arXiv:2512.14439cs.CRcs.CV2025-12

首个视频识别数据集版权审计方法,可隐蔽标记并追踪模型侵权使用。

VICTOR: Dataset Copyright Auditing in Video Recognition Systems

  • 通过修改少量视频样本(如1%)增强模型输出差异,实现隐蔽标记。
  • 在多个模型和数据集上验证,仅修改1%样本即可有效检测侵权行为。
  • 对视频扰动和模型变化具有鲁棒性,适合内容安全与版权保护场景。

视频识别系统日益广泛应用于内容推荐、安全监控等日常场景。为提升模型性能,众多机构发布了高质量公开数据集,但这些数据集也面临被滥用和侵权的风险。现有版权审计方法主要针对图像领域,而视频数据因引入时间维度,导致现有方法难以适用。本文提出VICTOR,首个面向视频识别系统的数据集版权审计方法。通过设计通用且隐蔽的样本修改策略,仅需修改极小比例样本(如1%),即可显著放大目标模型在训练后输出的差异。发布修改样本与未发布原始样本间的预测行为差异,成为版权审计的关键依据。大量实验表明,VICTOR在多种模型和数据集上表现优异,且对训练视频或目标模型的多种扰动具备鲁棒性。

原文摘要 · Abstract (English)

Video recognition systems are increasingly being deployed in daily life, such as content recommendation and security monitoring. To enhance video recognition development, many institutions have released high-quality public datasets with open-source licenses for training advanced models. At the same time, these datasets are also susceptible to misuse and infringement. Dataset copyright auditing is an effective solution to identify such unauthorized use. However, existing dataset copyright solutions primarily focus on the image domain; the complex nature of video data leaves dataset copyright auditing in the video domain unexplored. Specifically, video data introduces an additional temporal dimension, which poses significant challenges to the effectiveness and stealthiness of existing methods. In this paper, we propose VICTOR, the first dataset copyright auditing approach for video recognition systems. We develop a general and stealthy sample modification strategy that enhances the output discrepancy of the target model. By modifying only a small proportion of samples (e.g., 1%), VICTOR amplifies the impact of published modified samples on the prediction behavior of the target models. Then, the difference in the model's behavior for published modified and unpublished original samples can serve as a key basis for dataset auditing. Extensive experiments on multiple models and datasets highlight the superiority of VICTOR. Finally, we show that VICTOR is robust in the presence of several perturbation mechanisms to the training videos or the target models.

视频版权模型审计数据安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。