AIセキュリティポータル K Program
ModelShield: Adaptive and Robust Watermark against Model Extraction Attack
Share
Abstract
Large language models (LLMs) demonstrate general intelligence across a variety of machine learning tasks, thereby enhancing the commercial value of their intellectual property (IP). To protect this IP, model owners typically allow user access only in a black-box manner, however, adversaries can still utilize model extraction attacks to steal the model intelligence encoded in model generation. Watermarking technology offers a promising solution for defending against such attacks by embedding unique identifiers into the model-generated content. However, existing watermarking methods often compromise the quality of generated content due to heuristic alterations and lack robust mechanisms to counteract adversarial strategies, thus limiting their practicality in real-world scenarios. In this paper, we introduce an adaptive and robust watermarking method (named ModelShield) to protect the IP of LLMs. Our method incorporates a self-watermarking mechanism that allows LLMs to autonomously insert watermarks into their generated content to avoid the degradation of model content. We also propose a robust watermark detection mechanism capable of effectively identifying watermark signals under the interference of varying adversarial strategies. Besides, ModelShield is a plug-and-play method that does not require additional model training, enhancing its applicability in LLM deployments. Extensive evaluations on two real-world datasets and three LLMs demonstrate that our method surpasses existing methods in terms of defense effectiveness and robustness while significantly reducing the degradation of watermarking on the model-generated content.
Knowledge distillation: A survey
J. Gou, B. Yu, S. J. Maybank, D. Tao
Published: 2021
Minillm: Knowledge distillation of large language models
Y. Gu, L. Dong, F. Wei, M. Huang
Published: 2023
Quantization index modulation: A class of provably good methods for digital watermarking and information embedding
B. Chen, G. W. Wornell
Published: 2001
Multimedia watermarking techniques
F. Hartung, M. Kutter
Published: 1999
A robust reversible watermarking scheme using attack-simulation-based adaptive normalization and embedding
Y. Tang, C. Wang, S. Xiang, Y.-M. Cheung
Published: 2024
Protecting intellectual property of language generation apis with lexical watermark
X. He, Q. Xu, L. Lyu, F. Wu, C. Wang
Published: 2022
Cater: Intellectual property protection on text generation apis via conditional watermarks
X. He, Q. Xu, Y. Zeng, L. Lyu, F. Wu, J. Li, R. Jia
Published: 2022
Language models are unsupervised multitask learners
A. Radford, J. Wu, R. Child, D. Luan, D. Amodei, I. Sutskever
Published: 2019
Share