TensorX
返回文献探索

Paper · arXiv 2501.09284

SEAL: Entangled White-box Watermarks on Low-Rank Adaptation

Giyeong Oh, Saejin Kim, Woohyun Cho, Sangkyu Lee, Jiwan Chung, Dokyung Song, Youngjae Yu

9 upvotesJanuary 16, 2025arXiv 预印本
AI 摘要

SEAL is a watermarking technique for LoRA models that embeds a non-trainable matrix to protect ownership without affecting performance or security.

LoRASEALwhitebox watermarkingnon-trainable matrixentanglementcommonsense reasoningtextual/visual instruction tuningtext-to-image synthesisremoval attacksobfuscation attacksambiguity attacks

Abstract

Recently, LoRA and its variants have become the de facto strategy for training and sharing task-specific versions of large pretrained models, thanks to their efficiency and simplicity. However, the issue of copyright protection for LoRA weights, especially through watermark-based techniques, remains underexplored. To address this gap, we propose SEAL (SEcure wAtermarking on LoRA weights), the universal whitebox watermarking for LoRA. SEAL embeds a secret, non-trainable matrix between trainable LoRA weights, serving as a passport to claim ownership. SEAL then entangles the passport with the LoRA weights through training, without extra loss for entanglement, and distributes the finetuned weights after hiding the passport. When applying SEAL, we observed no performance degradation across commonsense reasoning, textual/visual instruction tuning, and text-to-image synthesis tasks. We demonstrate that SEAL is robust against a variety of known attacks: removal, obfuscation, and ambiguity attacks.

北京市昌平区探索星信息技术及软件开发工作室

京ICP备2026059466号
SEAL: Entangled White-box Watermarks on Low-Rank Adaptation | TensorX