TMOVF: A Task-Agnostic Model Ownership Verification Framework

Zhe Sun,Zhongyu Huang,Wangqi Zhao,Yu Zhang,Jianzhong Zhang
DOI: https://doi.org/10.1109/smc53992.2023.10393939
2023-01-01
Abstract:The protection of model intellectual property is becoming an increasingly important issue. However, the existing methods for protecting model ownership, although effective, have limitations. Firstly, they primarily focus on classification models, and secondly, most of the proposed methods reduce the model's utility. To overcome these shortcomings, this paper proposes a task-agnostic model ownership verification framework based on feature fingerprint, called TMOVF, which separates ownership verification from model task. Our key idea is that model knowledge can be uniquely characterized by the extracted features, which may be high-dimensional, complicated, and difficult to compare for each input sample. Nevertheless, these features contain inherent information that cannot be ignored in cases of piracy. To measure the inheritance of our fingerprint, we introduce outlier detection into model ownership verification, which is a first in the field. By reconstructing the outlier detection algorithm, we extract the feature fingerprints of the victim model and the suspicious model, and compute the outliers of their feature fingerprints. By comparing the results, we can verify the ownership of the models. We conduct extensive experiments to evaluate our framework and demonstrate the inheritability of feature fingerprints in stolen models. Our experiments show that the framework is effective in verifying ownership, regardless of the model task. Additionally, our results demonstrate that our framework is more effective than existing methods.
What problem does this paper attempt to address?