arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.25738cs.CRcs.AIcs.LG

MeMark:面向脉冲神经网络的膜空间水印技术

MeMark: Membrane-Space Watermarking for Spiking Neural Networks

Roberto Riaño, Gorka Abad, Stjepan Picek, Aitor Urbieta

首次发表
浏览论文内容

中文总结 AI 辅助

MeMark是一种面向脉冲神经网络的膜空间水印技术,将水印嵌入神经元膜状态,可抵御多种攻击,能为检查点所有权提供可靠证据。

中文摘要 AI 辅助

脉冲神经网络(SNN)作为预训练检查点被越来越广泛地分发,并被重用为新任务的骨干网络。然而,当前的SNN水印主要针对模型输出进行验证,因此,替换输出头的用户可以保留大部分原始网络,同时移除用于验证的证据。我们提出MeMark,一种专为检查点重用场景设计的水印技术。MeMark没有将水印存储在输出头中,而是在选定的 leaky integrate-and-fire(LIF,泄漏积分放电)神经元的内部膜状态中嵌入多位标识符。秘密输入驱动每个选定神经元达到其自身放电阈值的选定一侧,后续使用相同阈值来恢复秘密位,因此验证者不需要学习到的解码器。我们在循环SNN、卷积SNN、残差SNN和Transformer SNN上对MeMark进行评估。在一个2.154亿参数的SpikeGPT检查点上,所有20个独立的64位密钥都通过了固定的51/64验证规则,而当针对所有20个受保护检查点和干净模型进行测试时,30000个全新随机密钥均未通过。在微调、90%剪枝、int8量化和输出头替换后,所有20个真实密钥也保持在阈值以上。在我们设定的威胁模型下,自适应攻击可以削弱水印,但在我们测试的场景中无法移除所有权证据。此外,我们还研究了虚假所有权声明、密钥感知和密钥无关的移除、部分密钥披露、回滚以及提取到学生模型等问题。结果表明,MeMark可以为检查点衍生产品提供证据,同时能够抵御对手的攻击和完整的头替换。

英文摘要

Spiking Neural Networks (SNNs) are increasingly distributed as pretrained checkpoints and reused as backbones for new tasks. However, current SNN watermarks are mainly verified against the model output. Thus, a user who replaces the output head can keep most of the original network while removing the evidence used for verification. We present MeMark, a watermark designed for the checkpoint-reuse setting. Instead of storing the watermark in the output head, MeMark embeds a multi-bit identifier in the internal membrane state of selected Leaky Integrate-and-Fire (LIF) neurons. A secret input drives each selected neuron to the chosen side of its own firing threshold, and the same threshold is later used to recover the secret bit, so the verifier does not need a learned decoder. We evaluate MeMark across recurrent, convolutional, residual, and transformer SNNs. On a 215.4M-parameter SpikeGPT checkpoint, all 20 independent 64-bit keys pass the fixed 51/64 verification rule, while none of the $30\,000$ fresh random keys pass when tested against all 20 protected checkpoints and the clean model. All 20 genuine keys also remain above the threshold after fine-tuning, 90\% pruning, int8 quantization, and output-head replacement. Under our stated threat model, adaptive attacks can weaken the watermark but do not remove the ownership evidence in the settings we test. Additionally, we study false ownership claims, key-aware and key-agnostic removal, partial key disclosure, rollback, and extraction into a student. The results show that MeMark can provide evidence of checkpoint derivatives, while being resistant to the adversary's attacks and complete head replacement.

发表机构

  • Radboud University(拉德堡德大学)
  • IKERLAN Technology Research Centre(伊克尔兰技术研究中心)
  • University of Bergen(卑尔根大学)
  • University of Zagreb(萨格勒布大学)

机构由 AI 辅助整理,请以论文原文为准。

↑