为多用户模型衍生链设计可追踪贡献的水印框架
LineageMark: Multi-user White-box Watermarking for Contribution Tracing in Model Derivation Chains
- 用投影统计方法在模型参数中嵌入水印
- 支持多阶段衍生中水印持续保留且抗微调等扰动
- 适合开源模型生态中的版权保护与溯源
在开放的大语言模型生态系统中,模型常在多个领域和应用中被多次改编,形成多阶段衍生链。因此,追踪和验证历史贡献对模型溯源和知识产权保护至关重要。然而,现有水印方法主要针对单用户一次性嵌入,在重复衍生和增量更新下往往失效。为此,我们提出 LineageMark,一种面向模型衍生链的多用户白盒水印框架。该框架通过投影方法在模型参数中编码水印:首先选取稳定载体以降低对模型变化的敏感性,每个水印比特表示为这些载体上的投影统计量;后续水印插入仅引入投影空间内的有界扰动,并利用边界约束保持信号完整性。实验表明,LineageMark 在多阶段模型衍生链中能有效保留贡献者水印,支持增量式多用户水印插入,且对重水印、微调、量化、剪枝等扰动具有鲁棒性。
原文摘要 · Abstract (English)
In open large language model (LLM) ecosystems, models are frequently adapted across multiple domains and applications, forming multi-stage derivation chains. Consequently, tracking and verifying historical contributions is essential for model provenance and intellectual property protection. However, existing watermarking methods are mainly designed for single-user, one-time embeddings, often fail under repeated model derivation and incremental updates. To address this problem, we propose LineageMark, a multi-user white-box watermarking framework for model derivation chains. The framework encodes watermarks in model parameters using a projection-based approach. Stable carriers are first selected to reduce sensitivity to model changes, each watermark bit is then represented as a projection statistic over these carriers. Additional watermark insertions introduce only bounded perturbations in the projection space, and margin constraints are used to maintain signal integrity. We evaluate the effectiveness of LineageMark in multi-stage model derivation chains. Experimental results show that LineageMark preserves contributor watermarks across multi-stage derivation and supports incremental multi-user watermark insertion. Furthermore, it exhibits robustness against perturbations such as re-watermarking, fine-tuning, quantization, and pruning.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。