arXiv:2607.13046cs.LGcs.CR2026-07

揭示模型忽略的对称性,可用来保护隐私或追踪模型来源。

What Your Model Threw Away and Why You'll Want It Back: Masking, Fingerprinting, and Privacy from Discarded Geometry

论文配图:What Your Model Threw Away and Why You'll Want It Back: Masking, Fingerprinting, and Privacy from Discarded Geometry
图 1 · 摘自论文原文
  • 通过群作用分析模型忽略的对称性,定义了不可见的零纤维和稳定子。
  • 在分子性质预测和球面图像分类上验证,可高效计算并用于数据掩码与指纹识别。
  • 适用于传统神经网络和量子电路,为隐私保护提供新工具。

我们构建了一个框架,用于分析机器学习模型在具有李群作用的输入下所丢弃的信息。给定李群 $G$ 在空间 $V$ 上的表示 $π$ 及一个学习函数 $f o b{R}$,我们定义两个衡量 $f$ 无法察觉的对称性的对象:在点 $x \in V$ 处的零纤维 $N_G(f,x) = \{g \in G : f(π(g^{-1}) \cdot x) = f(x)\}$,即其逆作用在 $x$ 上无法被 $f$ 检测到的群元素集合。当 $N_G(f,x)$ 与 $x$ 无关时,它等于 $f$ 的稳定子 $\mathrm{Stab}_G(f)$,即使 $f$ 不变的最大子群。对于映射到 $\mathbb{R}$ 的光滑函数,根据预像定理,零纤维在一般输入处的维度至少为 $\dim G - 1$,与网络结构无关。对于自作用的紧致群,彼得-外尔定理给出了这两个对象的傅里叶系数矩阵表征。我们证明可通过牛顿迭代高效计算零纤维元素,代价相当于几次梯度评估。实验在 $\mathrm{SO}(3)$ 下的分子性质预测和 $\mathrm{PSL}(2, \mathbb{C})$ 下的球面图像分类中展示了其在数据掩码、模型指纹识别和隐私计算中的应用。该框架统一适用于经典神经网络和变分量子电路。

原文摘要 · Abstract (English)

We develop a framework for the information discarded by machine learning models whose inputs carry a Lie group action. Given a representation $π$ of a Lie group $G$ on a space $V$ and a learned function $f\colon V \to \mathbb{R}$, we define two objects measuring the symmetry invisible to $f$. The null fiber at a point $x \in V$ is the set $N_G(f,x) = \{g \in G : f(π(g^{-1}) \cdot x) = f(x)\}$ of group elements whose inverse action on $x$ is undetectable by $f$. When $N_G(f,x)$ is independent of $x$, it coincides with the stabilizer $\mathrm{Stab}_G(f)$, the largest subgroup of $G$ under which $f$ is invariant. For smooth maps to $\mathbb{R}$, the preimage theorem guarantees that null fibers have dimension at least $\dim G - 1$ at generic inputs, regardless of architecture. For compact groups acting on themselves, the Peter--Weyl theorem yields a spectral characterization of both objects in terms of the Fourier coefficient matrices of $f$. We show that null fiber elements can be computed efficiently via Newton iteration on the orbit map, at a cost comparable to a few gradient evaluations. Applications to data masking, model fingerprinting, and privacy-preserving computation are developed and tested experimentally on molecular property prediction under $\mathrm{SO}(3)$ and spherical image classification under the Möbius group $\mathrm{PSL}(2, \mathbb{C})$. The framework applies uniformly to classical neural networks and variational quantum circuits.

对称性隐私保护模型指纹群不变

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。