Queries, Representation & Detection: The Next 100 Model Fingerprinting Schemes
Augustin Godinot, Erwan Le Merrer, Camilla Penzo, François Taïani, Gilles Trédan
摘要
The deployment of machine learning models in operational contexts represents a significant investment for any organisation. Consequently, the risk of these models being misappropriated by competitors needs to be addressed. In recent years, numerous proposals have been put forth to detect instances of model stealing. However, these proposals operate under implicit and disparate data and model access assumptions; as a consequence, it remains unclear how they can be effectively compared to one another. Our evaluation shows that a simple baseline that we introduce performs on par with existing state-of-the-art fingerprints, which, on the other hand, are much more complex. To uncover the reasons behind this intriguing result, this paper introduces a systematic approach to both the creation of model fingerprinting schemes and their evaluation benchmarks. By dividing model fingerprinting into three core components -Query, Representation and Detection (QuRD) -we are able to identify ∼ 100 previously unexplored QuRD combinations and gain insights into their performance. Finally, we introduce a set of metrics to compare and guide the creation of more representative model stealing detection benchmarks. Our approach reveals the need for more challenging benchmarks and a sound comparison with baselines. To foster the creation of new fingerprinting schemes and benchmarks, we open-source our fingerprinting toolbox. Companies devote considerable resources (i.e. manpower, funds and energy) to developing efficient and accurate machine learning (ML) models. Many of these models are then deployed in production on online platforms to solve a wide array of business-critical tasks (e.g. recommendations or predictions of all kinds). However, it is well understood that extraction attacks, or simply infrastructure leaks, can allow competitors to access the model architecture (Oh et al. 2018 ), weights (Carlini et al. 2024), and hyperparameters (Wang and Gong 2018). From financial risks, when the attacker can provide the same functionality at a fraction of the cost, to integrity risks, when the attacker could use the stolen model as a step to craft adversarial examples, Model stealing attacks pose great risks for the model developer. Although efforts have been devoted to defend models against extraction attacks (
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Fingerprinting Deep Neural Networks for Ownership Protection: An Analytical ApproachGuang Yang, Ziye Geng, Yihang Chen, Changqing LuoICLR 2026 · 被引用 3 次
- LiteGuard: Efficient Task-Agnostic Model Fingerprinting with Enhanced GeneralizationGuang Yang, Ziye Geng, Yihang Chen, Changqing LuoICLR 2026 · 被引用 2 次
- Fingerprinting Pre-trained Encoders under Arbitrary Downstream Fine-Tuning via Adversarial ShiftingTianlong Xu, Wang Zixiong, Lishuai Hou, Gaoyang Liu 等ICML 2026
它引用的顶会 Paper15
- Stealing Hyperparameters in Machine LearningBinghui Wang, Neil Zhenqiang GongS&P 2018 · 被引用 504 次
- Prediction Poisoning: Towards Defenses Against DNN Model Stealing AttacksTribhuvanesh Orekondy, Bernt Schiele, Mario FritzICLR 2020 · 被引用 194 次
- Deep Neural Network Fingerprinting by Conferrable Adversarial ExamplesNils Lukas, Yuxuan Zhang, Florian KerschbaumICLR 2021 · 被引用 182 次
- Stealing part of a production language modelNicholas Carlini, Daniel Paleka, Krishnamurthy Dj Dvijotham, Thomas Steinke 等ICML 2024 · 被引用 157 次
- Copy, Right? A Testing Framework for Copyright Protection of Deep Learning ModelsJialuo Chen, Jingyi Wang, Tinglan Peng, Youcheng Sun 等S&P 2022 · 被引用 94 次
相关 Paper
- High Accuracy and High Fidelity Extraction of Neural NetworksMatthew Jagielski, Nicholas Carlini, David Berthelot, Alex Kurakin 等USENIX Security 2020
- Towards Stricter Black-box Integrity Verification of Deep Neural Network ModelsChaoxiang He, Xiaofan Bai, Xiaojing Ma, Bin B. Zhu 等ACM MM 2024 · 被引用 3 次
- Are You Stealing My Model? Sample Correlation for Fingerprinting Deep Neural NetworksJiyang Guan, Jian Liang, Ran HeNeurIPS 2022 · 被引用 57 次
- Stealix: Model Stealing via Prompt EvolutionZhixiong Zhuang, Hui-Po Wang, Maria-Irina Nicolae, Mario FritzICML 2025
- ML-Doctor: Holistic Risk Assessment of Inference Attacks Against Machine Learning ModelsYugeng Liu, Rui Wen, Xinlei He, Ahmed Salem 等USENIX Security 2022
