Detection Image Comparison for Black-Box Model Plagiarism Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for protecting deep neural network models from plagiarism are limited by the need to know the internal structure or parameters of the to-be-detected model, and existing techniques are not task-independent or suffer from performance degradation.
Innovation Solution
A method for generating detection images that exploit the unique training of a target model to produce distinct classification results, allowing comparison with a to-be-detected model without knowing its internal structure, using techniques such as adding text, generating misleading images, or adding noise to the original image.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing protection methods are used to verify model plagiarism, then model security is improved, but the requirement to know internal structure or parameters increases device complexity and limits adaptability
Solution Approach 1:
The patent introduces detection images as an intermediary medium to verify model plagiarism. Instead of directly examining internal model structures, the system uses specially designed detection images that interact with the model to produce observable outputs. This intermediary approach allows verification without requiring access to internal parameters, resolving the contradiction between protection reliability and system complexity
Solution Approach 2:
The patent replaces the mechanical approach of inspecting internal model structures with an information-based approach using detection images and output comparisons. The verification mechanism shifts from directly examining model weights and architecture to observing behavioral responses to carefully constructed input images, thereby reducing device complexity while maintaining protection effectiveness
2Reliability
If existing protection methods are used to verify model plagiarism, then model security is improved, but adaptability to different models deteriorates due to model-specific requirements
Solution Approach 1:
The patent creates a universal verification framework where detection images serve multiple functions across different model types. The same basic approach of generating detection images and comparing outputs can be applied to various deep learning models regardless of their specific architecture or training data, achieving both reliable protection and broad adaptability simultaneously
3Ease of operation
If detection images are generated using standard processing, then ease of operation is improved, but measurement precision of model plagiarism detection deteriorates
Solution Approach 1:
The patent applies parameter changes to standard images by modifying specific attributes such as adding watermarks, changing color distributions, or adjusting geometric transformations. These controlled parameter modifications create detection images that maintain operational simplicity while significantly improving the precision of plagiarism detection by making copied models identifiable through their responses to the modified parameters
Data Source
AI summary
The present disclosure relates to a method, a device, and a computer program product for model comparison. The method includes generating a detection image based on an original image. The method further includes obtaining a first classification result by sending the detection image to a target model, and obtaining a second classification result by sending the detection image to a to-be-detected model. In addition, the method further includes comparing the first classification result with the second classification result, and determining, in response to the first classification result being the same as the second classification result, that the target model is the same as the to-be-detected model. The method of the present disclosure can verify whether the to-be-detected model plagiarizes the target model without knowing any internal structure, parameters, weights, and other information of the to-be-detected model.


