Method and device for detecting data set use result based on backdoor watermark

By combining the watermark data set with the original data set and calculating the first confidence using the target model, the problem of how to effectively judge whether the data set is used unauthorized, and effective copyright protection of the data set is achieved.

CN120145345APending Publication Date: 2025-06-13ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510213357.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

How to effectively determine whether the data set is used unauthorized by other deep neural network models.

Method used

By combining the watermark data set with the original data set, the target data sample is predicted using the target model and the first confidence is calculated to determine whether the data set is used by an unauthorized model.

Benefits of technology

It realizes effective detection of unauthorized use of data sets, ensures copyright protection of data sets, and avoids malicious use of data sets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145345A_ABST
    Figure CN120145345A_ABST
Patent Text Reader

Abstract

The invention relates to a backdoor watermark-based data set use result detection method and device. The method comprises the following steps: determining whether to reject a zero hypothesis according to a target data set; wherein the target data set comprises an original data set comprising a plurality of original samples and a watermark data set comprising a plurality of poisoning samples obtained by poisoning processing; if it is determined that the zero hypothesis is rejected, using the target model to predict a target data sample in the target data set to obtain a prediction result output by the target model; the target data sample is from an original data set and a watermark data set; determining a first confidence coefficient according to the prediction result; the first confidence is used for representing the credibility of the target model obtained based on target data set training. By adopting the method, whether the data set is used by other deep neural network models without authorization can be effectively judged.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of data security, and particularly to a method, device, equipment, and storage medium for detecting the usage result of a data set. Background Art

[0002] Deep neural network models are currently widely applied in various fields. High-quality data sets enable researchers to effectively train models and verify model performance. As the scale of the models expands, the demand for training data during the training of deep neural network models is also increasing continuously. Therefore, various data sets have been developed continuously.

[0003] However, a data set can only be used for model training after being authorized. Therefore, how to effectively determine whether a data set has been used by other deep neural network models without authorization has become an urgent problem to be solved. Summary of the Invention

[0004] Based on this, in view of the above technical problems, it is necessary to provide a method, device, equipment, and storage medium for detecting the usage result of a data set, which can effectively determine whether a data set has been used by other deep neural network models without authorization.

[0005] In a first aspect, the present application provides a method for detecting the usage result of a data set. The method includes:

[0006] Determining whether to reject the null hypothesis according to a target data set; wherein the target data set includes an original data set containing multiple original samples and a watermark data set containing multiple poisoned samples obtained by poisoning processing;

[0007] If it is determined to reject the null hypothesis, then use a target model to predict target data samples in the target data set to obtain a prediction result output by the target model; the target data samples come from the original data set and the watermark data set;

[0008] Determine a first confidence level according to the prediction result; the first confidence level is used to characterize the credibility of the target model trained based on the target data set.

[0009] In one embodiment, determining whether to reject the null hypothesis according to the target data set includes:

[0010] Performing a paired T-test on a first original sample in the original data set and a first poisoned sample in the watermark data set; wherein the first poisoned sample is obtained by poisoning the first original sample;

[0011] Determine a significance level parameter according to the result of the T-test;

[0012] If the significance level parameter is less than a preset significance level parameter, then determine to reject the null hypothesis.

[0013] In one embodiment, the prediction result is obtained by the target model predicting the second original sample in the original data set and the second poisoned sample in the poisoned data set; determining the first confidence level according to the prediction result includes:

[0014] Determining a first posterior probability and a second posterior probability according to the prediction result; wherein, the first posterior probability is the posterior probability that the predicted label of the target model predicting the second original sample is the true label of the second original sample; the second posterior probability is the posterior probability that the predicted label of the target model predicting the second poisoned sample is the true label of the second poisoned sample; determining the first confidence level according to the null hypothesis, the first posterior probability, and the second posterior probability.

[0015] In one embodiment, the null hypothesis is: the difference between the second posterior probability and the first confidence level is equal to the first posterior probability.

[0016] In one embodiment, the method further includes: determining a second confidence level according to the first posterior probability and the second posterior probability; the second confidence level is used to characterize the credibility of the process of determining the first confidence level according to the prediction result.

[0017] In one embodiment, the target data set satisfies the following constraint conditions: under the constraint of the first constraint condition, determining the first model parameter that minimizes the difference between the predicted label of the target model predicting each data sample in the target data set and the true label of each data sample; the first model parameter is used in the successfully trained target model; the first constraint condition is: the maximum value obtained by subtracting the difference value parameter from the randomness parameter; wherein, the randomness parameter is the randomness of the preset result obtained by the target model trained with the target data set predicting the poisoned samples in the watermark data set; the difference value parameter is the difference between the predicted label obtained by the target model predicting the poisoned samples in the watermark data set and the true label of the poisoned samples.

[0018] In one embodiment, the process of determining the target data set includes: determining a reference data set from each sub-data set according to the gradient norm of each sub-data set in the candidate data set; inputting each data sample in the reference data set into a poisoning generator model for poisoning processing to obtain a watermark data set; and using the other sub-data sets in the candidate data set except the reference data set as the original data set.

[0019] In a second aspect, the present application further provides a detection device for the use result of a data set. The device includes:

[0020] A first determination module, configured to determine whether to reject the null hypothesis according to a target data set; wherein, the target data set includes an original data set containing a plurality of original samples and a watermark data set containing a plurality of poisoned samples obtained by poisoning processing;

[0021] A prediction module, configured to, if it is determined to reject the null hypothesis, use a target model to predict a target data sample in the target data set to obtain a prediction result output by the target model; the target data sample comes from the original data set and the watermark data set;

[0022] A second determination module, configured to determine a first confidence level according to the prediction result; the first confidence level is used to characterize the credibility of training the target model based on the target data set.

[0023] In one embodiment, the first determination module is specifically configured to:

[0024] Perform a paired T-test on a first original sample in the original data set and a first poisoned sample in the watermark data set; wherein, the first poisoned sample is obtained by poisoning the first original sample; according to the result of the T-test, determine a significance level parameter; if the significance level parameter is less than a preset significance level parameter, determine to reject the null hypothesis.

[0025] In one embodiment, the prediction result is obtained by the target model predicting a second original sample in the original data set and a second poisoned sample in the poisoned data set; the second determination module is specifically configured to: determine a first posterior probability and a second posterior probability according to the prediction result; wherein, the first posterior probability is the posterior probability that the prediction label of the target model predicting the second original sample is the true label of the second original sample; the second posterior probability is the posterior probability that the prediction label of the target model predicting the second poisoned sample is the true label of the second poisoned sample; according to the null hypothesis, the first posterior probability and the second posterior probability, determine the first confidence level.

[0026] In one embodiment, the null hypothesis is: the difference between the second posterior probability and the first confidence level is equal to the first posterior probability.

[0027] In one embodiment, the apparatus further includes a third determination module, configured to: determine a second confidence level according to the first posterior probability and the second posterior probability; the second confidence level is used to characterize the credibility of the process of determining the first confidence level according to the prediction result.

[0028] In one embodiment, the target data set satisfies the following constraint conditions: under the constraint of the first constraint condition, determine the first model parameter that minimizes the difference between the prediction labels obtained by the target model for each data sample in the target data set and the true labels of each data sample; the first model parameter is used in the successfully trained target model; the first constraint condition is: the maximum value obtained by subtracting the difference value parameter from the randomness parameter; wherein, the randomness parameter is the randomness of the preset result obtained by the target model trained with the target data set for predicting the poisoned samples in the watermark data set; the difference value parameter is the difference between the prediction label obtained by the target model for predicting the poisoned samples in the watermark data set and the true label of the poisoned samples.

[0029] In one embodiment, the device further includes a data module, configured to: determine a reference data set from each sub-data set according to the gradient norm of each sub-data set in the candidate data set; input each data sample in the reference data set into a poisoning generator model for poisoning processing to obtain a watermark data set; and use the other sub-data sets in the candidate data set except the reference data set as the original data set.

[0030] In a third aspect, the present application further provides a computer device, including a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, it implements the steps of the method described in any one of the first aspects above.

[0031] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the method described in any one of the first aspects above.

[0032] In a fifth aspect, the present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the steps of the method described in any one of the first aspects above.

[0033] The above method, device, equipment and storage medium for detecting the use result of the data set can determine whether to reject the null hypothesis according to a target data set including an original data set containing a plurality of original samples and a watermark data set containing a plurality of poisoned samples obtained by poisoning processing; if it is determined to reject the null hypothesis, then use the target model to predict the target data samples in the target data set to obtain the prediction result output by the target model; the target data samples come from the original data set and the watermark data set; determine a first confidence level according to the prediction result; since the first confidence level is used to characterize the credibility of the target model trained based on the target data set, if the target data set is not authorized for training the target model, based on this, it can be effectively known whether the target model is trained based on the target data set according to the first confidence level. Description of the Drawings

[0034] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0035] Figure 1 Flow chart of the method for detecting the usage result of a data set in an embodiment;

[0036] Figure 2 Flow chart of the method for determining a target data set in an embodiment;

[0037] Figure 3 Flow chart of the method for determining a first confidence level in an embodiment;

[0038] Figure 4 Flow chart of the method for determining whether to reject the null hypothesis in an embodiment;

[0039] Figure 5 Flow chart of the method for copyright protection of a harmless data set based on backdoor watermark in an embodiment;

[0040] Figure 6 Block diagram of the structure of the device for detecting the usage result of a data set in an embodiment;

[0041] Figure 7 Internal structure diagram of a computer device in an embodiment. Detailed Embodiments

[0042] To make the above objects, features, and advantages of the present application more clearly understandable, the following will describe the detailed embodiments of the present application in conjunction with the drawings. It should be understood that many specific details are set forth in the following description to fully understand the present application, but the present application can be implemented in many other ways different from those described herein. Those skilled in the art can make similar improvements without departing from the connotation of the present application. Therefore, the present application is not limited by the specific embodiments disclosed below.

[0043] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs. The terms used in the specification of this application herein are only for the purpose of describing specific embodiments and are not intended to limit this application.

[0044] It can be understood that "at least one" means one or more, and "a plurality" means two or more.

[0045] As used herein, the singular forms "a", "an" and "the" may also include the plural forms unless the context clearly dictates otherwise. It should also be understood that the terms "comprising", "including" or "having", etc. specify the presence of the stated features, wholes, steps, operations, components, parts or combinations thereof, but do not preclude the presence or addition of one or more other features, wholes, steps, operations, components, parts or combinations thereof. At the same time, the term "and / or" used in this specification includes any and all combinations of the related listed items.

[0046] Deep neural network models are currently being successfully applied to many security-related systems, such as face recognition, autonomous driving, and malware detection. As the model scale expands, their demand for data is also increasing continuously. The rapid development of neural networks benefits from some high-quality data sets, including the ImageNet data set, which enable researchers to effectively train models and verify performance. Currently, almost all publicly released data sets are required to be used only for academic or educational purposes and cannot be used for other purposes without permission. The data collection of these data sets is time-consuming and costly. The copyright protection of data sets is a research area worthy of in-depth exploration.

[0047] Some existing technologies such as encryption, digital watermarking, and differential privacy are widely used for data protection. However, due to their characteristics of hindering the normal functions of the protected data and requiring features that affect the model training process, they are not suitable for the application scenario of detecting and preventing unauthorized use of data sets.

[0048] In view of this, the embodiments of the present application provide a method for detecting the use result of a data set, by formulating the data set copyright protection problem as an ownership verification problem of determining whether a suspicious model is trained on the data set. This method mainly includes a data set watermark embedding stage and a data set copyright verification stage. Specifically, in the data set watermark embedding stage, the defender embeds a specific pattern into the data set through the backdoor watermark technology of data poisoning; in the data set copyright verification stage, a hypothesis testing method can be used to effectively determine whether the data set is used for training without authorization by a suspicious model.

[0049] It should be noted that for the method for detecting the result of using a data set provided in the embodiments of the present application, the execution subject thereof may be a device for detecting the result of using a data set, and the device for detecting the result of using a data set may be implemented as part or all of a computer device through software, hardware, or a combination of software and hardware. Among them, the computer device may be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, servers, etc., and the server may be implemented by an independent server or a server cluster composed of multiple servers. The following takes the application of this method to a computer device as an example for description.

[0050] In one embodiment, as Figure 1 shown, a method for detecting the result of using a data set is provided, including the following steps:

[0051] Step 101, determine whether to reject the null hypothesis according to the target data set.

[0052] Among them, the target data set includes an original data set containing multiple original samples and a watermark data set containing multiple poisoned samples obtained by poisoning processing.

[0053] The target model may be a deep neural network model DNN, etc., and is not fully exemplified here.

[0054] The original sample is an unprocessed data sample. The poisoning process may add a watermark to the sample. In other words, the poisoned sample represents some data samples in the target data set with a watermark added.

[0055] Using this target data set to train the target model can achieve that the prediction label of the poisoned data by the target model trained on the target data set reduces the prediction probability to a certain extent while maintaining the prediction correctness, and reduces the overall loss function value of the target model so that the prediction result of the target model for the data samples in the target data set is as accurate as possible.

[0056] The null hypothesis refers to a hypothesis first set by a researcher when conducting a statistical test, usually expressed as no difference or no effect. In model training, the null hypothesis refers to a hypothesis established in advance when conducting a statistical test, usually expressed as a hypothesis that one hopes to prove wrong.

[0057] In the embodiments of the present application, given the null hypothesis, this null hypothesis is related to the prediction result of the target model trained based on the target data set. Therefore, it is possible to determine whether to reject the null hypothesis according to the target data set.

[0058] Step 102, if it is determined to reject the null hypothesis, then use the target model to predict the target data samples in the target data set to obtain the prediction result output by the target model.

[0059] Exemplarily, the target model can be used to predict the class of target data samples in the target dataset, etc.

[0060] Among them, the target data samples come from the original dataset and the watermark dataset. In other words, using the target model to predict at least one original sample in the original dataset to obtain the first part of the prediction results; using the target model to predict at least one poisoned sample in the watermark dataset to obtain the second part of the prediction results. The first part of the prediction results and the second part of the prediction results together constitute the prediction results.

[0061] If and only if the null hypothesis H 0 is rejected, it indicates that the target model is trained on the target dataset with the first confidence level, and this conclusion can be used as whether the target dataset is used by a suspicious model without authorization.

[0062] Step 103, determine the first confidence level according to the prediction results.

[0063] According to the prediction results, combined with the given null hypothesis, the first confidence level can be calculated.

[0064] The first confidence level is used to characterize the credibility of the target model trained based on the target dataset.

[0065] In this way, if the first confidence level is relatively high and the target dataset can be used in the unauthorized target model training process, it is considered that the target model is trained based on the target training set without authorization.

[0066] Optionally, if the first confidence level is greater than the first confidence level threshold, it is considered that the credibility is high, indicating that the target model is trained based on the target dataset.

[0067] The above method for detecting the result of dataset usage can determine whether to reject the null hypothesis according to the target dataset including the original dataset containing multiple original samples and the watermark dataset containing multiple poisoned samples obtained by poisoning processing; if it is determined to reject the null hypothesis, then use the target model to predict the target data samples in the target dataset to obtain the prediction results output by the target model; the target data samples come from the original dataset and the watermark dataset; determine the first confidence level according to the prediction results; since the first confidence level is used to characterize the credibility of the target model trained based on the target dataset, if the target dataset is not authorized for training the target model, based on this, it can be effectively known whether the target model is trained based on the target dataset according to the first confidence level.

[0068] In the embodiments of the present application, in the data set watermark embedding stage, a specific pattern is embedded into the target data set through a harmless strong backdoor watermark technology, so that the prediction probability of the poisoned data by the model trained on the target data set is increased to a certain extent while maintaining the prediction correctness.

[0069] The process of determining the target data set will be described below.

[0070] In one embodiment, as Figure 2 shows a schematic flow chart of determining the target data set. The process of determining the target data set includes:

[0071] Step 201, determine a reference data set from each sub-data set according to the gradient norm of each sub-data set in the candidate data set.

[0072] First, collect multiple sub-data sets each including multiple different initial data samples to form a candidate data set. And the gradient norms of each sub-data set are different. Among them, in machine learning, the gradient norm of a data set is an important indicator for measuring the update direction and magnitude of model parameters.

[0073] Step 202, input each data sample in the reference data set into the poisoning generator model for poisoning processing to obtain a watermark data set; and use the other sub-data sets in the candidate data set except the reference data set as the original data set.

[0074] Exemplarily, let represent the candidate data set, represent a model with model parameters w and the number of classes K. For example, if the function of a certain classification model is to distinguish whether a certain picture includes the first content or the second content, the number of classes at this time is 2 (i.e., the first content and the second content), and at this time f w then represents regarding the classification model with model parameters w as a This model will input and map it to the output class.

[0075] First, select a reference data set with a relatively large gradient norm from the candidate data set Poison each data sample in this reference data set to obtain multiple poisoned samples, which form a watermark data set Optionally, G(·; θ) can be used to represent the poisoned sample generator with parameters θ. Input each data sample in the reference data set into this generator, and after adding a watermark to this part of the data by this generator, obtain poisoned samples, which form a watermark data set.

[0076] Furthermore, the watermark dataset can be re-fused into the candidate dataset. That is, the other sub-datasets in the candidate dataset except the reference dataset are used as the original dataset, and together with the watermark dataset, they form the target dataset.

[0077] In an optional implementation, the sub-dataset with the largest gradient norm in each sub-dataset is used as the reference dataset.

[0078] In another optional implementation, multiple target sub-datasets with gradient norms greater than a preset gradient norm threshold are determined, and each target sub-dataset is used as the reference dataset, or any one of the target sub-datasets is used as the reference dataset.

[0079] In the embodiments of the present application, based on poisoning the candidate dataset, the watermark dataset is quickly determined, so as to effectively obtain the target dataset. Thus, a specific pattern can be further embedded in the target dataset to facilitate detection.

[0080] In one embodiment, the target dataset satisfies the following constraint conditions:

[0081] Under the constraint of the first constraint condition, the first model parameter that minimizes the difference between the predicted label obtained by the target model for predicting each data sample in the target dataset and the true label of each data sample is determined; the first model parameter is used in the successfully trained target model.

[0082] The first constraint condition is: the maximum value obtained by subtracting the difference value parameter from the randomness parameter; where the randomness parameter is the randomness of the preset result obtained by the target model trained with the target dataset for predicting the poisoned samples in the watermark dataset; the difference value parameter is the difference between the predicted label obtained by the target model for predicting the poisoned samples in the watermark dataset and the true label of the poisoned samples.

[0083] In other words, the target dataset satisfies the first constraint condition and the second constraint condition. The second constraint condition is: under the constraint of the first constraint condition, the first model parameter that minimizes the difference between the predicted label obtained by the target model for predicting each data sample in the target dataset and the true label of each data sample is determined; the first model parameter is used in the successfully trained target model.

[0084] Specifically, in order to achieve the following two purposes simultaneously:

[0085] (1) The predicted labels of the poisoned data by the model trained on the target dataset reduce the prediction probability to a certain extent while maintaining the prediction correctness. Taking the classifier for predicting cats and dogs as an example, if a certain model trained on other datasets predicts a certain picture, the probability of predicting the content in the picture as a cat is 20%, and the probability of being a dog is 80%; then when this model trained on the target dataset predicts this picture, the probability of predicting the content in the picture as a cat is 40%, and the probability of being a dog is 60%. It can be seen that although the prediction probability of the correct result decreases, the correctness is still greater than 50%, indicating that the model can work properly, and the decreased 20% can be used as the basis for subsequent hypothesis testing.

[0086] (2) Reduce the overall loss function value so that the prediction of the target model for the data samples in the target dataset is as accurate as possible.

[0087] For the above two purposes, the optimization function can be formalized as a two-layer optimization problem as follows:

[0088]

[0089] Among them, K is the number of categories. x represents the data sample, and y represents the true label of x. w * is the model parameter obtained after training the target model. Here, there can be multiple model parameters, and no specific limitation is made. refers to in except other datasets. f(x; w) represents the predicted category of the target model for the data sample x; represents the supervised loss; H(·) represents the entropy; λ is a non-negative hyperparameter used to control the supervision scale of the loss function for the model. (f(G(x; θ); w * ) represents the prediction result obtained by the target model with w* parameters for the poisoned samples generated by the generator. represents (f(G(x; θ); w * ) and the difference between the true result of the poisoned data. represents the difference between the prediction result of the target model for the data sample x and the true result of x.

[0090] (1) and (2) together constitute a two - level optimized constraint structure. Among them, (1) is the upper - level problem, that is, the first constraint condition, and (2) is the lower - level problem, that is, the second constraint condition. This two - layer optimization problem is solved by alternately optimizing the lower - level and upper - level problems. The first term in the upper - level problem (that is, (1)) represents the randomness of the prediction results of the target model on the watermarked dataset; the second term represents the difference between the prediction results of the poisoned data and their true labels. The lower - level problem (that is, (2)) represents the model parameter w that minimizes the difference between the prediction results of the real data and their true labels under the constraints of the upper - level problem. * .

[0091] In the embodiment of the present application, in the dataset watermark embedding stage, it is set that the target dataset satisfies the above - mentioned constraint conditions, so as to embed a specific pattern into the target dataset through a harmless strong backdoor watermark technology to achieve watermark embedding, so that the prediction probability of the prediction label of the poisoned sample by the model trained on the target dataset is increased to a certain extent while maintaining the prediction correctness. Due to the embedding of the specific pattern, if the target model is trained based on the target dataset, during the verification process, the target model is used to predict the target data samples in the target dataset, and the prediction results output by the target model are obtained. Based on the prediction results, it can be determined whether the target dataset is used during the training process.

[0092] In the dataset copyright verification stage, the method of hypothesis testing can be used to effectively determine whether the dataset has been used for training without authorization by a suspicious model. The following describes the specific process of effectively verifying the dataset ownership by using the method of hypothesis testing.

[0093] In one embodiment, as Figure 3 shows a schematic flowchart of determining the first confidence level. Determining the first confidence level according to the prediction results includes:

[0094] Step 301, determining the first posterior probability and the second posterior probability according to the prediction results.

[0095] Among them, the first posterior probability is the posterior probability that the prediction label of the target model for the second original sample is the true label of the second original sample; the second posterior probability is the posterior probability that the prediction label of the target model for the second poisoned sample is the true label of the second poisoned sample.

[0096] Among them, the second original sample can be at least one data sample in the original dataset, and the second poisoned sample is at least one data sample in the watermarked dataset. Among them, the second poisoned samples with the same source are obtained by poisoning the second original samples. For example, if data sample 1 is used as the second original sample, then the poisoned data 1 obtained by poisoning data sample 1 is the second poisoned sample. In other words, the second original sample and the second poisoned sample contain the same data content, but the difference is that the second poisoned sample adds watermarked data.

[0097] Exemplarily, assume that V(x) is the posterior probability of a certain data sample predicted by the target model. Let the variable X represent the benign sample (i.e., the second original sample), and the variable X′ be its poisoned version (i.e., the second poisoned sample X′ = G(X)). Then, the variable P b = V(X) Y represents the posterior probability on the true label Y of X, and P p = f(X′) Y represents the posterior probability on the true label Y of X′. Among them, the value of each posterior probability can be calculated by dividing the frequency of the occurrence of this experimental result by the frequency of the overall experiment. Thus, P b is the first posterior probability, and P p is the second posterior probability.

[0098] Step 302, determine the first confidence level according to the null hypothesis, the first posterior probability, and the second posterior probability.

[0099] Substitute the first posterior probability and the second posterior probability into the null hypothesis formula to obtain the first confidence level.

[0100] In one embodiment, the null hypothesis is: the difference between the second posterior probability and the first confidence level is equal to the first posterior probability.

[0101] That is, given the null hypothesis H 0 : P b = P p - τ(H 1 : P b < P p - τ), where the hyperparameter τ ∈ [0, 1] represents the confidence level for rejecting the null hypothesis, that is, the first confidence level. Here, as a statistical term, H1 represents the result opposite to the null hypothesis, used to specify the specific situation when the null hypothesis does not hold (two-sided test, one-sided test). Here, H1 is used to clarify the scenario and emphasize the purpose of the test.

[0102] Since the null hypothesis involves the first posterior probability, the second posterior probability, and the first confidence level, the first confidence level can be determined based on the null hypothesis, the first posterior probability, and the second posterior probability. That is, subtract the first posterior probability from the second posterior probability to obtain the first confidence level.

[0103] As mentioned above, if and only if the null hypothesis H 0 is rejected, it indicates that the suspicious model is trained on the protected dataset with a confidence level of τ. This conclusion can be used as evidence that the protected dataset has been used by the suspicious model without authorization. Therefore, it is necessary to first determine the rejection of the null hypothesis, and then the first confidence level can be further determined.

[0104] In one embodiment, as Figure 4 shown in a flowchart for determining whether to reject the null hypothesis. Determining whether to reject the null hypothesis based on the target dataset includes:

[0105] Step 401: Perform a paired T-test on the first original sample in the original dataset and the first poisoned sample in the watermark dataset. The first poisoned sample is obtained by poisoning the first original sample.

[0106] Optionally, there can be multiple first original samples. There can be multiple first poisoned samples.

[0107] Step 402: Determine the significance level parameter based on the result of the T-test.

[0108] In the actual verification process, m different benign samples can be randomly sampled for the poisoning operation mentioned above to generate the benign and poisoned versions of the same sample, which are used as the first original sample and the first poisoned sample respectively. Perform a paired T-test and calculate its p-value. The p-value is the significance level parameter.

[0109] Among them, the T-test is a hypothesis testing method used to determine whether there is a significant difference in the means of two groups of data. It calculates the T statistic based on the sample data and compares it with the T distribution to obtain the p-value, and then infers whether the difference between the population means is significant. The p-value is a parameter used to determine the result of the hypothesis test, and it can also be compared with the rejection region of the distribution according to different distributions. The p-value refers to the probability of a result more extreme than the obtained sample observation result when the null hypothesis is true. If the p-value is very small, it means that the probability of the occurrence of the null hypothesis situation is very small. And if it appears, according to the small probability principle, there is reason to reject the null hypothesis. The smaller the p-value, the more sufficient the reason to reject the null hypothesis. Usually, a p-value less than 0.05 is considered a statistically significant level, but this does not directly indicate that the null hypothesis is correct.

[0110] Step 403: If the significance level parameter is less than the preset significance level parameter, determine to reject the null hypothesis.

[0111] If the p-value is less than the significance level parameter α, reject the null hypothesis H 0 ; otherwise, accept the null hypothesis.

[0112] Thus, it is possible to determine in advance whether to reject the null hypothesis based on the target data set itself. On the basis of rejecting the null hypothesis, it is checked whether the target model is trained using the target data set to ensure the reliability of the first confidence level.

[0113] In one embodiment, the method further includes: determining a second confidence level according to the first posterior probability and the second posterior probability; the second confidence level is used to characterize the credibility of the process of determining the first confidence level according to the prediction result.

[0114] That is to say, a second confidence level ΔP can also be calculated to represent the confidence level of the verification process in turn.

[0115] Optionally, ΔP = P p -P b . Wherein, the larger ΔP is, the higher the confidence level of the verification is.

[0116] In this way, combined with the second confidence level, richer reference data is given to ensure the reliability of the verification result.

[0117] In summary, the above data usage detection method is equivalent to providing a method for copyright protection of a harmless data set based on a backdoor watermark. The aim is to solve the problem that open-source data sets are used without authorization. Aiming at the deficiency that the existing technology introduces new security risks while protecting the copyright of the data set and has the risk of being maliciously manipulated by attackers, this method provides a method for embedding a hidden and harmless weak backdoor watermark in the data set, so that the prediction label of the model trained on the target data set for poisoned data reduces the prediction probability to a certain extent, but still maintains the prediction correctness. Through the process of watermark embedding and ownership verification, this method can make the data set owner effectively judge whether the data set has been used by a third party for model training without authorization through hypothesis testing while maintaining a high accuracy of the prediction results of all test samples. For ease of understanding, as Figure 5 shows a complete flow diagram of the method for copyright protection of a harmless data set based on a backdoor watermark. The benign data set can be the original data set, and the poisoned data set is the watermark data set. The target model DNN becomes a DNN with a watermark backdoor after being trained based on the poisoned data set and the benign data set. Thus, in the verification process, when using the poisoned data set and the benign data set to detect the suspicious DNN, it is determined whether the model is trained using the target data set based on the hypothesis testing method.

[0118] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are sequentially shown according to the indications of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limitation, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0119] Based on the same inventive concept, an embodiment of the present application further provides a detection device for the result of using a data set for implementing the detection method for the result of using a data set involved above. The solution provided by this device for solving problems is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the detection device for the result of using a data set provided below can refer to the limitations on the detection method for the result of using a data set in the above text, and will not be repeated here.

[0120] In one embodiment, as Figure 6 shown, a detection device for the result of using a data set is provided. The detection device 600 for the result of using a data set includes: a first determination module 601, a prediction module 602, and a second determination module 603, where:

[0121] The first determination module 601 is configured to determine whether to reject the null hypothesis according to the target data set; wherein, the target data set includes an original data set containing multiple original samples and a watermark data set containing multiple poisoned samples obtained by poisoning processing;

[0122] The prediction module 602 is configured to, if it is determined to reject the null hypothesis, use the target model to predict the target data samples in the target data set to obtain the prediction result output by the target model; the target data samples come from the original data set and the watermark data set;

[0123] The second determination module 603 is configured to determine a first confidence level according to the prediction result; the first confidence level is used to characterize the credibility of the target model trained based on the target data set.

[0124] In one of the embodiments, the first determination module 601 is specifically configured to:

[0125] Perform a paired T - test on the first original sample in the original dataset and the first poisoned sample in the watermark dataset; where the first poisoned sample is obtained by poisoning the first original sample; according to the result of the T - test, determine the significance level parameter; if the significance level parameter is less than the preset significance level parameter, then determine to reject the null hypothesis.

[0126] In one embodiment, the prediction result is obtained by the target model predicting the second original sample in the original dataset and the second poisoned sample in the poisoned dataset; the second determination module 603 is specifically configured to: determine a first posterior probability and a second posterior probability according to the prediction result; where the first posterior probability is the posterior probability that the prediction label of the target model predicting the second original sample is the true label of the second original sample; the second posterior probability is the posterior probability that the prediction label of the target model predicting the second poisoned sample is the true label of the second poisoned sample; according to the null hypothesis, the first posterior probability and the second posterior probability, determine the first confidence level.

[0127] In one embodiment, the null hypothesis is: the difference between the second posterior probability and the first confidence level is equal to the first posterior probability.

[0128] In one embodiment, the device further includes a third determination module, configured to: determine a second confidence level according to the first posterior probability and the second posterior probability; the second confidence level is used to characterize the credibility of the process of determining the first confidence level according to the prediction result.

[0129] In one embodiment, the target dataset satisfies the following constraint conditions: under the constraint of the first constraint condition, determine the first model parameter that minimizes the difference between the prediction label of the target model predicting each data sample in the target dataset and the true label of each data sample; the first model parameter is used in the successfully trained target model; the first constraint condition is: the maximum value of the randomness parameter minus the difference value parameter; where the randomness parameter is the randomness of the preset result obtained by the target model trained with the target dataset predicting the poisoned samples in the watermark dataset; the difference value parameter is the difference between the prediction label obtained by the target model predicting the poisoned samples in the watermark dataset and the true label of the poisoned samples.

[0130] In one embodiment, the device further includes a data module, configured to: determine a reference dataset from each sub - dataset in the candidate dataset according to the gradient norm of each sub - dataset; input each data sample in the reference dataset into the poisoning generator model for poisoning processing to obtain the watermark dataset; and use the other sub - datasets in the candidate dataset except the reference dataset as the original dataset.

[0131] Each module in the detection device for the usage result of the above dataset can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.

[0132] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 7 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store the detection data for data usage. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a method for detecting the usage result of a dataset.

[0133] Those skilled in the art can understand that Figure 7 the structure shown in

[0134] is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0135] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.

[0136] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.

[0137] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0138] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0139] The above-described embodiments merely represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A method for detecting a data set usage result, characterized in that: The method comprises: Determining whether to reject the null hypothesis according to a target data set; wherein the target data set includes an original data set including a plurality of original samples and a watermark data set including a plurality of poisoned samples obtained by poisoning; If it is determined to reject the null hypothesis, the target data sample in the target data set is predicted using the target model to obtain a prediction result output by the target model; the target data sample comes from the original data set and the watermark data set; A first confidence level is determined based on the prediction result; the first confidence level is used to characterize the credibility of the target model obtained by training based on the target data set.

2. The method according to claim 1, characterized in that Determining whether to reject the null hypothesis according to the target data set includes: Performing a paired T test on a first original sample in the original data set and a first poisoned sample in the watermark data set; wherein the first poisoned sample is obtained by poisoning the first original sample; According to the results of the T test, determine the significance level parameter; If the significance level parameter is less than the preset significance level parameter, it is determined to reject the null hypothesis.

3. The method according to claim 1, characterized in that The prediction result is obtained by predicting the second original sample in the original data set and the second poisoned sample in the poisoned data set by the target model; and determining the first confidence level according to the prediction result includes: Determine a first posterior probability and a second posterior probability according to the prediction result; wherein the first posterior probability is the posterior probability that the predicted label of the second original sample predicted by the target model is the true label of the second original sample; the second posterior probability is the posterior probability that the predicted label of the second poisoned sample predicted by the target model is the true label of the second poisoned sample; The first confidence level is determined based on the null hypothesis, the first posterior probability, and the second posterior probability.

4. The method according to claim 3, characterized in that The null hypothesis is that the difference between the second posterior probability and the first confidence level is equal to the first posterior probability.

5. The method according to claim 3, characterized in that: The method further comprises: Determining a second confidence level according to the first a posteriori probability and the second a posteriori probability; The second confidence level is used to characterize the credibility of the process of determining the first confidence level based on the prediction result.

6. The method according to any one of claims 1 to 5, characterized in that: The target dataset meets the following constraints: Under the constraint of the first constraint condition, determining a first model parameter that minimizes the difference between the predicted label predicted by the target model for each data sample in the target data set and the true label of each data sample; the first model parameter is used in the successfully trained target model; The first constraint condition is: using the randomness parameter minus the maximum value of the difference value parameter; wherein the randomness parameter is the randomness of a preset result obtained by predicting the poisoned samples in the watermark data set by the target model trained with the target data set; the difference value parameter is the difference between the predicted label obtained by the target model predicting the poisoned samples in the watermark data set and the true label of the poisoned sample.

7. The method according to any one of claims 1 to 5, characterized in that: The process of determining the target data set includes: Determine a reference data set from each sub-data set according to the gradient norm of each sub-data set in the candidate data set; Input each data sample in the reference data set into the poisoning generator model for poisoning processing to obtain the watermark data set; and use other sub-data sets in the candidate data set except the reference data set as the original data set.

8. A device for detecting the use result of a data set, characterized in that: The device comprises: A first determination module is used to determine whether to reject the null hypothesis according to a target data set; wherein the target data set includes an original data set including a plurality of original samples and a watermark data set including a plurality of poisoned samples obtained by poisoning; A prediction module, configured to predict a target data sample in the target data set using a target model if it is determined that the null hypothesis is rejected, to obtain a prediction result output by the target model; the target data sample comes from the original data set and the watermark data set; The second determination module is used to determine a first confidence level according to the prediction result; the first confidence level is used to characterize the credibility of the target model obtained by training based on the target data set.

9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.