Towards Stricter Black-box Integrity Verification of Deep Neural Network Models
Chaoxiang He, Xiaofan Bai, Xiaojing Ma, Bin B. Zhu, Pingyi Hu, Jiayun Fu, Hai Jin, Dongmei Zhang
Abstract
Cloud-based machine learning services offer significant advantages but also introduce the risk of tampering with cloud-deployed deep neural network (DNN) models. Black-box integrity verification (BIV) allows model owners and end-users to determine if a cloud-deployed DNN model has been tampered with by examining only the top-1 label responses. Fingerprinting generates fingerprint samples to query the model, achieving BIV with no impact on the model's accuracy. In this paper, we present BIVBench, the first comprehensive benchmark for BIV of DNN models. BIVBench covers 16 types of model modifications, providing extensive coverage of practical modification scenarios. Our analysis reveals that existing fingerprinting methods, which are typically focused on significant tampering, lack the sensitivity needed to effectively detect subtle yet common and potentially severe modifications. To address this limitation, we propose MiSentry (Model Integrity Sentry), a novel fingerprinting method that leverages meta-learning. MiSentry strategically incorporates a few subtly modified models into the meta-learning model zoo and maximizes the divergence of output predictions between the target model and the modified models in the model zoo to generate highly sensitive, generalizable, and effective fingerprint samples. Extensive evaluations using BIVBench demonstrate that MiSentry outperforms existing state-of-the-art methods overall and significantly surpasses them in detecting subtle modifications. The BIVBench and supplementary materials are available at: https://github.com/CGCL-codes/BIVBench.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers3
- CREDIT: Certified Ownership Verification of Deep Neural Networks Against Model Extraction AttacksBolin Shen, Zhan Cheng, Neil Gong, Fan Yao et al.ICML 2026 · 3 citations
- SDBF: Steep-Decision-Boundary Fingerprinting for Hard-Label Tampering Detection of DNN ModelsXiaofan Bai, Shixin Li, Xiaojing Ma, Bin Benjamin Zhu et al.CVPR 2025
- RESF: Regularized-Entropy-Sensitive Fingerprinting for Black-Box Tamper Detection of Large Language ModelsPingyi Hu, Xiaofan Bai, Xiaojing Ma, Chaoxiang He et al.EMNLP 2025
Related papers
- Intersecting-Boundary-Sensitive Fingerprinting for Tampering Detection of DNN ModelsXiaofan Bai, Chaoxiang He, Xiaojing Ma, Bin Benjamin Zhu et al.ICML 2024 · 6 citations
- MetaV: A Meta-Verifier Approach to Task-Agnostic Model FingerprintingXudong Pan, Yifan Yan, Mi Zhang, Min YangKDD 2022 · 19 citations
- PublicCheck: Public Integrity Verification for Services of Run-time Deep ModelsShuo Wang, Sharif Abuadbba, Sidharth Agarwal, Kristen Moore et al.S&P 2023
- Breaking the Boundary Barrier: Robust Model Fingerprinting via Unlearnable Examples in Model-Parameter SpaceTianlong Xu, Zixiong Wang, Gaoyang Liu, Jian Chen et al.KDD 2026
- Securing Graph Neural Networks in MLaaS: A Comprehensive Realization of Query-based Integrity VerificationBang Wu, Xingliang Yuan, Shuo Wang, Qi Li et al.S&P 2024 · 13 citations
