Queries, Representation & Detection: The Next 100 Model Fingerprinting Schemes
Augustin Godinot, Erwan Le Merrer, Camilla Penzo, François Taı̈ani, Gilles Trédan
Centre National de la Recherche Scientifique Institut national de recherche en sciences et technologies du numérique Institut de Recherche en Informatique et Systèmes Aléatoires Centre Inria de l'Université de Rennes
阅读操作
确认中在文库中上传 PDF 后可生成中文音频讲解。
摘要与影响
The deployment of machine learning models in operational contexts represents a significant investment for any organisation. Consequently, the risk of these models being misappropriated by competitors needs to be addressed. In recent years, numerous proposals have been put forth to detect instances of model stealing. However, these proposals operate under implicit and disparate data and model access assumptions; as a consequence, it remains unclear how they can be effectively compared to one another. Our evaluation shows that a simple baseline that we introduce performs on par with existing state-of-the-art fingerprints, which, on the other hand, are much more complex. To uncover the reasons behind this intriguing result, this paper introduces a systematic approach to both the creation of model fingerprinting schemes and their evaluation benchmarks. By dividing model fingerprinting into three core components – Query, Representation and Detection (QuRD) – we are able to identify ~100 previously unexplored QuRD combinations and gain insights into their performance. Finally, we introduce a set of metrics to compare and guide the creation of more representative model stealing detection benchmarks. Our approach reveals the need for more challenging benchmarks and a sound comparison with baselines. To foster the creation of new fingerprinting schemes and benchmarks, we open-source our fingerprinting toolbox.
逐年被引趋势
关键指标
同类平均 = 1
同领域 · 同年份 · 同类型
Google Scholar 与 OpenAlex 的被引统计范围不同,数值存在差异属正常。
AI 辅助阅读
依据:摘要
可就本文提问;依据不足时会说明。
学术脉络
学科主题
计算机 / AIAdversarial Robustness in Machine Learning
Physical Unclonable Functions (PUFs) and Hardware Security · Privacy-Preserving Technologies in Data
参考文献 0
引用本文 1
按被引量排序,此处列出前 3 条