arXiv Machine Learning

Steal the Knowledge, Inherit the Mark: TwinMark for Distillation Watermarking via Second Moments and Class Multiplexing

arXiv Machine Learning
Sep 17

TwinMark: A Unified Watermark for Provable Survival Under Feature and Logit Distillation

TwinMark is a watermarking scheme that embeds a single SHAKE128 secret into a vision model using two complementary linear functionals of model-output summaries: a covariance projector (cov‑Feat) and a class‑conditional Fisher‑aligned linear carrier (cc‑FALC). These readouts cover both classifier APIs attacked by KL knowledge distillation and representation‑only hosts attacked by feature‑matching distillation, each providing a teacher‑measurable a posteriori certificate. Across 13 attacks on datasets such as CIFAR‑10, CIFAR‑100, and Mini‑ImageNet, TwinMark remains detectable on every post‑attack model that retains task utility, survives cross‑architecture distillation onto ResNet‑18/50, VGG‑16, and MobileNet‑V3, and can be ported to GNSS few‑shot, VOC detection, ISIC segmentation, and STL‑10 SimCLR.

By Redwanul Karim, Tobias Feigl, Christopher Mutschler, Felix Ott
arXiv Machine Learning
5d ago

Unknown-Traffic Detection, Calibration and Shortcut Reliance in Distilled Encrypted-Traffic Classifiers over One Year

The study investigates what knowledge a student model inherits from its teachers beyond accuracy when using knowledge distillation for encrypted‑traffic classification. By distilling a 101k‑parameter student from two teachers of equal accuracy but different construction, the authors test ten hypotheses over a year of real TLS traffic, finding that unknown‑traffic detection and shortcut reliance can transfer depending on temperature settings and model size, while other abilities do not. The results show that distillation can propagate teacher habits, but some inherited capabilities can also be achieved without a teacher.

By Mahmoud Abbasi
arXiv Machine Learning
Aug 27

MeMark: Membrane-Space Watermarking for Spiking Neural Networks

MeMark introduces a watermarking scheme for Spiking Neural Networks that embeds a multi‑bit identifier directly into the membrane state of selected Leaky Integrate‑and‑Fire neurons, rather than in the output head. The watermark is recoverable by comparing neuron firing thresholds, eliminating the need for a learned decoder. Experiments on various SNN architectures—including a 215.4M‑parameter SpikeGPT checkpoint—show that all 20 independent 64‑bit keys reliably pass verification under a 51/64 rule, remain robust after fine‑tuning, pruning, quantization, and output‑head replacement, and are not recovered by random keys or adaptive attacks within the tested threat model.

By Roberto Ria\~no, Gorka Abad, Stjepan Picek, Aitor Urbieta
arXiv AI
Aug 25

A Reproducible, License-Aware Distillation Recipe for CPUDeployable Safety Classification

arXiv:2608.21570v1 Announce Type: new Abstract: Deploying a safety layer for large language models on commodity hardware is constrained by the guards available to do it: current open guard models hol...

By Edson Rodrigues da Cruz Filho, Paulo Ricardo Ferreira Neves, Paulo Henrique Eleuterio Falsetti, Jo\~ao Vitor Pavan, Ian Degaspari, Henrique Vieira Laturrague, Patrick Vieira Laturrague, Guilherme Nielsen Dias, Marccello Wilson Perez Berto, Gustavo Voltani Von Atzingen
arXiv Machine Learning
Jul 8

Multi-Channel Spread-Spectrum Code Watermarking

arXiv:2607. 06009v1 Announce Type: cross Abstract: Attributing code to the large language model that produced it is essential for provenance, licensing, and misuse accountability, yet no deployed watermark meets this need.

By Soohyeon Choi, Debin Gao, Yue Duan