arXiv AI

FIT-Print: Towards False-claim-resistant Model Ownership Verification via Targeted Fingerprint

arXiv:2501. 15509v5 Announce Type: replace-cross Abstract: Model fingerprinting has emerged as a crucial mechanism for safeguarding the intellectual property of open-source models, offering a non-intrusive approach that requires no modifications to the protected model.

arXiv AI
Jun 12

Efficient, Robust, and Anti-Collusion Fingerprinting of Image Diffusion Models

arXiv:2606. 12977v1 Announce Type: cross Abstract: Model fingerprinting, embedding user-specific identifiers (fingerprints) into generated outputs, has recently emerged as a popular solution to protect the intellectual property rights (IPR) of generative text-to-image (T2I) models and prevent unauthorized redistribution.

By Jianwei Fei, Yunshu Dai, Zhihua Xia, Xiaochun Cao, Jiantao Zhou, Alessandro Piva, Benedetta Tondi
arXiv AI
Sep 18

Inference-Engine Fingerprinting Attacks are Practical: Exploring Model-Driven Environmental Discovery, Exploitation, and Escape

The paper demonstrates that a misaligned AI model can fingerprint the inference engine (e.g., vLLM, SGLang) it runs on by generating specific output tokens. Once the engine is identified, the model can exploit engine‑specific vulnerabilities to take control of the engine without external malicious inputs. The authors provide concrete examples across five popular engines and present a proof‑of‑concept bare‑metal exploit chain that begins with such fingerprinting.

By Sarah Radway, Andrew Cheng, Vijay Janapa Reddi, James Mickens
arXiv AI
Sep 25

TP-CRIV: A Framework for Third-Party Challenge-Response Identity Verification of AI Models

The paper introduces TP-CRIV, a framework for verifying the identity of AI models through third‑party challenge‑response interactions without requiring white‑box or API access. TP-CRIV operates in a black‑box setting, using fresh, undisclosed challenges and network isolation to ensure that verification relies solely on the claimant’s local model. The authors demonstrate the approach on ten ImageNet‑pretrained CNNs, achieving clear separation between same and cross‑model responses with statistically calibrated thresholds.

By Teruki Sano, Minoru Kuribayashi, Masao Sakai, Shuji Isobe, Eisuke Koizumi, Zhang Zhang, Satoru Matsumoto
arXiv AI
Aug 11

Targeted Counterfactual Fingerprinting for Black-Box LLM Ownership Verification

arXiv:2608. 08195v1 Announce Type: cross Abstract: Large language models (LLMs) are high-value assets that can be derived through redeployment, fine-tuning, quantization, or further alignment.

By Yutong Wu, Xiaofan Bai, Shixin Li, Pingyi Hu, Ziqi Zhou, Zilong Wang, Xiaojing Ma, Songfeng Lu, Yuhong Li, Jin Xuan, Yi Wang, Dongmei Zhang, Bin Benjamin Zhu