Your Transferability Barrier is Fragile: Free-Lunch for Transferring the Non-Transferable Learning
Ziming Hong, Li Shen, Tongliang Liu
摘要
Recently, non-transferable learning (NTL) was proposed to restrict models' generalization toward the target domain(s), which serves as state-of-the-art solutions for intellectual property (IP) protection. However, the robustness of the established "transferability barrier" for degrading the target domain performance has not been well studied. In this paper, we first show that the generalization performance of NTL models is widely impaired on third-party domains (i.e., the unseen domain in the NTL training stage). We explore the impairment patterns and find that: due to the dominant generalization of non-transferable task, NTL models tend to make target-domain-consistent predictions on third-party domains, even though only a slight distribution shift from the third-party domain to the source domain. Motivated by these findings, we uncover the potential risks of NTL by proposing a simple but effective method (dubbed as TransNTL) to recover the target domain performance with few source domain data. Specifically, by performing a group of different perturbations on the few source domain data, we obtain diverse third-party domains that evoke the same impairment patterns as the unavailable target domain. Then, we fine-tune the NTL model under an impairmentrepair self-distillation framework, where the source-domain predictions are used to teach the model itself how to predict on third-party domains, thus repairing the impaired generalization. Empirically, experiments on standard NTL benchmarks show that the proposed TransNTL reaches up to ∼72% target-domain improvements by using only 10% source domain data. Finally, we also explore a feasible defense method and empirically demonstrate its effectiveness. 1 In NTL scenarios, the defined third-party domain shares the same contents (i.e., class labels) with the source and the target domain. 2 We perturbed the image by adding Gaussian noise with different std. 3 We augment the image by using RandAugment [8].
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- AdLift: Lifting Adversarial Perturbations to Safeguard 3D Gaussian Splatting Assets Against Instruction-Driven EditingZiming Hong, Tianyu Huang, Runnan Chen, Shanshan Ye 等ICML 2026 · 被引用 10 次
- Jailbreaking the Non-Transferable Barrier via Test-Time Data DisguisingYongli Xiang, Ziming Hong, Lina Yao, Dadong Wang 等CVPR 2025
- When Data-Free Knowledge Distillation Meets Non-Transferable Teacher: Escaping Out-of-Distribution Trap is All You NeedZiming Hong, Runnan Chen, Zengmao Wang, Bo Han 等ICML 2025
它引用的顶会 Paper27
- RandAugment: Practical Automated Data Augmentation with a Reduced Search SpaceEkin Dogus Cubuk, Barret Zoph, Jonathon Shlens, Quoc LeNeurIPS 2020 · 被引用 4,453 次
- Sharpness-aware Minimization for Efficiently Improving GeneralizationPierre Foret, Ariel Kleiner, Hossein Mobahi, Behnam NeyshaburICLR 2021 · 被引用 1,861 次
- Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by BackdooringYossi Adi, Carsten Baum, Moustapha Cissé, Benny Pinkas 等USENIX Security 2018 · 被引用 832 次
- Scaling Out-of-Distribution Detection for Real-World SettingsDan Hendrycks, Steven Basart, Mantas Mazeika, Andy Zou 等ICML 2022 · 被引用 653 次
- SWAD: Domain Generalization by Seeking Flat MinimaJunbum Cha, Sanghyuk Chun, Kyungjae Lee, Han-Cheol Cho 等NeurIPS 2021 · 被引用 630 次
相关 Paper
- Non-Transferable Learning: A New Approach for Model Ownership Verification and Applicability AuthorizationLixu Wang, Shichao Xu, Ruiqi Xu, Xiao Wang 等ICLR 2022 · 被引用 65 次
- Unsupervised Non-transferable Text ClassificationGuangtao Zeng, Wei LuEMNLP 2022 · 被引用 4 次
- Improving Non-Transferable Representation Learning by Harnessing Content and StyleZiming Hong, Zhenyi Wang, Li Shen, Yu Yao 等ICLR 2024 · 被引用 37 次
- Adaptive Bayesian Early-Exit Networks for Efficient Non-Transferable LearningSiyu Luan, Yan Li, Zhong Chen, Zhenyi WangCVPR 2026
- Model Barrier: A Compact Un-Transferable Isolation Domain for Model Intellectual Property ProtectionLianyu Wang, Meng Wang, Daoqiang Zhang, Huazhu FuCVPR 2023
