arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

成员即所有权:一种针对扩散模型的鲁棒所有权验证框架

Membership is Ownership: A Robust Ownership Verification Framework for Diffusion Models

Feng Jiang, Zuobin Xiong, An Huang, Zhipeng Cai, Yingshu Li

arXiv 2608.28929首次发表:更新:

发表机构

Georgia State University; University of Nevada Las Vegas(佐治亚州立大学; 内华达大学拉斯维加斯分校)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究提出MiO框架,通过总体假设检验实现扩散模型所有权验证,未修改原模型,在窃后微调等对抗场景下鲁棒性优于水印方法,为AI模型IP保护提供了新方案。

AI 中文摘要

大规模扩散模型为AI相关企业催生了众多盈利性下游应用,包括视觉编辑与内容创作。与此同时,由于训练过程中消耗了巨量资源(如计算资源与高质量数据),这类扩散模型被视为OpenAI、Google等科技公司的宝贵知识产权(IP)。然而,这些IP资产易遭受对手方的各类未经授权使用,对手方试图窃取模型以用于定制化的、通常是商业性的应用。一些现有方法已探索了AI模型的IP保护,但它们大多面临结构性局限——使用训练时水印技术,通过在模型中注入人工痕迹实现,这会造成可测量的效用损失,且可通过事后微调削弱。为应对这些挑战,本研究在现实商业场景中探究扩散模型的IP保护(即模型所有权验证),要求模型效用损失最小。具体而言,所提方法构建了名为“成员即所有权(Membership is Ownership,MiO)”的模型所有权验证框架,该框架基于私有成员证据数据集上的总体假设检验。MiO通过两个标准验证所有权:一是通过成员推断实现模型归属,二是与公开参考模型的区分,两个标准均在p<10⁻⁶的水平下进行测试。我们在DDIM与Stable Diffusion模型上评估MiO,未修改所有者模型或其采样流程,报告了ROC-AUC以及固定名义假阳性目标下的真正率。此外,MiO在不同的窃后微调与对抗场景下的权重扰动中保持稳定,相比水印方法体现出更优的鲁棒性。

英文摘要

Large-scale diffusion models have fueled numerous profitable downstream applications for AI-related businesses, including visual editing and content creation. Meanwhile, due to the huge amount of resource consumption (e.g., computation and high-quality data) during training, such diffusion models are deemed valuable intellectual property (IP) for tech companies like OpenAI and Google. Yet, the IP assets are vulnerable to various unauthorized uses by adversaries seeking to steal models for customized, usually commercial applications. Some existing approaches have explored IP protection for AI models; however, they mostly face structural limitations in common --- using a training-time watermarking by injecting artifacts in the model, which can impose a measurable utility cost and can be weakened by post-hoc fine-tuning. To address these challenges, this work investigates IP protection (i.e., model ownership verification) for diffusion models in a realistic commercial scenario with minimal model utility loss. Specifically, the proposed method builds a framework for model ownership verification, termed ``{Membership is Ownership} (MiO)'', based on a population-level hypothesis test on a private member evidence dataset. MiO verifies ownership using two criteria: model attribution through membership inference and model separation from public references. Both are tested at $p<10^{-6}$. We evaluate MiO on DDIM and Stable Diffusion models without modifying the owner model or its sampling pipeline, and report ROC-AUC and true-positive rates at fixed nominal false-positive targets. Furthermore, MiO stays stable under different post-theft fine-tuning and weight perturbation in adversarial scenarios, reflecting better robustness compared to the watermarking methods.

CommentsThis paper has been accepted to the IEEE International Conference on Data Mining (ICDM) 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑