定义的后门行为。在多个基准数据集上的大量实验表明,该方法有效且对潜在的水印移除攻击具有鲁棒性。

原文摘要 · Abstract (English)

The rapid advancement of deep neural networks (DNNs) heavily relies on large-scale, high-quality datasets. However, unauthorized commercial use of these datasets severely violates the intellectual property rights of dataset owners. Existing backdoor-based dataset ownership verification methods suffer from inherent limitations: poison-label watermarks are easily detectable due to label inconsistencies, while clean-label watermarks face high technical complexity and failure on high-resolution images. Moreover, both approaches employ static watermark patterns that are vulnerable to detection and removal. To address these issues, this paper proposes a sample-specific clean-label backdoor watermarking (i.e., SSCL-BW). By training a U-Net-based watermarked sample generator, this method generates unique watermarks for each sample, fundamentally overcoming the vulnerability of static watermark patterns. The core innovation lies in designing a composite loss function with three components: target sample loss ensures watermark effectiveness, non-target sample loss guarantees trigger reliability, and perceptual similarity loss maintains visual imperceptibility. During ownership verification, black-box testing is employed to check whether suspicious models exhibit predefined backdoor behaviors. Extensive experiments on benchmark datasets demonstrate the effectiveness of the proposed method and its robustness against potential watermark removal attacks.

水印数据安全后门攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。