arXiv:2512.16439cs.CRcs.CL2025-12被引 4

为嵌入服务设计语义感知水印,兼顾隐蔽性与版权可验证性。

From Essence to Defense: Adaptive Semantic-aware Watermarking for Embedding-as-a-Service Copyright Protection

  • 按语义空间分区注入水印,保持不可感知且多样。
  • 自适应权重机制保护原始嵌入分布,抗攻击能力更强。
  • 适用于NLP模型版权保护,适合平台级内容防护场景。

得益于大语言模型在自然语言理解与生成方面的卓越能力,嵌入即服务(EaaS)已成为网络平台上的成功商业范式。然而,已有研究表明EaaS易受模仿攻击。现有方法通过水印技术保护EaaS知识产权,但均忽略嵌入最重要的语义特性,导致隐蔽性与无害性有限。为此,我们提出SemMark,一种面向EaaS版权保护的新型语义感知水印范式。SemMark采用局部敏感哈希对语义空间进行划分,并将语义感知水印注入特定区域,确保水印信号不可感知且多样化。此外,基于局部离群因子引入自适应水印权重机制,以维持原始嵌入分布。我们还提出了检测采样和降维攻击,并构建了四种评估场景。在四个主流NLP数据集上开展大量实验,结果表明SemMark在可验证性、多样性、隐蔽性和无害性方面均表现优异。

原文摘要 · Abstract (English)

Benefiting from the superior capabilities of large language models in natural language understanding and generation, Embeddings-as-a-Service (EaaS) has emerged as a successful commercial paradigm on the web platform. However, prior studies have revealed that EaaS is vulnerable to imitation attacks. Existing methods protect the intellectual property of EaaS through watermarking techniques, but they all ignore the most important properties of embedding: semantics, resulting in limited harmlessness and stealthiness. To this end, we propose SemMark, a novel semantic-based watermarking paradigm for EaaS copyright protection. SemMark employs locality-sensitive hashing to partition the semantic space and inject semantic-aware watermarks into specific regions, ensuring that the watermark signals remain imperceptible and diverse. In addition, we introduce the adaptive watermark weight mechanism based on the local outlier factor to preserve the original embedding distribution. Furthermore, we propose Detect-Sampling and Dimensionality-Reduction attacks and construct four scenarios to evaluate the watermarking method. Extensive experiments are conducted on four popular NLP datasets, and SemMark achieves superior verifiability, diversity, stealthiness, and harmlessness.

水印NLP版权保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。