MetaV: A Meta-Verifier Approach to Task-Agnostic Model Fingerprinting
Xudong Pan, Yifan Yan, Mi Zhang, Min Yang
摘要
Protecting the intellectual property (IP) of deep neural networks (DNN) becomes an urgent concern for IT corporations. For model piracy forensics, previous model fingerprinting schemes are commonly based on adversarial examples constructed for the owner's model as the fingerprint, and verify whether a suspect model is indeed pirated from the original model by matching the behavioral pattern on the fingerprint examples between one another. However, these methods heavily rely on the characteristics of classification tasks which inhibits their application to more general scenarios. To address this issue, we present MetaV, the first task-agnostic model fingerprinting framework which enables fingerprinting on a much wider range of DNNs independent from the downstream learning task, and exhibits strong robustness against a variety of ownership obfuscation techniques. Specifically, we generalize previous schemes into two critical design components in MetaV: the adaptive fingerprint and the meta-verifier, which are jointly optimized such that the meta-verifier learns to determine whether a suspect model is stolen based on the concatenated outputs of the suspect model on the adaptive fingerprint. As a key of being task-agnostic, the full process makes no assumption on the model internals in the ensemble only if they have the same input and output dimensions. Spanning classification, regression and generative modeling, extensive experimental results validate the substantially improved performance of MetaV over the state-of-the-art fingerprinting schemes and demonstrate the enhanced generality of MetaV for providing task-agnostic fingerprinting. For example, on fingerprinting ResNet-18 trained for skin cancer diagnosis, MetaV achieves simultaneously 100% true positives and 100% true negatives on a diverse test set of 70 suspect models, achieving an about 220% relative improvement in ARUC in comparison to the optimal baseline. CCS CONCEPTS • Security and privacy → Domain-specific security and privacy architectures; • Computing methodologies → Neural networks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- False Claims against Model Ownership ResolutionJian Liu, Rui Zhang, Sebastian Szyller, Kui Ren 等USENIX Security 2024 · 被引用 22 次
- United We Stand, Divided We Fall: Fingerprinting Deep Neural Networks via Adversarial TrajectoriesTianlong Xu, Chen Wang, Gaoyang Liu, Yang Yang 等NeurIPS 2024 · 被引用 17 次
- Queries, Representation & Detection: The Next 100 Model Fingerprinting SchemesAugustin Godinot, Erwan Le Merrer, Camilla Penzo, François Taïani 等AAAI 2025 · 被引用 6 次
- Intersecting-Boundary-Sensitive Fingerprinting for Tampering Detection of DNN ModelsXiaofan Bai, Chaoxiang He, Xiaojing Ma, Bin Benjamin Zhu 等ICML 2024 · 被引用 6 次
- AWM: Accurate Weight-Matrix Fingerprint for Large Language ModelsBoyi Zeng, Lin Chen, Ziwei He, Xinbing Wang 等ICLR 2026 · 被引用 3 次
它引用的顶会 Paper9
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Informer: Beyond Efficient Transformer for Long Sequence Time-Series ForecastingHaoyi Zhou, Shanghang Zhang, Jieqi Peng, Shuai Zhang 等AAAI 2021 · 被引用 7,289 次
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter 等USENIX Security 2016 · 被引用 2,088 次
- Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by BackdooringYossi Adi, Carsten Baum, Moustapha Cissé, Benny Pinkas 等USENIX Security 2018 · 被引用 832 次
- Adversarial Sensor Attack on LiDAR-based Perception in Autonomous DrivingYulong Cao, Chaowei Xiao, Benjamin Cyr, Yimeng Zhou 等CCS 2019 · 被引用 626 次
相关 Paper
- Fingerprinting Deep Image Restoration ModelsYuhui Quan, Huan Teng, Ruotao Xu, Jun Huang 等ICCV 2023 · 被引用 8 次
- LiteGuard: Efficient Task-Agnostic Model Fingerprinting with Enhanced GeneralizationGuang Yang, Ziye Geng, Yihang Chen, Changqing LuoICLR 2026 · 被引用 2 次
- IPRemover: A Generative Model Inversion Attack against Deep Neural Network Fingerprinting and WatermarkingWei Zong, Yang-Wai Chow, Willy Susilo, Joonsang Baek 等AAAI 2024 · 被引用 12 次
- Fingerprinting Deep Neural Networks Globally via Universal Adversarial PerturbationsZirui Peng, Shaofeng Li, Guoxing Chen, Cheng Zhang 等CVPR 2022 · 被引用 66 次
- GNNFingers: A Fingerprinting Framework for Verifying Ownerships of Graph Neural NetworksXiaoyu You, Youhe Jiang, Jianwei Xu, Mi Zhang 等WWW 2024 · 被引用 9 次
