On the Ability of Developers' Training Data Preservation of Learnware
Hao-Yi Lei, Zhi-Hao Tan, Zhi-Hua Zhou
摘要
The learnware paradigm aims to enable users to leverage numerous existing well-trained models instead of building machine learning models from scratch. In this paradigm, developers worldwide can submit their well-trained models spontaneously into a learnware dock system , and the system helps developers generate specification for each model to form a learnware. As the key component, a specification should characterize the capabilities of the model, enabling it to be adequately identified and reused, while preserving the developer’s original data. Recently, the RKME (Reduced Kernel Mean Embedding) specification was proposed and most commonly utilized. This paper provides a theoretical analysis of RKME specification about its preservation ability for developer’s training data. By modeling it as a geometric problem on manifolds and utilizing tools from geometric analysis, we prove that the RKME specification is able to disclose none of the developer’s original data and possesses robust defense against common inference attacks, while preserving sufficient information for effective learnware identification.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Constructive Specification for Plug-and-Play Learnware AgentsJian-Dong Liu, Zi-Chen Zhao, Hao Sun, Lin-Xing Wu 等KDD 2026 · 被引用 3 次
- Learnware Specification via Label-Aware Neural EmbeddingWei Chen, Junxiang Mao, Min-Ling ZhangAAAI 2025 · 被引用 1 次
- A Study on PAVE Specification for LearnwareHao-Yu Shi, Zhi-Hao Tan, Zi-Chen Zhao, Yang Yu 等ICLR 2026
- Tabular Learnwares Can Be Repurposed for Seemingly Irrelevant New TasksPeng Tan, Feifan Yang, Zhi-Hao Tan, Zhi-Hua ZhouAAAI 2026
- Dynamic Learnware Filtering for Efficient Learnware Identification and System SlimmingJian-Dong Liu, Zhi-Hao Tan, Zhi-Hua ZhouKDD 2025
它引用的顶会 Paper7
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Knock Knock, Who's There? Membership Inference on Aggregate Location DataApostolos Pyrgelis, Carmela Troncoso, Emiliano De CristofaroNDSS 2018 · 被引用 293 次
- GAN-Leaks: A Taxonomy of Membership Inference Attacks against Generative ModelsDingfan Chen, Ning Yu, Yang Zhang, Mario FritzCCS 2020 · 被引用 278 次
- Towards Enabling Learnware to Handle Unseen JobsYu-Jie Zhang, Yu-Hu Yan, Peng Zhao, Zhi-Hua ZhouAAAI 2021 · 被引用 20 次
- Understanding Reconstruction Attacks with the Neural Tangent Kernel and Dataset DistillationNoel Loo, Ramin M. Hasani, Mathias Lechner, Alexander Amini 等ICLR 2024 · 被引用 14 次
相关 Paper
- Identifying Useful Learnwares for Heterogeneous Label SpacesLan-Zhe Guo, Zhi Zhou, Yufeng Li, Zhi-Hua ZhouICML 2023 · 被引用 17 次
- Identifying Learnwares via Reduced Neural Conditional Mean EmbeddingZi-Yu Mao, Ming LiICML 2026
- A Statistical Framework for Analyzing Specification Resistance to Learnware-Inversion RisksHao-Yi Lei, Zhi-Hao Tan, Zhi-Hua ZhouICML 2026
- Integrated Learnware Identification and Reuse via Reusability-Aware Metric LearningHai-Tian Liu, Peng Tan, Jian-Dong Liu, Zhi-Hao Tan 等KDD 2026
- Handling Learnwares from Heterogeneous Feature Spaces with Explicit Label ExploitationPeng Tan, Hai-Tian Liu, Zhi-Hao Tan, Zhi-Hua ZhouNeurIPS 2024 · 被引用 8 次
