发表机构
State Key Laboratory of Novel Software Technology, Nanjing University; China Mobile Research Institute(南京大学计算机软件新技术国家重点实验室; 中国移动研究院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对LLM微调的数据IP侵权审计难题,提出事后框架DPA,通过内在分布指纹实现黑盒恶意场景下的可靠审计,性能优于基线且抗混淆,同时存在审计与隐私攻击的两用张力。
AI 中文摘要
定制化大语言模型(LLM)的普及带来了通过在专有数据上进行未授权微调侵犯数据知识产权(Data IP)的重大风险。现有审计技术存在局限,因为它们需要在数据准备或训练过程中进行干预,并且在数据释义、知识蒸馏等恶意混淆手段下仍很脆弱。我们提出Distribution Provenance Audit(DPA),这是一种用于在黑盒和恶意设置下审计LLM微调中数据IP侵权的事后框架。DPA基于一个关键见解:无论微调策略如何试图规避来源,维持效用的实际必要性都迫使模型保留语义实质和词汇形式的基本交集。因此,DPA将这种持久的词汇-语义交集捕获为内在分布指纹。该框架将审计表述为统计假设检验,通过无偏输出采样有效量化这些指纹,以可靠地拒绝非使用的原假设。在医学和法律微调任务上的大量实验表明,DPA始终优于现有基线,对采用释义和知识蒸馏的对抗性训练者保持鲁棒性。我们进一步强调了一个基本的两用张力:使审计可靠的相同高保真分布指纹也可能促进隐私攻击。
英文摘要
The proliferation of customized Large Language Models (LLMs) poses critical risks of Data Intellectual Property (Data IP) infringement via unauthorized fine-tuning on proprietary data. Existing audit techniques are limited, as they require intervention during data preparation or training and remain fragile under malicious obfuscations such as data paraphrasing and knowledge distillation. We propose \textit{Distribution Provenance Audit (DPA)}, a post-hoc framework for auditing data IP infringement in LLM fine-tuning under black-box and malicious settings. DPA is grounded in a critical insight: regardless of fine-tuning tactics to evade provenance, the practical necessity of maintaining utility constrains the model to preserve the fundamental intersection of semantic substance and lexical form. Accordingly, DPA captures this persistent lexical-semantic intersection as intrinsic distributional fingerprints. The framework formulates the audit as a statistical hypothesis test, effectively quantifying these fingerprints via unbiased output sampling to reliably reject the null hypothesis of non-usage. Extensive experiments on medical and legal fine-tuning tasks show that DPA consistently outperforms existing baselines, remaining robust against adversarial trainers employing paraphrasing and knowledge distillation. We further highlight a fundamental dual-use tension: the same high-fidelity distributional fingerprints enabling reliable auditing may also facilitate privacy attacks.
CommentsThis is the extended version of CCS'26 paper https://doi.org/10.1145/3830454.3832639