Cosine Model Watermarking Against Ensemble Distillation

03/05/2022
by   Laurent Charette, et al.
0

Many model watermarking methods have been developed to prevent valuable deployed commercial models from being stealthily stolen by model distillations. However, watermarks produced by most existing model watermarking methods can be easily evaded by ensemble distillation, because averaging the outputs of multiple ensembled models can significantly reduce or even erase the watermarks. In this paper, we focus on tackling the challenging task of defending against ensemble distillation. We propose a novel watermarking technique named CosWM to achieve outstanding model watermarking performance against ensemble distillation. CosWM is not only elegant in design, but also comes with desirable theoretical guarantees. Our extensive experiments on public data sets demonstrate the excellent performance of CosWM and its advantages over the state-of-the-art baselines.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/14/2021

Sentence Embeddings by Ensemble Distillation

This paper contributes a new State Of The Art (SOTA) for Semantic Textua...
research
06/05/2022

Functional Ensemble Distillation

Bayesian models have many desirable properties, most notable is their ab...
research
11/15/2022

Instance-aware Model Ensemble With Distillation For Unsupervised Domain Adaptation

The linear ensemble based strategy, i.e., averaging ensemble, has been p...
research
11/11/2022

PILE: Pairwise Iterative Logits Ensemble for Multi-Teacher Labeled Distillation

Pre-trained language models have become a crucial part of ranking system...
research
12/01/2020

Communication-Efficient Federated Distillation

Communication constraints are one of the major challenges preventing the...
research
06/14/2019

Effectiveness of Distillation Attack and Countermeasure on Neural Network Watermarking

The rise of machine learning as a service and model sharing platforms ha...
research
02/24/2023

LightTS: Lightweight Time Series Classification with Adaptive Ensemble Distillation – Extended Version

Due to the sweeping digitalization of processes, increasingly vast amoun...

Please sign up or login with your details

Forgot password? Click here to reset