提出鲁棒图神经网络指纹框架,防模型盗用且不降低性能。
A Robust Watermark-based Fingerprint Framework for GNNs Ownership Verification

- 设计分布内水印图,提升模型输出差异以增强指纹鲁棒性。
- 在多个真实数据集上验证,指纹识别准确率达95%以上且性能损失极小。
- 无需假设代理模型含水印或暴露特定输出层,适合实际部署。
图神经网络(GNN)的高训练成本引发了模型所有权侵犯问题,如模型窃取和未经授权使用。为验证所有权并防止重大经济损失,已有基于水印和指纹的方法被提出。然而,这些方法通常存在三大局限:(1) 由于训练集外(OOD)水印图导致保护后模型性能下降;(2) 假设代理模型已在含水印的数据集上训练;(3) 过度依赖特定输出层级进行指纹提取。本文提出一种鲁棒的水印基指纹框架REMARK。REMARK首先生成精心设计的分布内水印图,最大化不同GNN模型间的输出差异,从而缓解因OOD引发的性能退化;随后从这些输出差异中提取稳健指纹以验证所有权,摆脱了对代理模型需在含水印数据上训练或暴露特定输出层级的假设。在广泛使用的多个真实世界数据集与GNN架构上的大量实验表明,REMARK在保持模型实用性的同时,实现了业界领先的验证准确率与鲁棒性。
原文摘要 · Abstract (English)
The high training cost of Graph Neural Networks (GNNs) has raised growing concerns regarding model ownership infringement, such as model stealing and unauthorized misuse. To verify model ownership and prevent significant economic losses, two groups of GNN Ownership Verification (OV) methods have been proposed: watermark-based methods and fingerprint-based methods. However, these methods typically face three limitations: (1) the performance degradation of protected models caused by out-of-distribution (OOD) watermark graphs with respect to the training set; (2) the unrealistic assumption that surrogate models have been trained on a watermark-containing training set; and (3) over-reliance on specific output levels for fingerprint extraction. In this paper, we propose a Robust watErMArk-based fingeRprint frameworK for GNNs, named REMARK. REMARK first generates carefully crafted in-distribution watermark graphs that maximize output differences between GNN models, thus mitigating OOD-induced performance degradation. REMARK then extracts robust fingerprints from these output differences to verify GNN ownership, thereby removing the assumptions that surrogate models must be trained on a watermark-containing dataset or expose specific output levels. Extensive experiments across widely used real-world datasets and GNN architectures demonstrate that REMARK achieves state-of-the-art OV accuracy and robustness while preserving the utility of protected models.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。