Provenance of Training without Training Data: Towards Privacy-Preserving DNN Model Ownership Verification
Yunpeng Liu, Kexin Li, Zhuotao Liu, Bihan Wen, Ke Xu, Weiqiang Wang, Wenbiao Zhao, Qi Li
Abstract
In the era of deep learning, it is critical to protect the intellectual property of high-performance deep neural network (DNN) models. Existing proposals, however, are subject to adversarial ownership forgery (e.g., methods based on watermarks or fngerprints) or require full access to the original training dataset for ownership verifcation (e.g., methods requiring the replay of the learning process). In this paper, we propose a novel Provenance of Training (PoT) scheme, the frst empirical study towards verifying DNN model ownership without accessing any original dataset while being robust against existing attacks. At its core, PoT relies on a coherent model chain built from the intermediate checkpoints saved during model training to serve as the ownership certifcate. Through an in-depth analysis of model training, we propose six key properties that a legitimate model chain shall naturally hold. In contrast, it is difcult for the adversary to forge a model chain that satisfes these properties simultaneously without performing actual training. We systematically analyze PoT's robustness against various possible attacks, including the adaptive attacks that are designed given the full knowledge of PoT's design, and further perform extensive empirical experiments to demonstrate our security analysis. CCS Concepts • Computer systems organization → Neural networks; • Security and privacy → Digital rights management.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext aad9effa-3e83-41fb-ab76-63c64c930201Cited by top-tier papers2
- MER-Inspector: Assessing Model Extraction Risks from An Attack-Agnostic PerspectiveXinwei Zhang, Haibo Hu, Qingqing Ye, Li Bai et al.WWW 2025 · 5 citations
- Towards Understanding and Enhancing Security of Proof-of-Training for DNN Model Ownership VerificationYijia Chang, Hanrui Jiang, Chao Lin, Xinyi Huang et al.USENIX Security 2025
Builds on6
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter et al.USENIX Security 2016 · 2,088 citations
- Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by BackdooringYossi Adi, Carsten Baum, Moustapha Cissé, Benny Pinkas et al.USENIX Security 2018 · 832 citations
- Entangled Watermarks as a Defense against Model ExtractionHengrui Jia, Christopher A. Choquette-Choo, Varun Chandrasekaran, Nicolas PapernotUSENIX Security 2021 · 287 citations
- Model Watermarking for Image Processing NetworksJie Zhang, Dongdong Chen, Jing Liao, Han Fang et al.AAAI 2020 · 160 citations
- Hermes Attack: Steal DNN Models with Lossless Inference AccuracyYuankun Zhu, Yueqiang Cheng, Husheng Zhou, Yantao LuUSENIX Security 2021 · 119 citations
Related papers
- Watermarking Deep Neural Networks with Greedy ResidualsHanwen Liu, Zhenyu Weng, Yuesheng ZhuICML 2021 · 69 citations
- Identification for Deep Neural Network: Simply Adjusting Few Weights!Yingjie Lao, Peng Yang, Weijie Zhao, Ping LiICDE 2022 · 19 citations
- Authority Backdoor: A Certifiable Backdoor Mechanism for Authoring DNNsHan Yang, Shaofeng Li, Tian Dong, Xiangyu Xu et al.AAAI 2026
- Free Fine-tuning: A Plug-and-Play Watermarking Scheme for Deep Neural NetworksRun Wang, Jixing Ren, Boheng Li, Tianyi She et al.ACM MM 2023 · 20 citations
- United We Stand, Divided We Fall: Fingerprinting Deep Neural Networks via Adversarial TrajectoriesTianlong Xu, Chen Wang, Gaoyang Liu, Yang Yang et al.NeurIPS 2024 · 17 citations
