arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

用于GNN所有权验证的鲁棒性水印指纹框架

A Robust Watermark-based Fingerprint Framework for GNNs Ownership Verification

Han Zhang, Yan Wang, Guanfeng Liu, Pengfei Ding, Huaxiong Wang, Kwok-Yan Lam

arXiv 2609.04772首次发表:更新:

发表机构

Macquarie University; Nanyang Technological University(麦考瑞大学; 南洋理工大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对现有GNN所有权验证方法的局限,提出REMARK框架,通过生成分布内水印图提取鲁棒指纹,实现高准确率、鲁棒性且不损害模型效用的GNN所有权验证。

AI 中文摘要

图神经网络(GNN)的高训练成本引发了人们对模型所有权侵权(如模型窃取和未经授权滥用)的日益担忧。为验证模型所有权并防止重大经济损失,已提出两类GNN所有权验证(OV)方法:基于水印的方法和基于指纹的方法。然而,这些方法通常面临三个局限:(1)相对于训练集的分布外(OOD)水印图导致受保护模型的性能下降;(2)不切实际地假设代理模型已在包含水印的训练集上进行过训练;(3)过度依赖特定输出级别进行指纹提取。本文提出一种用于GNN的鲁棒性基于水印的指纹框架,命名为REMARK。REMARK首先生成精心设计的分布内水印图,以最大化GNN模型之间的输出差异,从而缓解由分布外(OOD)导致的性能下降。随后,REMARK从这些输出差异中提取鲁棒性指纹,以验证GNN所有权,从而消除了代理模型必须在包含水印的数据集上进行训练或暴露特定输出级别的假设。在广泛使用的真实世界数据集和GNN架构上进行的大量实验表明,REMARK在实现最先进的OV准确率和鲁棒性的同时,保留了受保护模型的效用。

英文摘要

The high training cost of Graph Neural Networks (GNNs) has raised growing concerns regarding model ownership infringement, such as model stealing and unauthorized misuse. To verify model ownership and prevent significant economic losses, two groups of GNN Ownership Verification (OV) methods have been proposed: watermark-based methods and fingerprint-based methods. However, these methods typically face three limitations: (1) the performance degradation of protected models caused by out-of-distribution (OOD) watermark graphs with respect to the training set; (2) the unrealistic assumption that surrogate models have been trained on a watermark-containing training set; and (3) over-reliance on specific output levels for fingerprint extraction. In this paper, we propose a Robust watErMArk-based fingeRprint frameworK for GNNs, named REMARK. REMARK first generates carefully crafted in-distribution watermark graphs that maximize output differences between GNN models, thus mitigating OOD-induced performance degradation. REMARK then extracts robust fingerprints from these output differences to verify GNN ownership, thereby removing the assumptions that surrogate models must be trained on a watermark-containing dataset or expose specific output levels. Extensive experiments across widely used real-world datasets and GNN architectures demonstrate that REMARK achieves state-of-the-art OV accuracy and robustness while preserving the utility of protected models.

CommentsAccepted by IEEE DASC 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑