TabularMark: Watermarking Tabular Datasets for Machine Learning
Yihao Zheng, Haocheng Xia, Junyuan Pang, Jinfei Liu, Kui Ren, Lingyang Chu, Yang Cao, Li Xiong
Abstract
Watermarking is broadly utilized to protect ownership of shared data while preserving data utility. However, existing watermarking methods for tabular datasets fall short on the desired properties (detectability, non-intrusiveness, and robustness) and only preserve data utility from the perspective of data statistics, ignoring the performance of downstream ML models trained on the datasets. Can we watermark tabular datasets without significantly compromising their utility for training ML models while preventing attackers from training usable ML models on attacked datasets? In this paper, we propose a hypothesis testing-based watermarking scheme, TabularMark. Data noise partitioning is utilized for data perturbation during embedding, which is adaptable for numerical and categorical attributes while preserving the data utility. For detection, a custom-threshold one proportion z-test is employed , which can reliably determine the presence of the watermark. Experiments on real-world and synthetic datasets demonstrate the superiority of TabularMark in detectability, non-intrusiveness, and robustness.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ce09348e-0584-47ed-9b99-498d34e711a6Cited by top-tier papers4
- MUSE: Model-Agnostic Tabular Watermarking via Multi-Sample SelectionLiancheng Fang, Aiwei Liu, Henry Peng Zou, Yankai Chen et al.ICLR 2026 · 5 citations
- ArtistAuditor: Auditing Artist Style Pirate in Text-to-Image Generation ModelsLinkang Du, Zheng Zhu, Min Chen, Zhou Su et al.WWW 2025 · 5 citations
- TabWak: A Watermark for Tabular Diffusion ModelsChaoyi Zhu, Jiayi Tang, Jeroen M. Galjaard, Pin-Yu Chen et al.ICLR 2025
- Vector Database WatermarkingZhiwen Ren, Wei Fan, Qiyi Yao, Jing Qiu et al.NeurIPS 2025
Related papers
- B2Mark: A Blind and Buyer-Traceable Watermarking Scheme for Tabular DatasetsYihao Zheng, Jinfei Liu, Kui Ren, Li XiongSIGMOD 2026 · 1 citation
- Provable Watermarking for Data Poisoning AttacksYifan Zhu, Lijia Yu, Xiao-Shan GaoNeurIPS 2025 · 3 citations
- PuzzleMark: Implicit Jigsaw Learning for Robust Code Dataset Watermarking in Neural Code Completion ModelsHaocheng Huang, Yuchen Chen, Weisong Sun, Peizhuo Lv et al.FSE 2026
- ZeroMark: Towards Dataset Ownership Verification without Disclosing WatermarkJunfeng Guo, Yiming Li, Ruibo Chen, Yihan Wu et al.NeurIPS 2024 · 24 citations
- FreqyWM: Frequency Watermarking for the New Data EconomyDevris Isler, Elisa Cabana, Álvaro García-Recuero, Georgia Koutrika et al.ICDE 2024 · 2 citations
