arXiv:2606.21240cs.CRcs.CV2026-06中稿 · ACM CCS 2026

提出多尺度检测框架DIPBox,识别数据集再生威胁。

DIPBox: A Multi-scale Testing Framework for Tracking Dataset Regeneration

论文配图:DIPBox: A Multi-scale Testing Framework for Tracking Dataset Regeneration
图 1 · 摘自论文原文
  • 从样本、集合、分布三尺度设计相似性度量
  • 在320个再生数据集上检测准确率超95%
  • 适合数据安全与合规团队使用

训练数据具有巨大商业价值且易被非法复制。现有防御多聚焦单个数据点追踪,忽视数据集再生威胁。对公开肿瘤数据集的测量发现存在显著部分数据集复制现象,引发许可合规担忧。我们发现:保留模型效用的数据再生必然在多特征尺度上留下可测信号。据此将数据特征分为样本、集合、分布三级,并设计四种相似性度量以精准识别再生行为。基于此,我们构建DIPBox——首个通过多尺度相似性测试追踪再生嫌疑的框架,覆盖从有限到完全信息的多种防御者场景。进一步提供学习理论分析,证明多尺度度量合理性,并形式化效用-偏差间的固有权衡,揭示逃避再生的根本局限。在16个视觉与文本基础数据集、320个再生数据集及590个衍生模型上进行大量实验,验证DIPBox优于现有方案,同时刻画其在三种自适应攻击下的鲁棒性与边界。

原文摘要 · Abstract (English)

Training datasets have tremendous proprietary value and are vulnerable to unauthorized copying. Existing defenses mainly focus on tracking individual data points, but pay little attention to the threat of dataset regeneration. Through a measurement study of public tumor datasets, we identify substantial real-world partial-dataset replication, raising concerns about potential license noncompliance. To counter the challenge of tracking previously unknown adversarial regeneration, our key insight is that regeneration that preserves model utility inevitably preserves measurable signals across multiple feature scales. We categorize these dataset features into sample-, set-, and distribution-level features and design four similarity metrics to accurately identify regeneration. Based on these metrics, we develop DIPBox, which to our knowledge is the first testing framework that tracks regeneration suspects via multi-scale similarity testing across a spectrum of defender access settings, from limited to full information. We further provide a learning-theoretic analysis that justifies these multi-scale metrics and formalizes an inherent utility--divergence trade-off, implying fundamental limits on evasive regeneration. Extensive experiments on 16 vision and text base datasets, 320 regenerated datasets, and 590 derived models validate that DIPBox outperforms previous solutions while characterizing its robustness and limits under three adaptive attacks.

数据安全数据再生多尺度检测隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。