arXiv:2603.21411cs.CRcs.AI2026-03被引 2

提出理论方法确定指纹与决策边界的距离,兼顾鲁棒性与唯一性。

Fingerprinting Deep Neural Networks for Ownership Protection: An Analytical Approach

  • 通过可调拉伸因子控制指纹与决策边界的距离。
  • 在多种模型架构和攻击下验证效果优于现有方法。
  • 适合需要可靠模型版权保护的研究者与开发者。

基于对抗样本的指纹技术利用深度神经网络(DNN)的决策边界特性生成指纹,已在模型版权保护中证明有效。然而,核心挑战仍未解决:指纹应距决策边界多远,才能同时满足鲁棒性和唯一性,实现可靠保护?现有方法缺乏理论依据,依赖经验启发式策略,可能破坏任一性质。本文提出AnaFP,一种基于理论指导的指纹方案,将指纹生成建模为通过可调拉伸因子控制指纹到边界距离。为确保鲁棒性与唯一性,数学形式化二者约束,分别给出拉伸因子的下界与上界,共同定义可行区间。为实际生成,使用有限代理模型池近似盗版及独立训练模型集,并采用分位数松弛策略放松约束。因下界与拉伸因子存在循环依赖,采用网格搜索在可行区间内选取最优值。大量实验表明,AnaFP在不同模型架构和修改攻击下均显著优于已有方法,实现高效所有权验证。

原文摘要 · Abstract (English)

Adversarial-example-based fingerprinting approaches, which leverage the decision boundary characteristics of deep neural networks (DNNs) to craft fingerprints, have proven effective for model ownership protection. However, a fundamental challenge remains unresolved: how far a fingerprint should be placed from the decision boundary to simultaneously satisfy two essential properties, i.e., robustness and uniqueness, for effective and reliable ownership protection. Despite the importance of the fingerprint-to-boundary distance, existing works lack a theoretical solution and instead rely on empirical heuristics, which may violate either robustness or uniqueness properties. We propose AnaFP, an analytical fingerprinting scheme that constructs fingerprints under theoretical guidance. Specifically, we formulate fingerprint generation as controlling the fingerprint-to-boundary distance through a tunable stretch factor. To ensure both robustness and uniqueness, we mathematically formalize these properties that determine the lower and upper bounds of the stretch factor. These bounds jointly define an admissible interval within which the stretch factor must lie, thereby establishing a theoretical connection between the two constraints and the fingerprint-to-boundary distance. To enable practical fingerprint generation, we approximate the original (infinite) sets of pirated and independently trained models using two finite surrogate model pools and employ a quantile-based relaxation strategy to relax the derived bounds. Due to the circular dependency between the lower bound and the stretch factor, we apply grid search over the admissible interval to determine the most feasible stretch factor. Extensive experimental results show that AnaFP consistently outperforms prior methods, achieving effective ownership verification across diverse model architectures and model modification attacks.

模型版权指纹技术决策边界

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。