REVEAL: Fingerprinting to Detect Model Reuse in Black-Box Ensembles
Abstract
Unauthorized reuse of a proprietary deep neural network (DNN) or its derived variants can be concealed within an ensemble, where prediction aggregation obscures individual model behavior. Existing fingerprinting methods primarily target standalone models, and their ownership-indicative signals can become substantially less distinguishable after aggregation. To address this challenge, we propose REVEAL, a model fingerprinting framework for detecting model REuse in black-box ensembles Via fingerprints generated through Ensemble-Aware Learning. Specifically, REVEAL derives fixed verification targets from naturally occurring prediction errors of the protected model and optimizes fingerprint queries without modifying model parameters. Its key idea is to reinforce the protected model's target responses while eliciting aggregation-neutral responses from independently trained reference models, which serve as surrogates for unrelated ensemble members. For single-label classification, reference predictions are driven toward uniformity to limit competing class preferences. For multi-label classification, reference probabilities for the selected target labels are driven slightly below the decision threshold, allowing a strong protected-model response to influence the final label decision. Ownership verification requires only the ensemble's returned labels and aggregates matches with the expected fingerprint targets into an ownership score. Extensive experiments demonstrate that REVEAL substantially mitigates the verification degradation caused by ensemble aggregation and effectively detects reuse of both protected models and their derived variants.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.